3.1 Audit standards
According to ISO/IEC 18028-3, IT network security - Part 3: Security communications between networks using security gateways, audit is a “formal inquiry, formal examination, or verification of facts against expectations, for compliance and conformity”. Audit [12] is a “formal inspection and verification to check whether a Standard or set of Guidelines is being followed, that Re-cords are accurate, or that Efficiency and Effectiveness targets are being met. An Audit may be carried out by internal or external groups.”
ISO reserved a series of standards, ISO 27000, for information security matters