A&A-02: Independent Assessments

Control Family:

Audit & Assurance

PF v1.0 References:

Previous Version:

Control Statement

Conduct independent audit and assurance assessments according to relevant standards at least annually.

Implementation Guidance

Independent audit and assurance should be free from conflict of interest and undue influence in all matters related to audit and assurance engagements. The frequency of audit and assurance evaluations should comply with applicable standards, regulations, legal/contractual obligations, and statutory requirements. The audit and assurance process should assess all applicable CCM domains.

Auditing Guidance

  1. Examine the process to determine standards and regulations applicable to the organization's systems and environments.
  2. Determine if the organization maintains and reviews a list of such standards and regulations.
  3. Determine if senior management exercises oversight over the independence of the assessment process.
  4. Determine if the audit plan is informed by previous assessments, and is scheduled on an annual basis.

[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]

Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.