Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

4.3.3. Control Testing and Evaluation

💡 First Principle: A control that passed its last test is a control that worked under yesterday's conditions — configuration drift, business change, and evolving threats mean effectiveness has to be re-verified on a cycle, not assumed to be permanent.

Control testing ranges from automated continuous control monitoring (checking configuration state against a defined baseline in near real time) to periodic manual testing and formal audit. A control that passed an audit twelve months ago can fail silently well before the next audit cycle — through a configuration change, a business process change that routed around it, or a new technique that defeats the control's original design — which is exactly why retesting cadence, not just initial testing, is what the exam expects a mature program to plan for.

⚠️ Exam Trap: A control that passed testing once is sometimes assumed to remain effective indefinitely. The correct answer recognizes that controls require periodic retesting, since drift and change degrade effectiveness over time even without any single dramatic failure event.

Reflection Question: An access control passed its annual audit eleven months ago. A system change two months ago inadvertently widened its scope. What's the risk of relying solely on the annual audit cycle to catch this?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications