Posts

Showing posts with the label Controls

How to Test an Information Security Control: Control → Evidence → Test → Conclusion

Disclosure: This post contains affiliate links. If you click through and make a purchase, I may receive a small commission at no extra cost to you. As an Amazon Associate, I earn from qualifying purchases.     A Practical Auditor’s Approach to Determining Whether a Control Really Works "A control should not be considered effective simply because evidence exists. The real test is whether the evidence demonstrates that the control operated as intended and addressed the relevant risk ." An information security control can look perfectly acceptable on paper. There may be a policy. There may be a procedure. There may be screenshots. There may be reports. There may even be management approval. But when an auditor asks a more fundamental question— “How did you determine that this control actually worked?” —the assessment becomes much more interesting. Testing a control is not simply about collecting evidence and checking whether a document exists. A meaningful control ...