AUDIT: INDEPENDENT TARGET-PERFORMANCE COMPARISON
An audit is a test, similar to the revision of a passenger elevator, which is regularly checked to ensure safety and functionality. Here, there are clear technical specifications that must be met and are checked step by step by the technician.
In the area of IT, this is somewhat more complex, but the procedure corresponds to the classic target/performance comparison. Both internal specifications and external standards are used, which represent the “state of the art” in the respective test area. An audit typically takes place in two steps. In the first step, it is checked whether the planned measures (specifications) are suitable for controlling the respective risk. This is referred to as “design effectiveness” and in the second step the “operational effectiveness”, i.e. the actual implementation, is checked to ensure that the planned measures are actually applied or implemented in practice.