Courseiva
CAS-005Chapter 15 of 15Objective 4.5

Compliance, Auditing, and Legal Considerations

Compliance, auditing, and legal considerations are the rules and verification processes that protect organisations from legal liability and financial penalties. For the CAS-005 exam, you must understand how to prove that an organisation follows laws such as GDPR, HIPAA, and PCI DSS through systematic checks and documented evidence.

12 min read
Intermediate
Updated Jul 23, 2026
Reviewed by Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security

A simple way to picture Compliance, Auditing, and Legal Considerations

The Restaurant Health Inspection Analogy

Six months after opening your dream restaurant, a health inspector walks in unannounced. They check every surface, every fridge temperature, and every handwashing log. They want proof that your kitchen staff have been logging the temperature of the raw chicken every two hours for the past six months. They demand receipts showing you bought the chicken from an approved supplier. They ask to see the dishwasher's chemical test strips and the record of which staff member used them and when.

You cannot just say 'we are careful' or 'our food is safe.' You must show paper records, digital logs, and signed checklists that match exactly what the local health code requires. If your temperature logs are missing one day, the inspector writes a violation. If your supplier receipts don't match the menu, they shut you down temporarily.

The restaurant must pass three audits per year: one from the local health department, one from your food distributor for insurance purposes, and one from your bank to keep your small business loan. Each audit uses a different checklist, but they all look for the same thing: do your actual actions match your written policies and legal requirements?

In IT, compliance and auditing work exactly like this. Regulations such as GDPR or HIPAA are the health code. Auditors are the inspectors. Logs and access records are your temperature charts. The penalties can be fines, lawsuits, or even prison for executives who knowingly ignore the rules.

How It Actually Works

Compliance in IT means following a set of rules that come from laws, industry standards, or contracts. A law is a rule that a government requires everyone to follow, such as the General Data Protection Regulation (GDPR) in Europe, which forces companies to protect personal data. A standard is a voluntary guideline that an industry agrees to follow, such as the Payment Card Industry Data Security Standard (PCI DSS) for credit card processing. A contract is a written agreement between two parties, such as a cloud service provider promising not to share your customer data.

Auditing is the process of checking whether an organisation actually follows these rules. An auditor is a person or a piece of software that examines evidence: logs, configuration files, interview notes, and system outputs. The evidence proves that the organisation did what it claimed to do. If the evidence is missing, incomplete, or shows a violation, the organisation fails the audit.

There are three main types of audit:

Internal audit: performed by employees of the same organisation, usually to prepare for an external audit or to find problems early.

External audit: performed by an independent third-party company that specialises in compliance checking. Their report is trusted by regulators and customers.

Third-party audit: performed by a customer or partner who wants to verify that your organisation meets their requirements before signing a contract.

Legal considerations cover what happens when an organisation fails compliance or when a security breach occurs. Liability is the legal responsibility for damages. If a company loses customer data because it did not patch a known vulnerability, it can be sued by customers and fined by regulators. Due diligence means an organisation took reasonable steps to prevent harm, such as running security scans and training employees. Due care means the organisation acted with the same caution that a reasonable person would use in the same situation.

Reporting is the final step. After an audit, a report is created that summarises what was checked, what was found, and what must be fixed. The report goes to management, regulators, and sometimes to the public. Remediation is the process of fixing the violations found in the report. The organisation must then prove to the auditor that the fixes were applied correctly.

The relationship between these concepts is a cycle: a law or standard sets a requirement, the organisation implements controls to meet that requirement, an audit verifies that the controls work, a report documents the audit results, and remediation fixes any gaps. Then the cycle repeats, often annually or after a major change.

The compliance lifecycle: from identifying requirements to implementing controls, auditing, remediating, and reporting in a yearly cycle.

Walk-Through

1

Identify applicable regulations and standards

Determine which laws (e.g., GDPR, HIPAA), industry standards (e.g., PCI DSS, ISO 27001), and contractual requirements apply to the organisation based on the data it handles and the industry it operates in.

2

Implement controls to meet requirements

Deploy technical controls such as encryption, firewalls, and access logs, and administrative controls such as policies and training programmes to satisfy each specific requirement from step one.

3

Conduct an internal audit

Perform a self-check using a checklist of the requirements. Collect evidence such as logs, configuration files, and signed policy documents to prove each control is working.

4

Engage an external auditor

Hire an independent third party to perform a formal audit. Provide them with the internal audit evidence, and allow them to interview staff and run automated scans to verify compliance.

5

Remediate any findings

Analyse the audit report for non-compliant items. Fix each gap within a defined timeline, document the fix with evidence, and present it to the auditor for sign-off.

6

Report and maintain compliance

Produce a final compliance report (e.g., a Report on Compliance for PCI DSS). File it for regulator inspection, and continue the cycle by monitoring systems and scheduling the next audit.

