Chapter 14. Day 14 – Security Assessment and Testing - Controlling, Analyzing, Auditing, and Reporting
This chapter covers management and operational controls pertaining to security process data. Analyzing and reporting test outputs either automated or through manual methods, and conducting or facilitating internal and third party audits are covered in detail.
A candidate appearing for the CISSP exam is expected to understand the foundational concepts and have knowledge in the following key areas of controlling, analyzing, auditing, and reporting security tests from the security assessment and testing domains:
- Management and operational controls on security process data
- Disaster recovery and business continuity
- Analyzing and reporting test outputs
- Internal and third-party security audits