• Excellent evidence: Testing a control with a simulated activity designed to confirm it is in place and effective (e.g. attempting to run an application to check application control rulesets).
  • Good evidence: Reviewing the configuration of a system through the system’s interface to determine whether it should enforce an expected policy.
  • Fair evidence: Reviewing a copy of a system’s configuration (e.g. using reports or screenshots) to determine whether it should enforce an expected policy.
  • Poor evidence: A policy or verbal statement of intent (e.g. sighting mention of controls within documentation).

guidance on the eight essential mitigation strategies from the Australian Cyber Security Centre (ACSC)’

Beyond Cyber 101 mentorship into cybersecurity and beyond.