6.5 Security Awareness, Control Testing & Security Assessment Reporting
Key Takeaways
- Auditing a security awareness program means reconciling training completion records to an independent HR roster, since the classic finding is an incomplete population that omits contractors or an acquired subsidiary rather than a low completion rate.
- The blueprint's phrasing that a program must model appropriate security behaviors means leadership conduct is evidence: executives exempted from multi-factor authentication undercut the program regardless of completion statistics.
- A deficiency in suitability of design means the control could not achieve the criterion even if performed perfectly, while a deviation in operation means a well-designed control did not operate as described; design is evaluated first and an unsuitable design makes operating tests pointless.
- In a SOC 2 engagement, controls are evaluated against the Trust Services Criteria interpreted in light of the service organization's own service commitments and system requirements, so identical test results produce different conclusions under a four-hour and a seventy-two-hour recovery commitment.
- A security assessment finding is written with five elements - criteria, condition, cause, effect and recommendation - and the recommendation must address the cause rather than the sampled instances.
Security Awareness, Control Testing & Security Assessment Reporting
Quick Answer: The blueprint's Testing topic under Security is procedural rather than conceptual. Perform procedures to understand how the entity communicates security knowledge and models appropriate behavior through an awareness program. Perform a walkthrough of procedures relevant to IT security — IT risk management, human resources, training and education — and compare what you observe to the documented policy requirement. Provide input into a security assessment report by documenting issues, findings and recommendations. And detect deficiencies in design and deviations in operation of controls over a service organization's security service commitments in a SOC 2 engagement.
1. The Security Awareness Program
What a Complete Program Contains
- Onboarding training completed before or immediately upon the grant of system access, not within the first ninety days.
- Periodic refresher training, at least annually, tracked to completion.
- Role-based training layered on top of the general curriculum: developers receive secure coding; finance and treasury receive business email compromise and wire fraud; executives receive whaling; privileged administrators receive credential handling and change discipline.
- Phishing simulation run continuously rather than annually, with measured click, report and repeat-offender rates, and a defined remediation path for repeat clickers.
- Continuous reinforcement between formal sessions: targeted communications, intranet content, posters, and timely alerts when a live campaign is circulating.
- Modeling of behavior by leadership. The blueprint's phrasing — "to model appropriate security behaviors to personnel" — is deliberate. A program in which executives request and receive exemptions from multi-factor authentication is not an effective program regardless of its completion statistics.
Procedures to Obtain an Understanding
The blueprint asks the candidate to perform procedures, so the answer is a list of audit steps, not a description of good training:
- Inspect the curriculum and materials and assess whether the content addresses the risks the organization's own risk assessment identified. A generic vendor course that never mentions the entity's wire transfer process is a design weakness in the program.
- Obtain the completion report and reconcile the population. Compare trainee records to an independent HR active-employee roster. The classic finding is not low completion; it is an incomplete roster that quietly omits contractors, service accounts' human owners, or a recently acquired subsidiary.
- Test timeliness for new hires. Sample recent joiners and compare the training completion date to the system access grant date.
- Inspect phishing simulation results over the period, including trend, and — more importantly — evidence that repeat clickers were actually routed to the defined remediation.
- Inspect acknowledgment records. Signed acceptable use policy acknowledgments, dated, tracked, and re-executed on the defined cycle.
- Interview a sample of personnel across functions and levels to corroborate that the communicated expectations match what people actually believe and do.
- Inspect the communication channel evidence — the actual emails, intranet posts and alerts issued during the period — rather than accepting a description of the communication plan.
2. Walkthroughs of IT Security Procedures
A walkthrough follows one instance of a procedure end to end and compares what is observed to what the documented policy requires. The blueprint names three procedure areas.
| Area | What to Walk | Evidence to Inspect | Typical Finding |
|---|---|---|---|
| IT risk management | One full risk assessment cycle: identification, analysis, response decision, and monitoring of the response | The risk register, the meeting minutes approving risk decisions, the treatment plan and its status | A register that has not been updated since a major system change, or accepted risks with no expiry and no re-evaluation |
| Human resources | One new hire and one termination end to end | Background check results, signed policy acknowledgments, access request approvals, the termination checklist, timestamps of access revocation | Access revoked days after the termination date; background checks omitted for contractors |
| Training and education | One training cycle from assignment through completion and escalation | Assignment records, completion evidence, escalation correspondence for non-completion | Non-completion escalated to nobody; a documented consequence that has never been applied |
How to conduct it: select the instance, observe or reconstruct each step from evidence rather than description, identify the performer by name and role, and record the observed sequence against the documented requirement. Differences run in both directions — the documented step that never happens, and the step that happens but appears nowhere in the policy.
