Audit and compliance
Control
Also called: security control, internal control
A control is a specific measure put in place to achieve a security or operational outcome, such as requiring multi-factor authentication or reviewing access quarterly. Audits assess whether controls are designed appropriately and, in a Type II, whether they actually operated.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.