![]() |
Internal Audit, Consulting, and IT Security Solutions | ||||
| Services and Solutions | About Us | Contact Us | Resources | Careers | |
|
Independent diagnostic tests include penetration tests, audits, and assessments. Independent performance of security testing provides credibility to the test results. To be considered independent, testing personnel should not be responsible for the design, installation, maintenance, and operation of the tested system, as well as the policies and procedures that guide its operation. The reports generated from the tests should be prepared by individuals who also are independent of the design, installation, maintenance, and operation of the tested system. Penetration tests, audits, and assessments can use the same set of tools in their methodologies. The nature of the tests, however, is decidedly different. Additionally, the definitions of penetration test and assessment, in particular, are not universally held and have changed over time.
Compass Group Consultants information security services are fully compliant with FFIEC regulatory guidance, as well as the independence requirements recently outlined in the Sarbanes-Oxley Act and by the Securities and Exchange Commission. |