Control assurance and security testing procedure
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
For control owners and assurance reviewers to plan proportionate tests, define populations and criteria, record limitations, assess results and assign follow-up.
- Document type
- Procedure
- Format
- DOCX
- Pages
- 9
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-15
- Category
- Information security
- Licence
- Internal use
Description
For control owners and assurance reviewers to plan proportionate tests, define populations and criteria, record limitations, assess results and assign follow-up.
Contents
- Document control
- Purpose of this procedure
- Define the assurance decision
- Select the assurance method for the control state
- Independence and operator input
- Establish the control population
- Select a sample for the intended inference
- Combine assessment methods
- Separate the four control questions
- Authorize active security testing
- Observe the approved testing boundary
- Record observed conditions and limits
- Owner response and finding integrity
- Retest the implemented change
- Plan the next assurance cycle
- Rehearse control review and technical testing
Version history
- v1.015/09/2026