TechKnowSurge
CompTIA Security+ 5.5 ISC2 CISSP 6.5 NIST 800-53 CA-2 NIST 800-53 AU-6 ISC2 CISSP 6.1 CompTIA Security+ 5.3
VideoSecurityFree

Auditing

Auditing is the process of inspecting systems, accounts, and procedures to verify that policies are being followed and nothing has fallen out of alignment. This content covers the account management lifecycle, what to prioritize for regular audits, and the differences between internal self-assessments and third-party external audits.

Complete this video to capture a CTF flag worth 1 point.

About this video

Auditing is the practice of systematically inspecting processes, configurations, and access controls to confirm that what an organization intends to do is actually being done. Without a formal auditing process, gaps accumulate silently — procedures drift, permissions go uncorrected, and non-compliance goes undetected until a more serious problem surfaces. Auditing provides the mechanism to catch these misalignments before they become significant risks. Account management serves as a clear illustration of where auditing adds value. At every stage of the account lifecycle — provisioning, ongoing maintenance, role changes, and de-provisioning — there are opportunities for errors to occur. When a user transitions to a new role, new permissions are often granted without removing old ones, leaving that individual with broader access than their current responsibilities warrant. When an employee leaves the organization, accounts that should be deactivated sometimes remain open. Periodic audits, whether conducted monthly, quarterly, or annually, catch these discrepancies by cross-referencing HR records against active accounts and verifying that access levels match current job functions. Organizations must also decide which areas to audit and how frequently, prioritizing the systems and processes that carry the greatest risk. Not every process can be audited continuously, so critical systems typically receive more rigorous and regular attention. The scope of auditing extends beyond account management to include compliance programs, risk management processes, and asset inventories, among others. Audits can be conducted internally through self-assessments or cross-departmental reviews, which are cost-effective and can surface many common issues. However, internal audits carry an inherent limitation — objectivity is difficult to maintain when the people performing the review are also responsible for the processes being reviewed. External audits address this by bringing in independent third-party auditors who evaluate controls against established industry standards. In practice, most organizations benefit from a combination of both, using internal audits for ongoing oversight and external audits to satisfy vendor requirements, customer expectations, or regulatory obligations.

What you'll learn

What's covered

Auditing

Aligned to

CompTIA Security+
5.5 Explain types and purposes of audits and assessments.
5.3 Explain the processes associated with third-party risk assessment and management.
ISC2 CISSP
6.5 Conduct or facilitate security audits.
6.1 Design and validate assessment, test, and audit strategies.
NIST 800-53
CA-2 Control Assessments
AU-6 Audit Record Review, Analysis, and Reporting

Key terms

IT Audit
A systematic inspection of IT processes, controls, and systems to identify misalignments and verify that established procedures are being followed correctly.
Account Lifecycle Management
The process of provisioning, maintaining, and deprovisioning user accounts throughout their existence within an organization.
Provisioning
The process of creating and configuring user accounts and granting appropriate access rights when a user joins or changes roles in an organization.
De-provisioning
The process of revoking and removing a user's access rights and accounts when they leave an organization or no longer require access.
Self-Assessment
An internal audit in which an organization evaluates its own processes and controls; less costly than external audits but limited by potential bias and conflicts of interest.
Third-Party Audit
An independent examination of an organization's processes and controls conducted by an external auditor to provide an objective, industry-standard evaluation.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.

Topics

It Auditing Account Lifecycle Management Internal Audit Third Party Audit Compliance Identity And Access Management

Transcript

It's a nice idea that we could roll something out and it would be executed perfectly every time, that we would follow all the procedures exactly and nothing would fall through the cracks. But unfortunately that's not reality. Things always get out of sync, and we need something that keeps things in check. Well, that's what auditing does for us. Auditing allows us to identify when things are out of alignment, that things are out of sync.

What Auditing Is

The concept of auditing is very simple. It just means inspection. We're taking an inspection into things, and in this case right here we're inspecting to make sure that everything that we said we're going to do and that we've rolled out is actually being done.

The Life Cycle of an Account

Here's the life cycle of an account. When somebody is onboarded, they go through a provisioning process. They go through the maintenance of this account, where we do change management. And at some point in time there's a de-provisioning of the account.

Now, what happens is if we skip a step or do something wrong at the beginning, the user can oftentimes let us know and say, hey, I can't get into these systems, and then we go and correct that. So there's kind of a self adjustment that happens with that, because they just can't get access to certain things, and then they complain about it, and then we fix the issue.

But that same thing happens when they change positions. Maybe we give them permission for the new position, but we don't remove the permissions from the old position. So they've essentially got more access to things, everything that they had access to before plus everything new, and we haven't changed things properly.

Same thing with de-provisioning. When somebody leaves the company, hopefully we've got good processes in place to be able to decommission accounts and make sure that they're not able to still access our systems once they leave the company. But that doesn't always happen accurately or correctly, and so we need this auditing process to check all of these errors and what's happening along the way.

What Should We Audit?

So we do auditing in all different areas, but let's continue with that example of account management. Maybe we get the list from HR and we compare it against our accounts every now and then. Maybe we do this on a monthly basis, maybe it's on a quarterly basis, maybe it's on a yearly basis. We also make sure those accounts have access to the proper resources, that they're not able to get to resources that they shouldn't get to.

So what is it that we should audit? Well, we have a ton of processes. We've rolled out a compliance process, a risk management process, an asset management process. We've rolled out all these processes, and then in each one of those processes there are errors that can happen. So at the very least we can audit any of these items, but the ones that are most critical. And then at the most, we could actually audit all of this and do all of the auditing, and some businesses will do that because they need to be very secure. But more often than not, we need to pick and choose what is going to be our most critical systems that we should audit on a regular basis.

Self-Audits and External Audits

Now, largely so far I just talked about self-audit, which is fair, that we need to do self-audits. We need to go and double check people's work, we need to check our work, we need to check other people's work and make sure that things are done correctly. So we just need to do some self assessments here.

Self-assessments are great because they're a lot less expensive and they can catch a lot of flaws or a lot of issues. But it's also difficult to be objective, and there's a bit of a conflict of interest. That is, I do things in a certain way, and so whatever is outside of my purview, I'm not going to be able to audit those correctly.

So sometimes it requires us to go outside and get a third party auditor, somebody to come in and help us audit. It still could be done internally, possibly with something like a committee. A committee might be in charge of auditing, or somebody from another department might be in charge of some of these audits. It's one reason why a security team that's separate from the rest of it is very helpful, because they can do this auditing and be detached from the actual IT department and the actual operations department.

But sometimes it's called for to do external audits, to have somebody come in and do an audit for you. A lot of times if you're working with vendors or customers or partners, especially customers, I've seen a lot of times where they've required the company that I've worked for to get a third-party audit. So there are times when customers may do an audit on a company, but more often than not I find that they require a third-party auditor to come in and audit us to make sure we're doing the right things.

Ultimately we probably are going to do both internal audits and external audits, that we're going to have some auditing that we're going to do internally and then also hire a third party to come in and make sure that we're doing things correct from an industry standard perspective.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →