What to do at this stage
- 01
Choose evidence that demonstrates actual operation, including samples, observations and tests.
- 02
Evaluate effectiveness against agreed criteria and record the limitations of the evidence.
- 03
Assign findings and revisit treatment decisions where protection is weaker than assumed.
Questions to work through
- What evidence shows the control working?
- Is the sample sufficient for the claim being made?
- Which findings change our view of residual risk?
An access review should examine whether inappropriate permissions are detected and removed, as well as whether a review procedure exists.
A common trap
The presence of a policy establishes intent; it does not by itself establish operating effectiveness.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Insider Threat Management Evaluation Tool
Examine the effectiveness of an existing insider threat programme.
View in the SRMBOK shopASD Essential Eight Assessment Tool
Support a focused review of cyber security controls.
View in the SRMBOK shopSRMBOK Guide to OSCAL
Understand OSCAL, its control models, limitations and questions to ask before investing in compliance automation.
View in the SRMBOK shopRisk Control Effectiveness Criteria Template
Use defined criteria when evaluating control effectiveness.
View in the SRMBOK shopNIST CSF 2.0 Assessment Tool
Explore cyber security outcomes in a structured assessment workbook.
View in the SRMBOK shopElectronic Access Control System Audit Procedure
An editable procedure for sending access reports to sponsors, reviewing permissions and correcting inappropriate access.
View in the SRMBOK shopControl Effectiveness Assessment - PDF A4 Organisational Licence
Learn a control-effectiveness method using design, capability, feedback and evidence, with worked cases and calibration exercises.
View in the SRMBOK shopSRMBOK Template 13.6 Operational Governance Registers
Sixteen editable operational records covering inspections, incidents, access, keys, security clearances and training.
View in the SRMBOK shopSRMBOK ISO27000 Cybersecurity Review Tool
An editable Excel review tool combining a cyber control checklist, scorecard and control-effectiveness assessment.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.