What This Looks Like on the Job

Sarah works as a security analyst for a midsize e-commerce company that stores credit card numbers. The company must follow PCI DSS because it accepts Visa and Mastercard. Here is what happens in a typical compliance year:

First, Sarah reviews the PCI DSS requirements annually. There are twelve major requirements, such as 'protect stored cardholder data' and 'track and monitor all access to network resources and cardholder data.' She uses a checklist from the PCI Security Standards Council website to confirm her company meets each requirement.

Next, she performs an internal audit. She collects evidence such as:

Firewall configuration files showing that only necessary ports are open.

Encryption key management logs showing that card numbers are encrypted at rest.

Access control lists showing that only three employees have permission to see full card numbers.

Training records showing that every employee completed security awareness training last year.

She finds a problem: one employee has not completed the training. She files a ticket to the human resources team and follows up until the training is complete. She updates the internal audit report with a note that the gap was closed within 30 days.

Then an external auditor arrives from a company called Coalfire. The auditor spends three days interviewing Sarah, reviewing her evidence, and running automated scanners to check for vulnerabilities. The auditor uses a tool like Nmap to scan the network and a vulnerability scanner like Nessus to check for missing patches.

The auditor finds two issues: a server running an outdated version of OpenSSL, and a log server that does not send audit logs to the central SIEM (Security Information and Event Management) tool. Sarah documents these findings. She patches the server within 72 hours and configures the log forwarding within one week.

The external auditor produces a final report called a Report on Compliance (ROC). The ROC states that the company is compliant with PCI DSS, with two non-critical findings that were remediated. Sarah files the ROC in a secure document repository. She sends a summary to the board of directors.

Six months later, a breach occurs through an unpatched web server that was not covered by the audit scope. The company now faces legal liability because the audit scope was too narrow. Sarah's team must work with lawyers to show the ROC and the remediation records to prove they did due care. The regulator fines the company 10,000 pounds per month for failing to include that server.

How CAS-005 Actually Tests This

The CAS-005 exam tests Compliance, Auditing, and Legal Considerations in multiple choice questions with scenario-based case studies. You will see a story about a company and then be asked what the analyst should do next or which regulation applies. The exam loves to trap you on the difference between a requirement and a control, and between due care and due diligence.

Key topics that appear on the exam:

GDPR requirements: you must know that GDPR applies to any company handling EU personal data, even if the company is based outside the EU. Key rights include the right to be forgotten, right of access, and breach notification within 72 hours.

HIPAA Privacy and Security Rules: applies to healthcare providers, insurers, and their business associates. The Security Rule specifically requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).

PCI DSS: requires annual external audits for companies that process more than 6 million credit card transactions per year. It requires encryption of cardholder data, restricted access, and regular vulnerability scanning.

SOX (Sarbanes-Oxley Act): applies to publicly traded companies in the US. It requires accurate financial reporting and internal controls over financial systems. IT is involved because financial data passes through computer systems.

ISO 27001: an international standard for information security management. It is voluntary, but many companies use it to prove they have a rigorous security programme.

Trap patterns the exam uses:

Trap: they ask which regulation applies but give you a scenario with a healthcare company that does not transmit any patient data. The answer is HIPAA still applies because storing ePHI triggers the Privacy Rule, not just transmitting it.

Trap: they ask whether an external audit is required, but the scenario describes a small business that processes only 10,000 credit card transactions per year. PCI DSS requires an annual self-assessment questionnaire, not a full external audit, for low-volume processors.

Trap: they ask what 'due care' means and give you options like 'ensuring all software is patched within 24 hours' versus 'having a documented patching policy.' The correct answer is the documented policy, because due care is about having a reasonable process, not achieving perfect security.

Key definitions to memorise:

Due diligence: the process of investigating and verifying that a third party meets security requirements before signing a contract.

Due care: the ongoing practice of taking reasonable precautions to protect assets, such as running regular patching cycles.

Audit scope: the boundaries of what systems, processes, and locations are examined during an audit.

Evidence: logs, documents, and screenshots that prove a control is in place and effective.

Remediation: the act of fixing a compliance gap found in an audit.

Regulatory liability: legal consequences for failing to meet a law's requirements, such as fines or imprisonment.

Expect three to five questions on this domain. The questions are often situational, requiring you to select the most appropriate action from a list.

Key Takeaways

Compliance is not optional; laws such as GDPR, HIPAA, and PCI DSS apply to any organisation handling the regulated data, regardless of size or location.

Auditing is a sampling process that checks evidence against requirements; passing an audit does not guarantee full security, only that the checked items met the standard at that time.

Due diligence happens before a contract to investigate a third party's security; due care happens after the contract to maintain protection over time.

