Audits, assessments, gap analysis and where penetration testing fits

This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.

Objective 5.5 · Security Program Management and Oversight · 14% of the exam

Objective 5.5 asks you to explain how an organisation checks its own security: how evidence is gathered, how an engagement is scoped and who performs it, how the result is compared with a framework or with peers, and where penetration testing and other testing fit. It is the Domain 5 capstone, because an audit is where governance, risk, third-party management and compliance are all tested at once.

Why this matters

This objective supplies several reliable question types: internal versus external and who each serves; the penetration testing environment terms (known, partially known, unknown); and, new in SY0-801, the evidence-gathering methods and the threat models an assessor uses as reference points. Gap analysis has also moved here from Domain 1.

It is also where the course closes a loop. Every control in Domains 1 to 4 is eventually checked by somebody, and the form that check takes is in this lesson.

The lesson

Gathering evidence: sampling, questionnaires, interviews and assertions

An audit's conclusion is only as good as its evidence, and assessors gather it in a few standard ways.

  • Sampling. Nobody can test all 4,000 access changes made last year, so the auditor tests a sample and infers the rest. A statistical sample is chosen at random, so the result can be generalised with known confidence. A judgemental sample is chosen by the auditor's expertise, such as every change to a privileged account. Either way, the sample is drawn by the auditor from the complete population; a sample the auditee picked tests only what the auditee was confident about.
  • Questionnaires and surveys. Cheap, broad coverage across many teams or suppliers. Every answer is self-reported, so they show where to look rather than proving anything.
  • Interviews. Talking to the people who run a process shows how it actually works, which is often not how the procedure describes it. An interview answer is then corroborated with a record.
  • Assertions. An assertion is a claim by management that a control exists and operates: "every leaver's access is removed within one working day". The audit tests the assertion against evidence. Independent assurance reports such as SOC 2 contain management's assertion alongside the auditor's opinion, and the two are worth very different amounts: one is a claim, the other is a tested conclusion.

The evidence an auditor trusts most is a record the running system produced: a configuration export, a log, a ticket with an approval. A statement that a control exists comes last.

MITRE ATT&CK, the Cyber Kill Chain and the Diamond Model as reference sources

Assessors need a common map of how attacks unfold, so that "are we protected?" becomes a list of specific questions. Three models serve as that map.

  • MITRE ATT&CK is a free knowledge base of adversary behaviour built from observed, real-world intrusions. Tactics are the attacker's goal at each step (initial access, persistence, privilege escalation, lateral movement, exfiltration and others); techniques and sub-techniques are the ways each goal is achieved. In an assessment it is used to ask, technique by technique, whether the organisation would prevent it, detect it, or miss it. The output is a coverage map that shows the detection gaps.
  • The Cyber Kill Chain, published by Lockheed Martin, describes an intrusion as seven stages: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. Its defensive idea is that breaking any link stops the attack, and that controls should exist at every stage, not just at the perimeter.
  • The Diamond Model of Intrusion Analysis describes every intrusion event by four linked points: the adversary, their capability, the infrastructure they used, and the victim. An analyst who knows one point pivots to the others: an IP address (infrastructure) leads to the tooling (capability) seen elsewhere, which leads to other likely victims.

The exam's distinction: ATT&CK is a detailed catalogue of techniques, the Kill Chain is a sequence of stages, and the Diamond Model is a way of relating the elements of one event. All three are used here as reference sources against which controls are judged.

Scoping with an audit charter, and internal versus external engagements

An audit charter is the formal document, approved by the board or its audit committee, that establishes the internal audit function: its purpose, its authority to access records, systems and people, its responsibilities, and its reporting line. Its most important clause is independence: internal audit reports to the audit committee, not to the head of IT, because an auditor who reports to the person being audited cannot produce an uncomfortable finding. Each engagement then has its own scope (which systems, which period, against which criteria) and a frequency, set by risk, regulation or contract.

Internal engagements are performed by the organisation's own people:

  • compliance audits against a specific obligation, producing findings with owners and dates;
  • the audit committee, the board-level body that commissions audits, receives findings and holds management to closing them;
  • self-assessments, where a team checks its own controls. Cheapest and most frequent, useful for fixing things early, and not evidence for anyone outside.

External engagements are performed by outsiders, and their defining property is independence:

  • regulatory audits and examinations, conducted by or for a regulator, with enforcement consequences;
  • assessments by a third party evaluating against a standard or giving an expert opinion;
  • independent third-party audits, the certification or attestation audits (ISO/IEC 27001, SOC 2, PCI DSS) whose reports other organisations rely on.

The discriminator: internal serves management and improvement; external serves outsiders who need assurance they cannot get by asking you. Whatever the type, findings are tracked to closure, and the scope is the first thing to read: a clean report on a narrow scope says nothing about what was outside it.

