Skip to content

Control assessment against a framework

Choosing a framework, testing design and operation, gathering evidence that holds up, and reporting a gap plan.

Free on glitchdata intermediate 4 lessons 54 min

What you'll learn

  • Choose a framework that matches why you are assessing
  • Distinguish design effectiveness from operating effectiveness
  • Gather evidence and sample periods defensibly
  • Turn an assessment into a prioritised gap plan

About this course

Sooner or later somebody asks whether your controls work — a customer, an auditor, a regulator, or your own board. Answering well means assessing design and operation against a standard, with evidence rather than assertions.

This course covers choosing between CIS, ISO 27001 and the NIST framework, the difference between a control that exists and one that operates, how to sample and evidence, and how to turn the result into a plan instead of a score.

Before you start

  • Some exposure to security governance or audit

Course content

4 lessons · 54 min

  1. 1
    Choosing a framework for the question you have

    CIS to decide what to do, ISO 27001 to prove a programme exists, NIST CSF to have the conversation.

    Free preview 13 min
  2. 2
    Design versus operating effectiveness

    Two different tests: would it work if it ran, and did it run?

    14 min
  3. 3
    Evidence, sampling and exceptions

    How to gather proof that survives challenge, and what a single failure in a sample means.

    14 min
  4. 4
    From assessment to a gap plan

    Turning findings into a sequenced plan rather than a maturity score nobody acts on.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security