Audit Objectives
Definition
The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the requirements of ISO 27001 Annex A.5.15? Objectives determine which evidence is relevant and what a finding means.
- Definition
- The questions the audit is designed to answer
- Stated in terms of
- Control criteria
- Example
- Do access controls satisfy ISO 27001 Annex A.5.15?
- Determines
- Which evidence is relevant and what a finding means
Common questions
How do audit objectives differ from audit scope?+
Scope defines the boundary of what is included, such as which systems, locations, or time period. Objectives define the questions being asked within that boundary, such as whether a specific control satisfies a specific requirement, and it is the objectives that give a finding its meaning.
What happens if audit objectives are vague, such as 'assess security'?+
Vague objectives leave the evidence collection and conclusions open to inconsistent interpretation between auditors, make findings hard to benchmark against a defined criterion, and can allow scope creep or gaps in coverage that a clearly stated objective would have prevented.
Related terms
- Audit Criteria
- The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
- Audit Plan
- The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
- Audit Scope
- The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
- Auditee
- The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...