What an auditor, or Sekit's evidence engine, asks for.
Internal audit report
The output of the internal reviews the company runs on its own security controls, with findings and improvement actions.
From the Sekit evidence catalog
In practice
Audit testing that touches live systems needs the same care as any other change to production: a defined scope agreed in advance, a qualified tester, and safeguards that keep the systems being tested available throughout. Auditors want to see penetration tests scoped deliberately rather than run against production with no isolation plan, and every finding tracked to closure or formal acceptance rather than left in a report nobody revisits. Automating evidence collection where possible reduces the risk that the audit activity itself becomes disruptive, since pulling data from system logs is safer than an auditor querying a live production database directly.
Common gaps
A penetration test was run against production with no documented scoping agreement, so the tester's access and test windows were never formally bounded.
Findings from the last internal audit report remain open with no owner assigned for remediation and no target date set when they were logged.
Evidence for the audit was collected by manually querying the production database rather than through the automated collection tooling already available.
Questions your auditor will ask
How do you make sure a penetration test doesn't disrupt production operations?
The technical environment is prepared with isolated targets where needed and safeguards that keep production available, and the test is scoped deliberately with a qualified tester before it starts.
Are audit findings tracked to resolution?
Every finding is tracked to closure or formal acceptance rather than left open, recorded in the internal audit report.
How is evidence collected for internal audits without disrupting live systems?
Audit evidence collection is automated where possible, pulling from system data instead of manual screenshots or direct queries against live systems.
Where regulation demands it
NIS2 art. 7.2 requires security assessments and testing of the organization's systems, and ENS org.4 requires a formal authorization process before such testing activity can start.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.