Instiq
Chapter 5 · Control evaluation·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.3Information security and business continuity controls

Key points

Covers how an auditor evaluates the design and operating effectiveness of security controls such as access management, encryption, and log monitoring, together with BCP and disaster-recovery controls, and diagnoses deficiencies such as deviations from least privilege and an untested BCP.

Security controls that protect the confidentiality, integrity, and availability of information systems, and business-continuity controls that keep the business running through disasters and failures, are areas where the auditor rigorously evaluates not only whether they are designed but also whether they are effective. The focus is on whether access rights are narrowed to the minimum necessary for the job, whether encryption and log monitoring function rather than existing only in form, and whether a BCP not only exists as a document but has its effectiveness verified through drills. The auditor views security controls in terms of prevention, detection, and correction, and evaluates availability against recovery objectives.

5.3.1Security controls (access management, encryption, log monitoring)

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.