A systematic process is used for both assessments and audits.  Both are applied as a management tool as oppose to a technical-review tool.  Outcome of both is a report. They both often use similar methods and techniques to perform their appraisal.

Note:  This article focuses on

some of the similarities and distinguishing factors between

the terms assessment and audit when expressed in the software industry.

Auditor/assessor style (e.g., impartial, collaborative) is dependent on the appraisal-customer (internal vs external) and, the appraisal's purpose and potential impact/risks.

Audit/assessment duration and type of interaction (group vs 1-on-1) depends on purpose, scope and type of appraisal.

Note:  The differences shown above are typical -- self-triggered assessments/audits may be

any combination of that shown or special cases such as that for dry-run audits.

Share
Related Documents
  1. Security Focus : Newsletter Archive (1750)
  2. [Ebook] Exploiting Software How to Break Code (3457)
  3. [Ebook] Practical Unix & Internet Security, 3rd Edition (4412)
  4. [Ebook] Internet Security: A Jumpstart for Systems Administrators and IT Managers (3711)
  5. What is a Security stress testing? (2118)
  6. Software Quality Assrance Traceability Audit (1699)
  7. Project Audit Checklist (3463)
  8. Software Product Audit (1249)
  9. [Free] Belarc Advisor : Personal PC Audit for Test Environment (1429)
  10. Quality Control Audit Process (1473)
  11. The use of test plans as a quality instrument (1056)
  12. [Free] Watcher : testing tool and passive vulnerability scanner (2221)
  13. What is the difference between Inspection and Audit ? (1705)
  14. [Free] skipfish : web application security reconnaissance tool. (2564)
  15. [Video] seNetsparker - A free web app security testing tool (996)
  16. Creating a Web security testing policy (1963)
  17. Building web application security into your development process (1654)
  18. Security Testing for Web Application (2147)
  19. [Ebook] Security Engineering: A Guide to Building Dependable Distributed Systems (5492)
  20. Secure Software Advisory for security testing (1107)