Security Audit
A security audit is a systematic assessment of an organization's security controls, policies, and practices to determine whether they meet defined requirements.
“An audit evaluating an organization's security processes and infrastructure.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Security Audit?
Security audits evaluate technical, administrative, and physical controls to identify weaknesses, verify compliance, and recommend improvements.
Compliance verification: Confirms adherence to policies and standards.
Control evaluation: Reviews security measures and their effectiveness.
Improvement focus: Identifies areas requiring corrective action.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Security audit points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Security audit helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Security audit in the context of ISTQB terminology?
Question 2
A tester needs to explain Security audit to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Security Audit. Test your understanding with topic-specific questions in our Mock Exams.