External audits typically focus on verifying compliance with standards, policies, or regulatory requirements and usually assess whether controls are in place and functioning as required.
The effectiveness and efficiency of the ISMS (Information Security Management System) are generally more in the scope of internal audits or management reviews rather than external audits.
External audits are conducted in a planned and timely manner (A) and have no advisory role within the organization (C), as auditors must remain independent and objective.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
hayalou
1 week ago