Cybersecurity Audit
Plain-language explanation
Under California's CCPA regulations, a cybersecurity audit is the annual audit required for a business whose processing of consumers' personal information presents significant risk to consumers' security under the applicable regulation.
Why It Matters
The California requirement introduces defined scope, independence, evidence, reporting, and certification expectations for businesses that meet the regulatory threshold.
In Practice
The California requirement should be distinguished from generic uses of the phrase cybersecurity audit. Applicability, audit content, auditor independence, reporting, and certification are governed by the CCPA regulations.