Skip to content

Audit Criteria

Definition

The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the organization's own security policies. Criteria are defined in the planning phase, not during fieldwork.

Definition
Standards against which audit evidence is compared
Common examples
ISO/IEC 27001, NIST SP 800-53, PCI-DSS
Also includes
The organization's own security policies
Set during
Planning phase, not fieldwork

Common questions

Why must audit criteria be fixed during planning rather than during fieldwork?+

Choosing the criteria after evidence is already gathered lets the auditor pick standards that flatter or fail the findings, undermining objectivity. Setting criteria up front also tells the auditee in advance what they are being measured against.

What happens when audit criteria conflict, such as an internal policy that is stricter than a regulatory standard?+

The auditor generally tests against the stricter applicable requirement, since meeting the more lenient standard does not demonstrate compliance with the organisation's own binding policy, and both gaps are typically reported separately so the reader knows which criterion was failed.

Related terms

Audit Objectives
The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
Audit Plan
The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
Audit Scope
The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
Auditee
The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
Scope Creep
The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.