3. Detecting Design Deficiencies vs. Operating Deviations
This distinction drives every SOC 2 security finding, and candidates lose points by conflating the two.
| Deficiency in suitability of design | Deviation in operation | |
|---|---|---|
| Question | If this control operated exactly as described, every time, would the criterion be achieved? | Did the control, as described, actually operate that way throughout the period? |
| Evidence | Policy text, configuration, the control description, the criterion | Samples, logs, tickets, approvals, system evidence across the period |
| Example | The policy requires user access reviews annually while the service commitment promises access is removed within 24 hours of termination — the design cannot achieve the commitment even if performed perfectly | The policy correctly requires quarterly reviews and three of four quarters were performed |
| Consequence | Testing operating effectiveness is pointless; the control is deficient on its face | Evaluate frequency, root cause, compensating controls, and effect on the criterion |
The sequencing rule: evaluate design first. If the design is unsuitable, do not proceed to test operating effectiveness — a control that could not achieve the criterion even when performed perfectly is deficient regardless of how consistently it was performed.
Anchoring to Service Commitments and System Requirements
In a SOC 2 engagement, controls are evaluated against the applicable Trust Services Criteria, interpreted in light of the service organization's own service commitments (what it promised customers, in contracts, SLAs and public statements) and system requirements (what the system must do to meet those commitments and comply with law). So a finding is written against the criterion, but its severity is judged against what the organization promised. A four-hour recovery commitment and a seventy-two-hour recovery commitment are evaluated against the same availability criteria and produce entirely different conclusions from the same failover test result.
4. Writing Findings for a Security Assessment Report
The blueprint asks candidates to "provide input into a security assessment report by documenting the issues, findings and recommendations identified while performing tests of controls." Findings are written to a fixed five-element structure. Omitting an element is what turns a legitimate observation into an argument with the client.
| Element | The Question It Answers | Example |
|---|---|---|
| Criteria | What should be? | "CC6.2 requires that access is removed upon termination; company policy requires removal within 24 hours." |
| Condition | What is? | "For 6 of 25 terminated employees sampled, network access remained active between 4 and 31 days after the termination date." |
| Cause | Why did it happen? | "Termination notifications are sent by email to a shared IT mailbox with no ticket, no service level, and no exception report for unprocessed notices." |
| Effect | So what? | "Former employees retained access to the customer database, creating risk of unauthorized access and inability to attribute activity to a current authorized user." |
| Recommendation | What should be done? | "Integrate the HR system with the identity platform to trigger automated disablement on the termination effective date, and produce a weekly exception report of accounts active for users flagged terminated." |
Drafting standards that matter in practice:
- Quantify the condition. "Six of twenty-five" is a finding. "Access removal is sometimes late" is an opinion.
- Address the cause, not the instance. A recommendation to revoke the six accounts fixes six accounts. A recommendation to automate the trigger fixes the control.
- Never name the individual. Findings address the process. Naming a person converts an audit report into a personnel matter and reliably ends cooperation.
- Rate severity consistently using a defined scale tied to likelihood and impact on the criterion or the service commitment, not to how the finding felt to discover.
- Distinguish a finding from an observation. A control failure is a finding. An efficiency opportunity with no control consequence is an observation and belongs in a separate section.
- Obtain management's response — the remediation action, a named owner, and a target date — before the report is issued, so the report leaves with an accountable plan attached.
- Aggregate before concluding. Individually minor deviations in provisioning, access review and termination may be individually tolerable and collectively demonstrate that the access management control set as a whole does not achieve the criterion.
Exam framing: For a service auditor, the finding document is the input to Section IV of a Type 2 report. Section IV must state the control tested, the procedure applied, the sample size, and the number and nature of deviations — and every identified deviation is reported there regardless of whether the opinion ends up unmodified.
A service organization's SOC 2 report includes a service commitment that terminated users' access is removed within 24 hours. The organization's documented control states that a user access review is performed annually and that any accounts belonging to former employees are removed at that time. The control operated exactly as written in each of the past three years. How should the service auditor characterize this?
An auditor testing termination access removal finds that 6 of 25 sampled former employees retained network access for between 4 and 31 days after their termination dates, because HR sends termination notices to a shared IT mailbox with no ticket, no service level and no exception reporting. Which recommendation best addresses the finding?
Which procedure provides the most persuasive evidence about whether an entity's security awareness program reaches its full intended population?