Gap analysis and benchmarking against industry, international and regional frameworks

A gap analysis compares the current state of your controls with a required state, and lists the differences. It is useful when it names a specific target ("we do not meet this numbered requirement of the framework we adopted"), produces per-item findings with owners, and feeds the risk register, where each gap is fixed, covered by a compensating control, or accepted with a reason. It is the correct first step when an organisation adopts a new framework or prepares for an audit: you cannot plan remediation before you know the gaps.

The target is usually a framework or standard, and they come in three kinds:

  • Industry-based: imposed by a sector on its participants. PCI DSS for anyone handling payment cards is the standard example.
  • International: written for use anywhere, such as ISO/IEC 27001 for an information security management system, with ISO/IEC 27002 as its control guidance.
  • Region-specific: tied to a country or bloc, such as FedRAMP for cloud services sold to US federal agencies, Cyber Essentials in the UK, or the requirements EU member states apply under the NIS2 directive.

Benchmarking is related but different. Where a gap analysis compares you with a requirement, benchmarking compares you with others: peers in your sector, or a maturity scale. It answers "are we behind or ahead of organisations like us?", which is a useful argument for funding, and it does not by itself say whether you are compliant.

Penetration testing by environment and approach, and functional versus behavioural testing

Penetration testing is authorised, simulated attack to find weaknesses that can actually be exploited. A vulnerability scan reports what a tool recognises; a test shows what is exploitable and how minor findings chain together. Written authorisation and rules of engagement, from the third-party lesson, are what separate it from a crime.

By how much the tester is told:

  • Known environment: full information (architecture, credentials, source). Finds the most per hour; does not simulate an outsider.
  • Partially known environment: some information, such as a standard user account. The usual compromise, and a good proxy for an insider or an attacker with a foothold.
  • Unknown environment: nothing beyond the target. Most realistic as an outside attacker, least efficient.

By approach: physical testing of doors, badges and reception; offensive (red team) simulation of the attacker; defensive (blue team) assessment of detection and response; and integrated (purple team) work, where both sides share what they did and saw and build detections in the same session. If a scenario asks how to test whether the security team would notice an intrusion, the answer is a red or purple team exercise, not a scan. Reconnaissance is passive (public sources, never touching the target) or active (scanning and probing, which is detectable and so also tests your monitoring).

Two further kinds of test sit beside these:

  • Functional testing checks that a control does what it is specified to do when exercised: the account locks after the set number of failures, the backup actually restores, the firewall rule blocks the port it should.
  • Behavioural testing checks how people and systems actually behave under realistic conditions: whether staff report a simulated phish, whether a receptionist challenges a visitor, whether a system degrades safely under unexpected input or load.

An audit asks whether the controls exist. A functional test asks whether they work. A behavioural test or red team asks whether they hold up in practice.

What to take into the exam

  • The auditor draws the sample from the full population; questionnaires and assertions are claims until tested.
  • ATT&CK catalogues techniques, the Kill Chain sequences stages, the Diamond Model relates adversary, capability, infrastructure and victim.
  • The audit charter gives internal audit its authority and independence.
  • Internal serves management; external serves outsiders who need independent assurance.
  • Gap analysis compares you with a requirement; benchmarking compares you with peers.
  • Known finds most, unknown is most realistic, partially known is the usual choice; purple team is integrated offensive and defensive work.

Practise what you just read

1. A tester is given a standard user account and nothing else, to simulate an insider or an attacker with a foothold. Which environment is this?

Select one

  1. Known environment test
  2. Unknown environment test
  3. Partially known environment
  4. Credentialed scan environment
Show answer

C. A partially known environment gives the tester some information, such as a standard account. It is the usual compromise and a good proxy for an insider. Known gives full information and finds the most per hour; unknown gives nothing and is the most realistic outsider simulation.

2. Management wants to know whether the security team would actually notice an intrusion. Which activity answers that question?

Select one

  1. A red or purple team exercise
  2. A credentialed vulnerability scan
  3. An internal compliance audit
  4. A gap analysis against ISO 27001
Show answer

A. A red team simulates an attacker and a purple team combines offensive and defensive work, so both test detection and response. A scan reports what a tool recognises, an audit asks whether controls exist, and a gap analysis compares controls with a framework.

3. An auditor testing access changes lets the IT team choose which twenty changes to examine. What is wrong with this?

Select one

  1. Twenty changes are far too few to test
  2. Samples must come from the full set
  3. Audits must test every change made
  4. IT may only choose a judgemental set
Show answer

B. The auditor must draw the sample from the complete population, whether statistically at random or judgementally by expertise. A sample the auditee picked tests only what the auditee was confident about, so the result cannot be generalised to the rest.

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.