Control effectiveness is separate from control existence
Existence is easy to evidence and tells you almost nothing.
A screenshot proves something was configured once. Whether it still is, whether it covers everything it should, and whether it would stop the thing it was bought for are separate questions requiring separate testing. The gap between the two is where most control failures sit, quietly, between audits.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Risk acceptance spends organisational toleranceSigned, and spent
- Risk owners need authority over the consequenceThe name, not the lever
- Risk aggregation can reveal concentrationAll on one leg
