Our library of Internal Controls includes testing methodologies and link to Policies and Compliance Frameworks.
Name | Objective | Testing Methodology | Success Criteria | Policies | |
|---|---|---|---|---|---|
| To ensure that the organization's Information Security Policy and its topic-specific policies are ... | Evidence: Obtain the latest version of the Information Security Policy and all topic-specific polici... | All Information Security and topic-specific policies are current, reflect organizational needs, and ... | 1 | ||
| To ensure that information security roles and responsibilities are properly defined, allocated, and ... | Evidence: Collect the organizational structure and roles documentation. Gather records of informatio... | All roles within the organization have clearly defined and documented information security responsib... | 1 | ||
| To ensure that management and staff comply with information security policies, and management suppor... | Evidence: Management Communications: Collect recent communications (e.g., emails, memos) from manage... | Management Support Verification: Clear evidence of management's active support and endorsement of in... | 1 | ||
| Ensure timely and appropriate contact with relevant authorities and adherence to regulatory requirem... | Evidence: Obtain a record of all reported information security incidents from the Incident Managemen... | All necessary contacts with authorities in response to information security incidents are made in ac... | 1 | ||
| To ensure the organization actively participates in and benefits from engagement with relevant speci... | Evidence: Obtain a list of special interest groups and security forums in which the organization is ... | Active and relevant participation in identified special interest groups and forums. Regular and effe... | 1 | ||
| To ensure comprehensive collection, analysis, and utilization of threat intelligence across strategi... | Evidence: Collect documentation on the threat intelligence sources and methods used (internal and ex... | Threat intelligence sources and methods comprehensively cover strategic, tactical, and operational a... | 1 | ||
| Ensure that information security is integrated into all project management processes, from initiatio... | Evidence: Obtain a list of current and recent projects managed by the organization. Gather project m... | All projects demonstrate thorough integration of information security measures throughout their life... | 1 | ||
| Ensure a comprehensive and up-to-date inventory of all organizational assets, including detailed inf... | Evidence: Obtain the current Inventory of Information and Associated Assets document. Gather ownersh... | The asset inventory is complete, accurate, and includes all required details such as network and har... | 1 | ||
| To ensure that all individuals accessing or using the organization's information and associated asse... | Evidence: Obtain the current Inventory of Information and Associated Assets document. Gather compreh... | All users comply with the acceptable use standards as per the Acceptable Use Policy. Effective monit... | 1 | ||
| To ensure that information within the organization is classified and labeled correctly according to ... | Evidence: Obtain the latest version of the organization's information classification policy and labe... | All examined information is classified and labeled correctly in accordance with the organization's i... | 1 |