When Evidence Exists but the Security Control Is Still Ineffective
A Practical Auditor’s Guide to Moving Beyond the Checkbox In information security audits, one of the most common mistakes is to equate the existence of evidence with the effectiveness of a control. An organization may provide a policy, system screenshot, log extract, report, approval record, or compliance certificate. At first glance, the evidence may appear sufficient. But an important audit question remains: Does the evidence actually demonstrate that the control is appropriately designed, implemented, operating consistently, and achieving its intended security objective? This distinction is particularly important in BFSI, critical applications, regulated environments, ISO/IEC 27001 implementations, and formal Information Security Management Systems (ISMS). A control can have documentation and supporting evidence and still fail to provide the intended level of protection. 1. Evidence Is Not the Same as Control Effectiveness Consider a simple control requirement: “Privilege...