Standards interpretation

Cyber resilience: what constitutes adequate evidence

Standards Interpretation

Interpretation of cyber resilience identifies scope, evidence, decision authority, material exceptions and continuing review.

For the applicable requirement, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope.

A narrow control applied to the relevant process may create false assurance. In the present context, retention beyond an identified need, secondary use without adequate authority and inaccurate data affecting decisions may produce acceptable aggregate reporting while individual learners remain exposed to material disadvantage. For cyber resilience, the test should deliberately include exceptions and cases in which the expected outcome was not achieved.

Application to cyber resilience

For the matter, a provider should be able to trace the expectation from approved policy through implementation, monitoring, identified exceptions and corrective action.

Assurance concerning the matter should state the scope examined, evidence relied upon and any condition preventing a complete conclusion. Unsupported elements should remain open. For decisions concerning cyber resilience, that distinction should remain visible in the decision record, public reporting and later review.

Evidence concerning cyber resilience should be relevant to the stated requirement, sufficiently complete for the affected scope, current for the decision period and attributable to a source with knowledge or control of the matter. Volume does not cure a gap in relevance.

  • Test incident and recovery arrangements.
  • Control third-party processing.
  • Assign accountable data owners, identifying the accountable function and affected scope.
  • Limit and review access.
  • Minimise collection.

Controls for cyber resilience

In examining cyber resilience: what constitutes adequate evidence, across the defined scope, an isolated example cannot establish consistent operation, and an isolated failure should be evaluated for materiality, recurrence and systemic effect.

Relevant evidence for cyber resilience will normally include lawful authority and consent records where relevant, a register of information assets and purposes, incident response and notification records, retention and secure disposal evidence, and supplier and transfer arrangements. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit.

When examining cyber resilience, decisions concerning the matter should remain traceable to the information available for the stated reference period.

Review of cyber resilience

A competent review of the conclusion should define the proposition to be established, identify the minimum combination of records, test authenticity and reconcile contradictions. Expand the sample where an exception, complaint or material unexplained variation indicates that the initial evidence may not be representative.

For cyber resilience, the final record on the control should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion.

  • Does it cover the material scope?
  • What would require expanded testing?
  • What fact must be established?
  • Is the evidence current and attributable?
  • Do independent sources agree?

Implications for cyber resilience

In examining cyber resilience: what constitutes adequate evidence, for the control, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.

Accountability for the conclusion should follow decision-making authority. Across the defined scope, relevant evidence should reach the body authorised to commit resources, amend policy or accept residual risk, and its judgement should be recorded. For cyber resilience, where work is delegated, the record should continue to identify who is accountable for material consequences to learners.

For cyber resilience, a clear objective, proportionate evidential basis and account of affected learners are required.