Measuring Control Effectiveness - John Mitchell
Measuring Control Effectiveness - John Mitchell
Measuring Control Effectiveness - John Mitchell
John Mitchell PhD, MBA, CEng, CITP, FBCS, CFIIA, CISA, CGEIT, QiCA, CFE
Monitoring
Control
Activity
Control
Risk Objectives
Information &
Communication Analysis
H
i
g E
h
L
Senior Management I
D Inherent
Attention K
E Risk
Local Management L
I
Attention C Likelihood
H
O Reduction
No Action O
D
B Residual
Risk Consequence
L Reduction
o A
w
A B C D E
Low CONSEQUENCE High
Residual
Inherent Risk Controls
Risk
Risk 1 None
Risk 2 Some
Risk 3 Lots
7 Fails to detect the event and does not have a business continuity
plan
Design
Implementation
Monitoring
Evaluation
Apply DIME:
Design = 2 (3)
Implementation = 3 (3)
Monitoring = 2 (3)
Evaluation = 1 (3)
Division:
Location:
1) Control 1
2) Control 2
3) Control 3
4) Control 4
C Where the answer to a minimum requirement is Is it performed? Who/what performs it? How How is it evidenced?
NO: Contr. Contr.
Class Score
Please give details of any alternative controls N/A Yes No
providing assurance
D Where the score for control effectiveness is < 3 Contr. Proposed Pot. Who/what will perform How How will it be evidenced?
Class Implementation Score it? Often?
Please detail the control which is to be Date
implemented to improve the result
H
i
g E 8
h
L
I 3,4,5,6,7,9, 12) Power
D 2,18
10,11,13,14
12
K Loss
E
L 14) 3rd Party
I Support
C 16
H
O
O
D
B 1
L 15) Loss of
o A 17 15 Data Centre
w
A B C D E
Low CONSEQUENCE High
Whether you use CMM or ISO 15504 you still need to assess control
effectiveness
The evidence must show who/what operates the control and the
frequency of operation
[email protected]
www.lhscontrol.com