| Simple random |
Eligible units are sufficiently comparable and each unit should have an equal selection opportunity. |
Freeze the ordered frame, preserve the tool and version, random seed, requested size, generated positions, selected IDs, and date. |
Reduces conscious selection bias and supports probability-based designs when properly evaluated. |
May underrepresent small high-risk subgroups unless they are separately addressed. |
Randomly select user-access recertifications from a validated annual population. |
Could every eligible unit be selected, and can the identical selection be regenerated? |
| Systematic random-start |
A stable, complete ordered population is available and a periodic interval is operationally efficient. |
Record the frame order, population size, interval calculation, random start, wrap or end rule, and selected IDs. |
Simple to execute and spreads selections across the frame. |
Hidden periodicity or a meaningful sort order can bias coverage. |
Select every nth approved firewall change after a documented random start. |
Does the source ordering correlate with administrator, site, time, or control outcome? |
| Stratified random |
Risk, platform, location, value, privilege, or process differences could be masked in one pooled population. |
Define strata before selection; preserve membership rules, counts, allocation, seeds, and separate evaluation logic. |
Ensures coverage of material subgroups and may improve efficiency. |
Incorrect strata or unsupported aggregation can distort a combined conclusion. |
Sample privileged, standard, service, and guest accounts separately. |
Are strata mutually exclusive, collectively appropriate, and evaluated at the right level? |
| Cluster or multistage |
Populations are distributed across many sites, business units, systems, or providers and travel/access cost is material. |
Document each selection stage, probability or judgment at every stage, cluster comparability, and weighting/evaluation requirements. |
Can reduce collection cost and coordinate fieldwork. |
Units within a cluster may be correlated; a few selected sites may not represent all sites. |
Select locations, then randomly select endpoint hardening records within each chosen location. |
Why do selected clusters support the stated enterprise conclusion? |
| Risk-based targeted |
The audit needs direct coverage of critical, unusual, failed, or suspected items. |
Record the risk rule before testing, the full set meeting the rule, selected identifiers, exclusions, and why remaining items were not examined. |
Concentrates effort where business impact or likelihood is greatest. |
Not a representative sample unless combined with a separately designed representative selection. |
Test all domain administrators, emergency changes, and internet-facing critical vulnerabilities. |
Does the report clearly limit results to targeted items? |
| Haphazard nonstatistical |
A nonstatistical design is approved and the auditor selects without a conscious pattern or deliberate exclusion. |
Preserve the frame, instructions, selected IDs, timing, preparer, and evidence that convenience or result knowledge did not drive selection. |
May be practical for some low-complexity tests. |
Selection probabilities are not measurable; subconscious bias and convenience selection remain risks. |
Select change tickets across the audit period without favoring easy-to-retrieve records. |
Why is this approach sufficient, and how was bias controlled? |
| Full-population analytics |
A reliable rule, query, or analytic can evaluate every unit for a defined attribute. |
Preserve source validation, code/query, tool version, parameters, exclusions, error handling, results, and manual validation of the analytic. |
Can detect all rule-defined exceptions in the validated frame. |
It tests only what the logic can observe; data defects and false positives can affect every result. |
Evaluate every terminated user against directory disable timestamps. |
Was the analytic independently validated, and what conditions could it miss? |
| Hybrid coverage |
Critical items need complete or targeted testing while the remaining population needs representative coverage. |
Separate the census/targeted segment from the residual sample; preserve distinct populations, methods, results, and conclusions. |
Balances high-risk certainty with efficient broader assurance. |
Blended percentages can mislead if segments are aggregated without a valid basis. |
Test all privileged accounts plus a random sample of standard accounts. |
Can reviewers trace each result to the correct segment and conclusion? |