Instiq
Chapter 5 · Control evaluation·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.3Information security and business continuity controls

Key points

Covers how an auditor evaluates the design and operating effectiveness of security controls such as access management, encryption, and log monitoring, together with BCP and disaster-recovery controls, and diagnoses deficiencies such as deviations from least privilege and an untested BCP.

Security controls that protect the confidentiality, integrity, and availability of information systems, and business-continuity controls that keep the business running through disasters and failures, are areas where the auditor rigorously evaluates not only whether they are designed but also whether they are effective. The focus is on whether access rights are narrowed to the minimum necessary for the job, whether encryption and log monitoring function rather than existing only in form, and whether a BCP not only exists as a document but has its effectiveness verified through drills. The auditor views security controls in terms of prevention, detection, and correction, and evaluates availability against recovery objectives.

5.3.1Security controls (access management, encryption, log monitoring)

  • Access management is a preventive control based on the principle of least privilege, granting users only the minimum rights necessary for their jobs. The auditor reconciles the rights list against actual job duties, evaluating whether rights of departed or transferred staff remain and whether privileged IDs are distributed more widely than necessary. Leaving excessive rights in place is a design or operating deficiency.
  • Encryption is a preventive control that protects the confidentiality of stored and transmitted data. The auditor evaluates whether encryption's scope and key management (storage, rotation, and segregation of keys) are appropriate. Log monitoring is a detective control that captures and monitors records of access and operations to detect fraud or anomalies after the fact. If logs are merely captured but no one monitors or analyzes them, the detective control is effectively non-functional—an operating deficiency.

5.3.2Business continuity (BCP, disaster recovery) controls

  • A BCP (business continuity plan) keeps critical operations running or recovers them quickly through disasters or major failures. It sets an RTO (recovery time objective) and RPO (recovery point objective) and provides alternate facilities, data-recovery procedures, and a communication chain. The auditor evaluates whether the plan is consistent with the priority of critical operations and the recovery objectives.
  • What the auditor most emphasizes in BCP controls is verification of effectiveness through drills. However detailed the plan, if failover/recovery drills are not actually conducted to confirm that the RTO/RPO can be met, it will not function when it matters. A state where the document is prepared but there is no drill record is flagged as an operating deficiency where the corrective control (recovering from a failure that has occurred) lacks effectiveness.
Exam point

Most-tested: "access management follows least privilege; excessive rights are detected by reconciling the rights list against job duties", "log monitoring functions as a detective control only when logs are monitored and analyzed, not merely captured", and "a BCP verifies RTO/RPO attainment through drills, not just a document." Remember that availability controls are evaluated down to the effectiveness (drills) of the corrective control.

Suppose a systems auditor is evaluating the security and business-continuity controls of a financial institution's core banking system. First, for access management, the auditor obtains the list of privileged IDs (system-administrator rights) granted and reconciles each ID holder against their actual job duties. This reveals that a privileged ID belonging to a former operator who has already transferred to another department remains without being disabled. The auditor diagnoses this as a deviation from the principle of least privilege—an operating deficiency—where rights no longer needed for the job were left in place, and recommends the preventive control of rigorously performing a rights review and immediate revocation upon transfer or departure. Next, for log monitoring, to corroborate the explanation that "operation logs for privileged IDs are captured," the auditor confirms whether the logs are actually reviewed periodically and whether anomalous operations raise alerts, and finds that the logs merely accumulate with no one analyzing them. The auditor flags this as an operating deficiency where the detective control is effectively non-functional, and recommends periodic log review and an escalation mechanism for deviations. Finally, for the BCP, the auditor confirms a fine plan document setting an RTO (e.g., recover core banking within four hours), but discovers that no actual failover/recovery drill has been conducted in the past two years. The auditor diagnoses that even though the on-paper design is sound, as long as it is not verified through a drill that the RTO can be met, the effectiveness of the corrective control is not assured—an operating deficiency, and recommends conducting periodic recovery drills and reflecting issues found in the drills back into the BCP. In this way, the core of the auditor's judgment in evaluating security and business-continuity controls is not to look only at the design of rules and plans, but to confirm trails of "whether it actually functions"—reconciling rights, actually monitoring logs, and conducting drills.

ControlControl typeAuditor's effectiveness check
Access management (least privilege)PreventiveReconcile rights list against duties; confirm revocation for transfers/departures
Log monitoringDetectiveConfirm not just capture but periodic review and anomaly alerting
BCP / disaster recoveryCorrectiveConfirm records that drills verified RTO/RPO attainment
Warning

Trap: "If logs are captured, the detective control is effective" is wrong—logs function as a detective control only when periodically reviewed and analyzed and escalated on anomalies. If merely captured with no one looking, it is an operating deficiency. Also wrong: "if the BCP document is finely designed, the continuity control is effective"—unless drills verify that RTO/RPO can actually be met, the effectiveness of the corrective control is not assured.

CIA triad and BCP.
Protecting and staying resilient

5.3.3Section summary

  • Access management is based on least privilege; the auditor diagnoses excessive rights and missed revocations by reconciling the rights list against actual duties
  • Log monitoring is insufficient if only captured; it functions as a detective control only with periodic review and anomaly alerting
  • A BCP is confirmed not just by document design but by drills verifying RTO/RPO attainment; no drills is an operating deficiency of the corrective control

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. An auditor is evaluating access-management controls for privileged IDs. Reconciling the granted list against each holder's actual duties, they find that a privileged ID of a former operator who has transferred to another department remains without being disabled. Which is the most appropriate diagnosis and recommendation?

Q2. An auditor is evaluating log monitoring of privileged operations as a detective control. The operator explains that "all operation logs are captured and retained long-term." Which is the most important item for the auditor to confirm in judging the effectiveness of this detective control?

Q3. An auditor is evaluating the BCP of a financial institution's core banking system. A detailed plan document setting an RTO within four hours is in place, but no failover/recovery drill has been conducted in the past two years. Which is the most appropriate diagnosis by the auditor?

Check your understandingPractice questions for Chapter 5: Control evaluation

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.