Control testing
Testing of technical and process controls, with objective evidence of which ones work and which need improvement. Security on paper is not the same as security in daily work.
Who it is for and when
Suits organisations that have controls in place but lack proof that they are applied, and that need evidence which holds up in an audit or a customer question.
- The controls are described in policy, but nobody knows whether they are followed.
- An auditor or customer has asked for evidence and you have nothing to show.
- You have implemented measures after a review and want to verify that they had effect.
- You want recurring testing instead of one annual push.
What we do
- Selecting the controls. We agree which controls to test, based on risk, the requirements that affect you and what was last reviewed.
- Testing technical controls. Vulnerability scanning, configuration review and targeted tests to verify that systems are actually protected: patch levels, misconfigurations and weaknesses in networks and applications.
- Testing process controls. Interviews and review of policies, routines and training, with sampling to confirm they are applied: access reviews, approvals and completed exercises.
- Evidence per control. Each control is given a result with the underlying evidence retained, in a form that holds up in an external audit.
- Recommendations and walkthrough. Weaknesses are documented with concrete recommendations and walked through with the people who will act on them.
What you get
- Test results per control, with rationale
- Evidence in a form that holds up in an external audit
- Concrete recommendations per weakness
- A summary for management
- The option to set testing up as recurring
Scope and price
A defined engagement, or recurring with a subset of the controls per period. The scope is driven by how many controls are included and how deeply they are tested.
The price varies from engagement to engagement and depends on the scope. You get an estimated cost proposal and, where possible, a fixed price.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
How does this differ from an internal audit?
An internal audit reviews the management system as a whole against a standard. Control testing goes deep into individual controls and shows with evidence whether they work in practice. The two are often combined.
Do you test both technology and routines?
Yes, and that is the point. A control can be correctly described in a routine without being applied, or applied without being documented. We test both to see whether security works in daily operations.
Can testing be set up as recurring?
Yes. Many choose to test a subset of controls each quarter so that all are covered during the year, which also evens out the workload.
Would you like to know whether the controls work in practice?
Contact us