Concept and mechanism
Program management continues after delivery. Compare implemented controls with requirements, track deviations, and review effectiveness after changes. A finding fixed in code needs proportionate retesting before claiming the flaw was addressed in scope. For vendors, check the service, period, and exclusions of presented evidence; an assessment of another product does not automatically resolve the contracted product’s risk. Shared responsibility depends on the service. In IaaS, protecting physical infrastructure does not mean the provider manages every customer application and identity. Record the responsibility matrix and demonstrate the organization’s controls.
Guided application
Plan exit before contract end: continuity, data return or migration, applicable retention, revocation, and completion evidence. For media disposal, select sanitization appropriate to the technology and validate the outcome; quick formatting does not prove irrecoverability. In RUN, an availability SLA does not replace ownership of integrity alerts. Exception conditions are controls too: if compensating monitoring is absent, approval lacks an essential condition. For authentication, choose properties meeting the requirement. Two knowledge secrets do not create independent factors; a phishing-resistant solution should include account recovery and authenticator enrollment in the analysis.
A SaaS pilot using synthetic data can validate functionality; it does not itself authorize real customer-data processing.
Common pitfalls
Logo as assurance scope; cloud as transfer of everything; contract end as automatic revocation.
Related topics: Prepare response and continuity · Contain, recover, and learn
Maintain evidence and responsibilities through entry, operation, and exit.
Reference: Technical Guide to Security Testing and Assessment · CISM current outline before November 3, 2026