What to do at this stage
- 01
Prepare acceptance tests that trace back to the agreed security requirements.
- 02
Record test results, defects, limitations and the evidence supporting acceptance.
- 03
Return failed controls for correction and retest before relying on their intended performance.
Questions to work through
- Has each requirement been demonstrated?
- Were important interfaces and failure conditions tested?
- Who can accept an unresolved limitation?
Test the complete alarm pathway: detection, notification, acknowledgement and response. A device activating is only part of that sequence.
A common trap
A supplier’s completion statement is not a substitute for evidence that the control meets the specified requirement.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Risk Control Effectiveness Criteria Template
Use defined criteria when evaluating control effectiveness.
View in the SRMBOK shopControl Effectiveness Assessment - PDF A4 Organisational Licence
Learn a control-effectiveness method using design, capability, feedback and evidence, with worked cases and calibration exercises.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.