ISC2 CISSP Practice Question
A CISO arranges for security control testing to be performed by staff who work in a different department than the systems being evaluated. These evaluators are familiar with the organization's policies and report their findings to a governance committee. Which audit approach is being described?
Regulatory audit
External audit
Third-party audit
Internal audit