Memory hook: Fund the capability, assign an owner, test the result.
Must remember
Build a roadmap from current-state gaps to target outcomes, with dependencies, staffing, budget and milestones. Integrate security into procurement, development, HR and operations instead of relying on a separate review at the end. Asset inventory and classification identify what needs protection and who can decide its handling.
Select preventive, detective and corrective controls with operational feasibility in mind. Test design effectiveness and operating effectiveness separately: a well-written access-review procedure may never be followed. Retain evidence, address exceptions and verify remediation. Compensating controls require demonstrable coverage of the original risk, not just convenient substitution.
Awareness programs address broad behavior; role-specific training prepares people such as developers, administrators and responders. Measure demonstrated behavior and exposure reduction alongside completion. A high training-attendance rate can coexist with unsafe credential handling.
Supplier due diligence examines criticality, data access, security practices, continuity, subcontractors and exit options. Contracts define responsibilities, incident notification, audit rights, service levels and secure data return/deletion. Review assurance-report scope, period and exceptions, including customer responsibilities. Ongoing monitoring is necessary because a supplier’s condition can change after onboarding.
KPIs track performance, KRIs signal changing exposure, and control indicators show whether safeguards operate. Choose measures with thresholds, owners, trend context and a decision they support. Report unresolved exceptions and accepted risks honestly. A lower incident count could reflect weaker detection rather than improved security.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Check a supplier assurance report | Read scope, period, exceptions and complementary customer controls. |
| Demonstrate training effectiveness | Observe relevant behavior and risk outcomes. |
| Program slips due to skill gaps | Adjust staffing, sequencing or scope with accountable sponsors. |
Traps
- Certification badges do not eliminate supplier risk.
- A metric without an action threshold may become decorative reporting.
Active recall
1. Design versus operating effectiveness?
Whether a control could address the risk versus whether it actually works consistently.
2. Why assess fourth parties?
Subcontractors can introduce dependencies and access outside the immediate contract.
3. What is a KRI?
An indicator of changing risk exposure.
4. Why review customer controls in an assurance report?
The provider’s assurance may assume the customer performs specific controls.
5. Why test remediation?
A closed ticket does not prove the weakness was fixed.