Attestation is the practice of providing verifiable evidence that security policies and procedures are being followed. It plays a central role in audits and compliance activities across cybersecurity disciplines.
Attestation in Cybersecurity
Attestation is a word that I didn't really encounter much before I was in cybersecurity, but I definitely see it now, and you'll encounter it as well.
Attestation just means evidence or proof of something. So it's pretty straightforward: it just means that we're going to show evidence or proof of something. So when we do an audit, we're looking for an attestation that there is proof that we're doing something, that we are actually accomplishing what we set out to accomplish.
So how does this apply? Let's apply it to maybe an external auditor. They come in and they want you to attest to something, they want you to verify something. And so what they're going to do is maybe they ask, give me a list of all the employees that have left over this last month. And so then you would give them this list, and then they might choose one, two or three, or maybe even all four, and say, okay, I want proof that this person's account is shut off and when it was shut off.
And then we would have to go into our accounting system and show that we actually decommissioned that account, we deprovisioned that account, we turned that account off, we disabled that account. That shows them — that is proof — that we are in fact following our policy.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →