Costs are the number one limitation for any company. They won’t waste money just for the fun of it whether it’s internal or external.
If it’s an internal audit you aren’t attempting to achieve any accreditation or certification so for me it would be certification.
Speaking from experience doing security audits at clients, internal audits do NOT result in an official certification of any kind. See it as a way of 1) finding gaps and fixing them by a certain date by which an external audit will actually perform the audit and provide certification.
And to add to this, everything has costs to it. Internal audit = blocking personnel from doing their day to day to answer to questions, to go through documentation, have people involved internally who actually do the audit, sometimes aided by consulting firms who work from an internal audit perspective as well... All these things cost $$€€
in my work, i don't think Internet audit focus on operation efficiency, our SOP will increase after their audit every time, our workload increases as well
Because external audits does not take on the role of a "trusted advisor" but more of a regulator with punitive capability, I see "A" as the BEST answer.
The CCSP offical guide mentioned that internal audit covers cost, design, performance...while external covers some sort of the efficiency of control implementation.
internal audit may be the first phase of certification process, before going with external auditor for certification.Internal audit is recomanded.Costs should be best answer
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
kjjcraigskel
Highly Voted 4Â years, 1Â month agoaxman832005
2Â years, 8Â months agoCptSweatbread
2Â years, 3Â months agoTreebeard88
10Â months, 3Â weeks agoZeezee2
Highly Voted 3Â years agoZeezee2
3Â years agogloby118
Most Recent 5Â months, 1Â week agoLenell
1Â year, 11Â months agoEric0223
2Â years, 1Â month agokepalon
2Â years, 8Â months agocarls233
3Â years, 1Â month agoBanzaaai
3Â years, 2Â months agoCISSP_Wannabe
3Â years, 8Â months agoSa007788
3Â years, 10Â months agoQ2
4Â years ago