| Privileged access is limited and reviewed. | Applicable external access-control criteria; internal privileged-access standard; contractual administrator restrictions. | Directory roles, cloud roles, local administrator controls, service accounts, break-glass accounts, PAM workflow, and quarterly review. | Authoritative account and role exports, approvals, review records, HR status, PAM logs, exceptions, and configuration evidence. | Reconcile privileged identities; sample assignments and use; inspect review completeness; test termination and emergency access cases. | Separate standing from eligible access; record unmanaged local accounts, unsupported systems, and time-bound exceptions. | Identity owner; system owners; audit preparer; independent reviewer. |
| Security-relevant changes are authorized and traceable. | Change-control criteria from applicable framework; internal change standard; customer availability commitments. | Service desk, infrastructure as code, cloud changes, firewall changes, emergency process, testing, approvals, and rollback plans. | Change population, approvals, timestamps, code or configuration diffs, test results, implementation logs, incidents, and rollback evidence. | Validate the population; sample normal and emergency changes; compare approvals and implementation; inspect failed or unauthorized changes. | Do not combine application and infrastructure populations when workflows differ; expand testing when exceptions indicate a systemic gap. | Change manager; technical owner; service owner; audit reviewer. |
| Critical events are collected and investigated. | Logging, monitoring, incident, and retention criteria; internal detection standard; regulated-data obligations. | Endpoint, identity, network, cloud, application, and security-platform sources feeding SIEM, MDR, or operational monitoring. | Source inventory, ingestion health, parsing, retention configuration, alert rules, tickets, escalation records, and incident samples. | Reconcile expected sources to active ingestion; inspect gaps and exclusions; sample alerts through closure; validate timestamps and retention. | A healthy agent is not proof of usable central logging; document licensing, parsing, time, retention, and ownership limitations separately. | SOC or MDR owner; platform owners; incident lead; audit reviewer. |
| Critical information and services can be restored. | Recovery and availability criteria; business impact decisions; contractual RTO/RPO; internal backup and recovery standard. | Protected backup repositories, immutability, access control, monitoring, restore testing, application recovery, failover, and failback. | Coverage reports, job history, failure tickets, repository settings, restore records, recovery exercises, capacity, and dependency evidence. | Reconcile critical assets to protection; inspect failures; sample restores; compare measured results with approved objectives and scope. | Successful backup jobs do not prove recoverability; record missing dependencies, untested applications, partial restores, and stale objectives. | Recovery owner; application owners; infrastructure team; audit reviewer. |
| Security exceptions are controlled. | Risk-management and exception requirements; internal risk-acceptance procedure; relevant contractual notification conditions. | Exception register, approval workflow, risk analysis, compensating controls, expiration, monitoring, renewal, and closure. | Complete exception population, approvals, risk records, owner acknowledgment, monitoring output, expiration alerts, and closure evidence. | Validate completeness against technical deviations and overdue findings; sample authorization and monitoring; inspect expired exceptions. | Operational necessity alone is not approval; treat missing owner, scope, expiration, or monitoring as a control-design or implementation issue. | Risk owner; security governance; technical owner; audit reviewer. |
| Third-party access and services are governed. | Supplier, privacy, contractual, and service-provider criteria; internal vendor-risk and access standards. | Due diligence, contract clauses, access provisioning, data flows, assurance reports, monitoring, renewal review, and termination. | Vendor inventory, criticality, contracts, reviews, access records, SOC reports, issues, monitoring, and offboarding evidence. | Reconcile procurement, accounts, applications, and data flows; sample critical providers; inspect report scope and complementary controls. | A third-party report is relevant only when its service, system, period, criteria, exceptions, and complementary user controls match the environment. | Business owner; procurement; legal or privacy; IT owner; audit reviewer. |