Regulatory liability can include fines, lawsuits, and prison for executives who knowingly ignore compliance requirements.

Audit scope defines exactly which systems, processes, and locations are examined; anything outside scope is not checked and may still fail compliance.

Remediation is the process of fixing audit findings, and the organisation must prove the fix was applied correctly before the audit can close.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Due Diligence

Occurs before a contract or acquisition

Focuses on investigating a third party's security posture

Example: reviewing a cloud provider's SOC 2 report before signing a contract

Due Care

Occurs after a contract is signed

Focuses on ongoing protection of assets

Example: running quarterly vulnerability scans on systems managed by that cloud provider

Internal Audit

Performed by employees of the organisation

Purpose is to find gaps before external review

Results are typically not shared outside the organisation

External Audit

Performed by an independent third party

Purpose is to provide an unbiased compliance opinion

Results are shared with regulators, customers, and insurers

GDPR

Applies to any organisation handling EU personal data

Fines up to 4% of annual global turnover or 20 million euros

Includes the right to be forgotten and breach notification within 72 hours

HIPAA

Applies to US healthcare entities and their business associates

Fines up to $1.5 million per violation category per year

Focuses on privacy and security of electronic protected health information (ePHI)

Watch Out for These

Mistake

Compliance is optional for small businesses because regulators only go after big companies.

Correct

Compliance with laws such as GDPR and HIPAA applies to any organisation, regardless of size, that handles the regulated data. Fines and enforcement actions have been issued against small clinics and little startups.

Beginners often think that only large corporations are at risk because they hear about big fines in the news, but regulators actively pursue small businesses to set an example.

Mistake

If a company has never been audited, it automatically passes compliance because no one checked.

Correct

Compliance is about whether you actually meet the requirements, not whether you have been caught. An audit verifies compliance, but failing to be audited does not mean you are compliant.

People conflate 'being found compliant' with 'being compliant.' This misconception arises because auditing seems like the main event, but the underlying rules exist independently.

Mistake

Auditors always find every problem, so if you pass an external audit, you are completely secure.

Correct

An audit checks only a sample of systems and processes within a defined scope. It can miss problems outside that scope or problems that occur after the audit date. Passing an audit indicates minimal risk for the audited period, not total security.

Beginners view audits as a comprehensive rubber stamp, similar to a school exam, rather than a limited check based on sampling and scope.

Mistake

Due diligence and due care are the same thing, just different wording.

Correct

Due diligence is the initial investigation before a contract or acquisition. Due care is the ongoing maintenance and protection after the contract is signed. They are separate stages with different requirements.

The words sound similar, and many study guides present them together, causing confusion. Beginners memorise the term without understanding the timeline difference.

Mistake

PCI DSS compliance is only about encryption of credit card numbers.

Correct

PCI DSS has twelve requirements covering firewalls, access control, monitoring, testing, policy, and vendor management. Encryption is just one part of the standard.

Media coverage often highlights encryption stories, so beginners assume that is the sole focus, missing the many other administrative and physical controls.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between a law and a standard in compliance?

A law is a binding rule enforced by a government with penalties for non-compliance, such as GDPR. A standard is a voluntary set of guidelines developed by an industry body, such as ISO 27001, which organisations may choose to follow to prove their security posture.

Do I need an external audit for PCI DSS if I only process 10,000 card transactions per year?

No. The PCI DSS requirement for an external audit applies only to merchants processing over 6 million transactions annually. Lower-volume merchants can complete a self-assessment questionnaire (SAQ) and undergo a quarterly network scan by an Approved Scanning Vendor (ASV).

What happens if my organisation fails a compliance audit?

Failure typically results in a remediation plan where you must fix the gaps within a specific timeframe. If you fail to remediate, you may face fines, loss of certification (e.g., unable to process credit cards), increased scrutiny, or legal action from regulators or customers.

Can a compliance audit be done entirely by software?

Software can assist by scanning configurations and collecting logs, but a full audit usually requires human judgement to interpret evidence and interview staff. Some audits, such as SOC 2 Type II, rely heavily on manual review of policies and evidence.

Is HIPAA only for hospitals and doctors?

No. HIPAA applies to all 'covered entities' (healthcare providers, health insurers, and healthcare clearinghouses) and their 'business associates' (any vendor that handles protected health information, such as cloud storage providers or billing companies).

What is a Report on Compliance (ROC) in PCI DSS?

A ROC is a formal document produced by a Qualified Security Assessor (QSA) after an external audit. It details the audit scope, controls tested, findings, and overall compliance status. It must be submitted to the acquiring bank and the payment card networks.

Terms Worth Knowing

Keep going

You've finished Compliance, Auditing, and Legal Considerations. Continue through the CAS-005 study guide to build a complete picture of the exam.

Done with this chapter?