3.4 Vulnerabilities associated with new controls
Once the new control is implemented, it is recommended to test the control to ensure that risk has been appropriately mitigated.
It must be noted that each new control implemented should be evaluated for additional vulnerabilities.
In few cases, it may happen that these additional risk may exceed the risk that it is meant to address.
Conduct of user acceptance testing may help to identify vulnerabilities with respect to new controls.
Key aspects from CRISC exam perspective
CRISC Question
|
Possible Answer
|
What is the best next action
after implementation of a new control?
|
To test the
control to ensure that it mitigates the risk
|