Control Criterion
Definition
The standard against which a control is evaluated. Criteria may come from an external standard (ISO 27001 Annex A, NIST CSF, PCI-DSS), a regulation (GDPR Article 32, HIPAA Security Rule), or the organisation's own documented policy. A finding requires a stated criterion: a control cannot be deficient unless there is a defined expectation it fails to meet.
- Sources
- ISO 27001 Annex A, NIST CSF, PCI-DSS
- Also from
- Regulation, e.g. GDPR Art 32, HIPAA
- Required for
- A defensible audit finding
Common questions
Why can't an auditor report a control deficiency without a stated criterion?+
Without a defined expectation to measure against, there is no objective basis for calling the control deficient, so the finding would rest on the auditor's opinion rather than a documented standard.
Can an organisation's own internal policy serve as the audit criterion?+
Yes, a formally adopted internal policy is a valid criterion, provided it is documented and the organisation actually committed to meeting it.
Related terms
- Audit Chain of Custody
- The documented record of when audit evidence was collected, by whom, from what source, and how it has been stored and accessed...
- Design Effectiveness
- The assessment of whether a control is designed in a way that would prevent or detect the risk it targets, if it...
- Evidence Sufficiency
- The standard that evidence must meet to support an audit conclusion. Evidence must be relevant to the control being tested, reliable in...
- Fieldwork
- The active evidence-gathering phase of an audit, during which the auditor applies testing procedures to specific controls and collects the evidence that...
- Operating Effectiveness
- The assessment of whether a control has consistently functioned as designed over the audit period. Requires evidence of actual operation, such as...