Compliance audits verify whether a management system meets defined requirements – for example internal audits under ISO/IEC 27001 (Clause 9.2) or certification and surveillance audits by accredited bodies. Technical security audits operate one level deeper: they measure the actual state of specific systems – configurations, permissions, rule sets – against a technical benchmark such as a CIS Benchmark or an IT-Grundschutz module. The two perspectives complement each other: the compliance audit demonstrates a working process, the technical audit the actual level of hardening. A certificate alone therefore says little about the configuration quality of individual systems – and vice versa.
IT Security Audits with a Clear Benchmark
How technical security audits and compliance audits work together – from Active Directory to M365, firewalls and architecture, assessed against CIS Benchmarks, vendor baselines and BSI IT-Grundschutz.
3established reference frameworks: CIS Benchmarks, vendor baselines, BSI IT-Grundschutz
100+CIS Benchmark guides for over 25 product families
111modules in the IT-Grundschutz Compendium (Edition 2023), across ten layers
2profiles in most CIS Benchmarks: Level 1 baseline hardening, Level 2 higher protection needs
An IT security audit answers a simple question with a rigorous methodology: does the actual state of your systems match what policies, standards and your own security concept prescribe? Unlike a penetration test, which demonstrates the exploitability of individual vulnerabilities, an audit systematically assesses configurations, permissions and architecture decisions against a defined benchmark. Three reference frameworks have become established for this purpose: the CIS Benchmarks, vendor security baselines and the modules of the BSI IT-Grundschutz Compendium. This article puts technical audits and compliance audits into context, describes typical formats and approaches, and offers guidance on a sensible audit cycle.
The Essentials at a Glance
Six topic blocks — tap to expand.
Typical Audit Formats
Four focused formats from practice – tap a tab for the audit focus.
- Examines permission and delegation structures, privileged accounts and groups, trust relationships and the hardening of domain controllers.
- As the central identity system, AD is a prime attack target.
Privileged accountsDelegationTrust relationshipsDomain controllers
- Assesses tenant settings, identity and access policies, logging and external sharing.
- Measured against catalogs such as the CIS Microsoft 365 Foundations Benchmark.
Tenant settingsAccess policiesLoggingExternal sharing
- Checks the rule set for overly broad permissions as well as orphaned and redundant rules.
- Also examines the change process.
Rule baseOverly broad permissionsOrphaned rulesRedundant rulesChange process
- Takes a broader view of network segmentation, zoning concepts and administrative access paths.
Network segmentationZoning conceptsAdministrative access paths
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
CIS Benchmarks
More than 100 consensus-based, vendor-neutral configuration guides with Level 1/Level 2 profiles serving as the assessment basis for technical audits; continuously updated.
IT-Grundschutz-Kompendium, Edition 2023
111 modules across ten layers, including APP.2.2 Active Directory Domain Services and NET.3.2 Firewall as requirement catalogs for system-level audits.
Guidelines on Firewalls and Firewall Policy (NIST SP 800-41 Rev. 1)
Foundational publication on firewall technologies and firewall policies with recommendations on selection, configuration, testing and operation; status final.
Security baseline for Windows Server 2025, version 2602
Example of continuously maintained vendor baselines that can be compared against existing group policies using the Security Compliance Toolkit.
DIN EN ISO 19011:2018 – Leitfaden zur Auditierung von Managementsystemen
Methodological framework for audit principles, audit programs and auditor competence, on which technical security audits also rely.
Related Services
Want to know where your systems really stand?
In a no-obligation initial consultation, we determine which audit format and which benchmark fit your environment.