For the engagement owner. Define the decision first. Different assessment methods produce different kinds of evidence.
Start with the conclusion you need
An audit and a penetration test can both reveal security weaknesses, but they do not answer identical questions. A control audit compares evidence with agreed criteria. A penetration test attempts to cross selected security boundaries under authorised conditions. Before requesting either, write the decision the report should support. A board may need to understand recurring access-governance failures. An engineering owner may need to know whether a particular authorisation boundary can be bypassed before release. The right procedure follows from that question.
Avoid selecting a service solely because a questionnaire uses the word “audit”. Ask what the recipient expects to see: control coverage, operating records, technical exploitation evidence, a formal opinion or a certificate. Those requirements can change the scope, assessor eligibility and cost substantially.
Read diagram text
- Audit
- Does the control meet agreed criteria?
- Pentest
- Can the selected boundary be crossed?
- Decision
- Choose evidence appropriate to the question.
What a control review can establish
Consider privileged access. An assessor can compare role assignments with approvals, examine expiry settings and sample periodic reviews. A finding may state that four selected assignments lacked a documented expiry or current approval. That is evidence about the assessed control. It does not prove those accounts were compromised or that an attacker obtained administrative access. The report should identify the population, selected records, evidence dates and limitations so readers can distinguish an observation from an inference.

What a penetration test adds
An authorised test can explore whether a weakness produces an exploitable path, subject to rules of engagement and safeguards. This can help demonstrate consequences that a documentary review cannot establish. However, a successful test of one path does not establish whether every access review operated during the previous quarter. Similarly, failure to exploit a sampled system is not evidence that all related governance controls are effective. Neither method should borrow the other’s conclusions without supporting work.
Read diagram text
- Configuration
- Current implementation evidence.
- Operating sample
- Selected records over an agreed period.
- Exploitation
- Observed consequence in authorised conditions.
Combine the work without blurring it
A combined engagement needs separate objectives, procedures and permissions. Use the audit to identify control expectations and operating gaps. Use targeted technical validation where the risk justifies it. Keep exploitation targets, timing, stop conditions and cleanup arrangements explicit. Report the source of each conclusion: document examination, configuration review, interview, sampled transaction or authorised technical validation. Management should be able to trace a recommendation to the actual procedure rather than a generic security label.
Read diagram text
- Objectives
- Separate the assurance questions.
- Permissions
- Approve active work explicitly.
- Reporting
- Identify the procedure behind each finding.
Turn findings into the right next step
An isolated configuration issue may need correction and verification. A recurring failure may also require process ownership, enforced approval or population reconciliation. Decide which evidence will demonstrate closure before assigning the task. If active testing was excluded from the audit, do not silently add it during follow-up. Agree the new scope and permission first. Related guidance from the same Atlant Security portfolio: defining a penetration-testing scope and assigning operational security responsibilities. Use these when an audit recommendation needs a separately scoped technical test or a clearly owned operational improvement.
Prepare a useful first conversation
Use the audit scoping brief builder to record your objectives, control areas, platforms and evidence period. Review its draft before sending it to Atlant Security through the contact form. You can attach an NDA or RFP for human review. Begin with non-sensitive context and approximate counts; confidential control evidence belongs in an agreed secure channel. The brief does not authorise system access, accept an NDA or establish an assurance opinion.
Read diagram text
- Correct
- Change the faulty control.
- Verify
- Inspect implementation and new evidence.
- Sustain
- Assign ownership and recurring review.
Primary sources
- Atlant Security IT security audit
- NIST Cybersecurity Framework
- NIST SP 800-53A assessment methodology
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.
Published by Atlant Security. Sources, editorial policy and corrections.

