National Security Auditing Criteria
The first important goal of the national security auditing criteria is to harmonise official measures: when an authority conducts an audit in a company or an organisation to verify their security level. The authorities may complement the audit, when necessary, with a security assessment and, in some cases, with consulting. These measures do not belong, however, to the actual auditing. In this 2011 version of the security auditing criteria the focus is solely on security.
The second important goal is to support companies and other organisations as well as authorities with their service providers and subcontractors to work on their own internal security. This is why the criteria contain recommendations that are separate and outside of the official requirements; it is hoped that useful security practices will be chosen and applied, thus progressing to the level of official requirements.







