Instiq

5Control evaluation

Practice questions →Glossary →
  • 5.1Evaluating planning and development controls

    Covers how a systems auditor evaluates the design and operating effectiveness of preventive and detective controls in project management, requirements definition, testing, migration, and production release, and diagnoses design deficiencies such as a lack of segregation of duties between development and operations.

  • 5.2Evaluating operations and maintenance controls

    Covers how an auditor evaluates the design and operating effectiveness of controls over job management, change management, configuration management, incident management, and backups, and diagnoses deficiencies such as uncontrolled emergency changes.

  • 5.3Information security and business continuity controls

    Covers how an auditor evaluates the design and operating effectiveness of security controls such as access management, encryption, and log monitoring, together with BCP and disaster-recovery controls, and diagnoses deficiencies such as deviations from least privilege and an untested BCP.

  • 5.4Evaluating outsourcing and cloud controls

    Covers how an auditor gains assurance over outsourced and cloud services they cannot directly access—through vendor management, subcontracting, SLAs, the right to audit (audit response), and the division of responsibility—including the use of a third-party assurance report (SOC report).