Assessing implemented security controls
The goal of assessing the implemented security controls is to ensure that the controls have been adequately implemented as part of the information system.
In order to properly assess the information system's security controls you should be asking if the security controls are the following:
- Implemented as expected: Are the agreed upon security control designs part of the production information system?
- Operating appropriately: Are the security controls impacting the production system negatively and providing the required security functionality?
Testing security controls should be a formalized procedure within your organization. Security control implementation can be very complicated and there are typically a large number of requirements that need to be implemented. Without a formalized plan, you will find it very difficult to adequately and completely test your newly implemented security controls. Your testing procedures will be ad hoc, and you run the risk...