Skip to content

Evidence and Sampling in Control Assessments

Testing whether a control works, not whether somebody says it does.

Editorial team 2 min read

A control assessment asks two questions: is the control designed to achieve its objective, and is it operating as designed. Design is read; operation must be sampled.

The evidence ladder

From weakest to strongest: somebody says the control runs; a document says it should run; a screenshot shows it ran once; a system export shows every instance in the period; you re-perform the control yourself and get the same result.

Aim at least two rungs up from an interview. Screenshots are the most common evidence and among the weakest — they show one moment, chosen by the person being assessed.

Sampling

For a control that runs many times — access reviews, change approvals, starter and leaver processing — pick a sample across the whole period rather than the most recent few, and include the awkward cases: emergency changes, contractors, transfers between teams, and anyone who left in a hurry.

What exceptions mean

One failure in twenty-five is not noise; it is a 4% failure rate in a control somebody is relying on. Record it, find out why, and separate "the control was skipped" from "the control does not work" — those have different fixes.

Writing it up

Say what you tested, over what period, how you chose the sample, what you found and what it means for the objective. An assessment that cannot be re-performed from its own write-up is an opinion.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025