Cybersecurity Policy Testing
Evidence-based testing that determines whether documented procedures are implemented, operating and consistent with firm policy.
Know when to bring this work into the program.
Use policy testing when the documents look complete but leadership needs evidence that employees, IT teams and service providers are actually following them.
A scope built around the risk.
Evidence-based testing that determines whether documented procedures are implemented, operating and consistent with firm policy.
- Sampling of procedures required by written policy
- Evidence that approvals and reviews occur on schedule
- Consistency between policy, technology configuration and practice
- Exceptions, ownership and corrective action
Useful output for the people who must act.
- Test plan mapped to policy requirements
- Evidence samples and test results
- Exceptions with accountable recommendations
- Documentation suitable for compliance files and exams
A process designed for cybersecurity policy testing.
Select requirements
Begin with sampling of procedures required by written policy and confirm the systems, people and evidence needed to answer the client’s specific questions.
Sample the evidence
Review evidence that approvals and reviews occur on schedule. Then evaluate consistency between policy, technology configuration and practice to determine whether the relevant controls operate as intended.
Record exceptions
Assess exceptions, ownership and corrective action and connect the result to credible security, operational and business impact.
Correct and verify
Provide test plan mapped to policy requirements and evidence samples and test results, then align responsible parties around the next actions.
Move from activity to clarity.
Are stated procedures operating as written?
To answer this, Elteni analyzes sampling of procedures required by written policy together with evidence that approvals and reviews occur on schedule. The client receives test plan mapped to policy requirements, with the evidence, context and next steps needed to act.
Can recurring reviews and approvals be demonstrated?
To answer this, Elteni analyzes evidence that approvals and reviews occur on schedule together with consistency between policy, technology configuration and practice. The client receives evidence samples and test results, with the evidence, context and next steps needed to act.
Do technical settings support the policy language?
To answer this, Elteni analyzes consistency between policy, technology configuration and practice together with exceptions, ownership and corrective action. The client receives exceptions with accountable recommendations, with the evidence, context and next steps needed to act.
The result does not have to live in another report.
Relevant findings, evidence, owners and remediation status can be centralized in the Elteni Platform as part of an ongoing relationship.
Explore the Elteni Platform →