01Technical Audits vs. Compliance Audits
Compliance audits verify whether a management system meets defined requirements – for example internal audits under ISO/IEC 27001 (Clause 9.2) or certification and surveillance audits by accredited bodies. Technical security audits operate one level deeper: they measure the actual state of specific systems – configurations, permissions, rule sets – against a technical benchmark such as a CIS Benchmark or an IT-Grundschutz module. The two perspectives complement each other: the compliance audit demonstrates a working process, the technical audit the actual level of hardening. A certificate alone therefore says little about the configuration quality of individual systems – and vice versa.
02Typical Formats: AD, M365, Firewall, Architecture
In practice, focused formats have become established. An Active Directory security audit examines permission and delegation structures, privileged accounts and groups, trust relationships and the hardening of domain controllers – as the central identity system, AD is a prime attack target. An M365/cloud configuration audit assesses tenant settings, identity and access policies, logging and external sharing against catalogs such as the CIS Microsoft 365 Foundations Benchmark. A firewall rule base review checks the rule set for overly broad permissions, orphaned and redundant rules as well as the change process; an architecture review takes a broader view of network segmentation, zoning concepts and administrative access paths.
03Benchmarks I: CIS Benchmarks and Vendor Baselines
The CIS Benchmarks published by the Center for Internet Security are consensus-based, vendor-neutral configuration guidelines – more than 100 guides for over 25 product families, from operating systems and cloud platforms to network components. Each recommendation specifies the secure target value along with audit and remediation steps; most benchmarks are divided into two profiles: Level 1 for baseline hardening with minimal operational impact, Level 2 for higher protection needs. In addition, vendors maintain their own baselines: Microsoft publishes continuously updated Security Baselines for Windows, Windows Server and other products, which can be compared against existing group policies using the Security Compliance Toolkit. For audits, one rule applies: benchmark, version and profile must be stated explicitly in the report – otherwise the results are not reproducible.
04Benchmarks II: BSI IT-Grundschutz Modules
The BSI's IT-Grundschutz Compendium (Edition 2023) contains 111 modules across ten layers and defines basic and standard requirements per module as well as requirements for increased protection needs. Particularly relevant for technical audits are system-level modules such as APP.2.2 Active Directory Domain Services – fully revised for the 2023 edition – or NET.3.2 Firewall. Compared with the detailed configuration settings of the CIS Benchmarks, IT-Grundschutz modules are more abstract, but they also cover organizational and operational aspects and can be linked directly to an ISMS based on the BSI standards or ISO/IEC 27001. The BSI is currently evolving IT-Grundschutz into a fully process-oriented, digital body of rules whose requirements can also be evaluated by machine; according to the BSI, the Compendium remains applicable during the multi-year transition period.
05Approach and Reporting
Methodologically, security audits follow ISO 19011, the guideline for auditing management systems: defined audit objectives and criteria, a planned audit program and evidence-based findings. The typical process: scoping (systems, benchmark, protection needs), data collection via configuration exports, read-only tool access, interviews and document review, followed by comparison against the benchmark and an assessment of each deviation in context – not every deviation is a risk if compensating controls are in place. The report separates a management summary with the overall picture and top risks from the technical section, in which each finding is documented with evidence, risk assessment and a concrete recommendation. What matters most is prioritization by actual risk rather than by mere checklist compliance.
06A Sensible Audit Cycle
There is no universally binding audit rhythm for technical audits – the cycle should be defined on a risk basis. A proven practice is to audit critical systems such as Active Directory, central firewalls and cloud tenants annually, and additionally after significant changes (migrations, new platforms, mergers). At the compliance level, ISO/IEC 27001 requires internal audits at planned intervals (Clause 9.2); certificates run on a three-year cycle with annual surveillance audits. Since CIS Benchmarks and vendor baselines are updated continuously and configurations drift during operation, many organizations complement point-in-time audits with continuous, tool-based configuration monitoring.