← CISA: audit IT, controls, and resilience
10 / 10 · 60 MIN

Audit the operational effect

Assess batches, retries, recovery, privileges and logging against the business outcome and in-scope period.

Connect execution to input and business date

A job can finish without error while processing the wrong file. Connect execution to the manifest, input identifier, business date, expected quantity and recipient result. Scheduler timing and exit code establish technical aspects but do not replace process reconciliation. In a funds close, using the previous day’s data can produce a formally valid file while still failing the requirement. On finding the discrepancy, preserve evidence and communicate with the operational authority. The auditor should not trigger reprocessing without knowing effects already applied and having authorization.

Distinguish the transfer from its attempt

One logical transfer can have several technical attempts. If P42 is sent as R1 and R2, uniqueness of R1 and R2 does not prevent a duplicated financial effect. Assess which identity the control uses, how long it retains state and how it handles failure between applying an effect and acknowledging it. Authorized testing should include the relevant retry and verify the result without assuming idempotency from a feature name. If recipient data is missing, communicate uncertainty. Blind repetition or ordering full reversal may enlarge the problem being addressed.

Measure unavailability without duplicating minutes

The SLA unit determines how events should be combined. For the same end-to-end service, intervals 10:00–10:20 and 10:10–10:30 represent thirty unique minutes, rather than forty. If the contract measures components separately, its rule may differ; do not transfer the calculation without confirming the measured object. Identify overlap, contractual window, approved exclusions and timestamp origin. Taking interval unions resolves double counting but does not establish that every incident was recorded. Keep mathematical calculation validation separate from the quality of evidence supplied as input.

The restored point and log potential

A snapshot through 09:40 after failure at 10:00 leaves twenty minutes between the demonstrated point and failure. Logs available through 09:58 may allow that point to advance, but file existence does not establish successful application and validation. With a five-minute RPO, do not declare compliance based only on that possibility. Also do not declare definitive twenty-minute loss before evaluating incremental recovery. Record current state, pending steps, dependencies and acceptance ownership. Reporting should follow evidence as it develops without rewriting what was previously observed.

Check the complete path and effective permissions

Recovering queries does not establish the ability to submit instructions to a partner. Define the business operations that must work and follow dependencies, identities and confirmations. Apply the same logic to copy separation: a distinct account is insufficient if the production administrator can assume a deletion-capable role. The effective authorization path takes precedence over the nominal design when assessing that requirement. Test only with authorization and conditions preserving service and evidence. The absence of previous deletions does not remove a capability that the control was intended to prevent.

A snapshot does not represent the whole period

The final access list may be correct after six hours of transient privilege. If the criterion covers the month, examine authorization, scope and use during that window. Available privilege does not prove misuse; removed access does not erase historical exposure either. For denial testing, choose a representative identity: a disabled account failing login does not establish export blocking for an active unpermitted account. Define positive and negative conditions and identify configuration and test data. The conclusion should refer to the control actually exercised rather than merely a favorable result.

Record protection and security boundaries

An immutable repository protects received events but does not create events lost during agent failure. Seek authorized corroboration and keep the gap explicit; silence proves neither no activity nor misuse. Follow encryption boundaries as well: TLS between client and proxy does not automatically cover plaintext traffic between proxy and application. If the requirement includes that segment, document the gap and management response. Evidence of a control in another layer, such as encryption at rest, does not replace required transit protection. The conclusion follows scope and the observed mechanism.

IN PRACTICE

Two incidents for the same service, 10:00–10:20 and 10:10–10:30, yield thirty unique minutes. The calculation does not prove record completeness and precedes applying authorized contractual exclusions.

Common pitfalls

Confusing attempt with transfer; adding overlapping outages; assuming logs were applied; using only final access state; treating immutability as completeness or partial TLS as complete protection.

Related topics: Batches and reconciliation · Recovery and SLA · Logging and privileges

Take this idea with you

Assess effects, periods and effective paths. A useful conclusion preserves valid results, identifies gaps and lets the operational authority decide using proportionate evidence.

Create account

Reference: Assessing Security and Privacy Controls · CISA outline effective August 1, 2024

CISA® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.