← CISM: manage security, risk, and incidents
10 / 11 · 60 MIN

Measure controls in the actual service

Interpret coverage, collection, sampling and exception paths without confusing activity with demonstrated protection.

The denominator is part of the measure

A percentage needs a population, period and inclusion rule. With 180 controlled accounts out of 200, observed coverage is 90%. Discovering another 100 in-scope uncontrolled accounts changes the result to 60%, even if none of the 180 controls failed. Discovery reveals omitted exposure; it does not retroactively create a malfunction. Preserve history with the scope change identified and show the current 120 gaps. Tracking the old cohort alongside may help, but never to hide the total population now known or avoid treatment.

Samples and segments are not interchangeable

A sample of twenty low-impact applications does not establish protection of critical applications left outside it. Define the assessment question before selecting the sample and record what conclusions it supports. In a banking service, separate criticality, privileges, suppliers and operational windows when these differences affect risk. When comparing training campaigns, also consider difficulty and population: fewer clicks in an easier exercise do not prove training caused improvement. Retain results with context and seek consistent comparisons, without deleting observations merely because they make the narrative less favorable.

Work output and the exposure balance

Counting closed tasks shows activity but does not necessarily show reduced outstanding work. With 120 initial gaps, 45 arrivals and 30 validated closures, the final balance is 135. It grew by fifteen despite closures. Add criticality and age to distinguish a queue of small adjustments from persistent exposure in essential systems. Closure should have an evidence criterion; moving a ticket between columns does not prove effectiveness. The program owner uses the balance to discuss capacity and priorities while keeping team throughput separate from the evolution of risk.

Collection also needs controls

A dashboard can remain green after losing contact with its agent. Define expected freshness, collection ownership, missing-data treatment and how discrepancies are investigated. If the last observation is eight days old, explain what remains known and what is no longer demonstrated. When monitoring was an exception condition, failure also affects the risk decision. It does not automatically make the service compromised but requires assessing exposure and alternatives. Confidence in the measure depends on both indicator logic and the path through which data reaches reporting.

Test alternative paths and changes

Testing the normal path does not automatically cover emergency access, exports or supplier changes. A shared account able to change payments needs authorization, attribution, records and review appropriate to risk. An exported spreadsheet may have different controls from its source application. An assurance report preceding a material migration leaves a time gap to assess. Follow actual flows and request evidence proportionate to changes, without assuming a commercial name or old document retains full validity. The objective is to understand effective protection in the service as it operates now.

Fallback and exit have their own criteria

When an authorization control fails, unrestricted continuation and blocking everything can both have material consequences. Prepare an approved fallback with limits, roles, records, reconciliation and rehearsal in the actual operational window. If dual validation exists only during office hours, Saturday readiness is not demonstrated. During supplier exit, deleting active data also does not prove handling of retained backups. Identify scope, access, retention period and final disposition under applicable requirements. In both cases, the conclusion must respect evidence and actual conditions rather than simply relying on the presence of an approved document.

IN PRACTICE

Account discovery changes coverage from 180/200 to 180/300. Reporting retains the old cohort for comparison and presents 120 gaps, prioritized by privilege and critical service.

Common pitfalls

Excluding accounts to improve coverage; attributing causality to incomparable campaigns; counting tickets as effectiveness; inferring backup deletion from active data; accepting fallback without operational staffing.

Related topics: Data quality and sampling · Supplier assurance · Handover and continuity

Take this idea with you

Measure the right population, keep uncertainty visible and test paths the service actually uses. A useful measure leads to a decision with ownership and evidence.

Create account

Reference: Identifying and Selecting Security Measures · CISM current outline before November 3, 2026

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.