Define control objective

OrderTabWhat you do in real lifeLondonBuild example
1Start with RequirementTake the requirement you are assessing.ISO 27001 A.5.15 — Access Control
2Understand the RequirementDetermine what the requirement is trying to achieve.Prevent unauthorised access to information and systems.
3Define Control ObjectiveWrite the desired outcome the control must achieve.Ensure access to LondonBuild’s systems and information is authorised, appropriate and limited according to business need.
4Identify the RiskAsk what could happen if the objective isn’t achieved.Unauthorised users could access sensitive company or project information.
5Determine Control ActivityDecide what activity/process should achieve the objective.Access is approved based on job role and business need.
6Identify Control OwnerDetermine who is accountable for the control.IT Manager
7Define Control FrequencyDetermine how often the control operates.At onboarding/change of role + quarterly review
8Define Expected EvidenceDetermine what should prove the control is operating.Access requests, manager approvals, user-access reports
9Define Testing ApproachDecide how you will later test the control.Sample 10 users and verify approval and appropriate access.
10Document the ControlPut everything into the GRC system/control register.Control ID, objective, activity, owner, frequency, evidence, test method.