Internal Audit
Noun · Security & Infosec
Definitions
An audit conducted by an organization's own internal audit function to evaluate whether controls, processes, and risk management practices are designed and operating effectively. In security, internal audits often test policy compliance, access management, and evidence quality before external review.
In plain English: A review done inside an organization to check whether its controls and processes are working properly.
Example: "The internal audit found that privileged access reviews were documented but not actually performed."
Related Terms
- Compliance
- SOX Compliance
- Anti-Phishing
- Data Protection
- Inspection
- IT Asset Management
- IT Audit
- IT Governance
- Multi-Layered Defense
- Owner
- Permission Audit
- Policy Enforcement
- Preventative Control
- Process Security
- Program Security
- Protection Level
- Protection Mechanism
- Regulatory Compliance
- Review
- Risk Control
- Risk Mitigation
- Risk Owner