Skip to content

Audit Evidence

Definition

Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it), appropriate (relevant and reliable), and obtained through a defined procedure. A scan report satisfies these conditions when it is authenticated, scoped, and current.

Definition
Information used to draw conclusions about a control
Must be
Sufficient and appropriate
Appropriate means
Relevant and reliable
Example accepted
An authenticated, scoped, current scan report

Common questions

What makes a vulnerability scan report sufficient versus appropriate as audit evidence?+

Sufficiency refers to quantity, having enough scope and coverage across the systems in question, while appropriateness refers to quality, meaning the scan was run with valid credentials, covered the right assets, and reflects a current state rather than a stale or unscoped result.

Why can two pieces of audit evidence support the same finding with different weight?+

Evidence obtained directly by the auditor, such as an authenticated scan the auditor observed running, is generally weighted more heavily than evidence supplied by the auditee, such as a self-reported remediation summary, because the auditor has less assurance over its accuracy.

Related terms

Approved Scanning Vendor (ASV)
An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates...
CVSS (Common Vulnerability Scoring System)
An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10...
Remediation Prioritisation
The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating...
Risk Acceptance
A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
Vulnerability Assessment
A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.