How to Test an Information Security Control: Control → Evidence → Test → Conclusion
A Practical Auditor’s Approach to Determining Whether a Control Really Works "A control should not be considered effective simply because evidence exists. The real test is whether the evidence demonstrates that the control operated as intended and addressed the relevant risk." An information security control can look perfectly acceptable on paper. There may be a policy. There may be a procedure. There may be screenshots. There may be reports. There may even be management approval. But when an auditor asks a more fundamental question— “How did you determine that this control actually worked?” —the assessment becomes much more interesting. Testing a control is not simply about collecting evidence and checking whether a document exists. A meaningful control test should establish a logical connection between: Risk → Control → Objective → Evidence → Test → Result → Conclusion This article presents a practical approach that auditors, GRC professionals and control ow...