{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-e3a39062b0cc8a30","slug":"2024-02-06-evidence-across-delivery-settings-for-cyber-resilience","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2024-02-06","last_modified_date":"2024-02-06","title":"Evidence across delivery settings for cyber resilience","summary":"Sets out the scope, decision criteria and evidential basis relevant to evidence across delivery settings for cyber resilience, including the treatment of material limitations.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Growing dependence on digital education infrastructure","reference_authority":"Relevant public authorities and official international sources","sections":[{"heading":null,"paragraphs":["The growing dependence on digital education infrastructure provides the immediate context for cyber resilience. The control, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope.","In relation to evidence across delivery settings for cyber resilience, the intended substantive result should remain the starting point for review. The control, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period. Assurance should not stop at adoption, resourcing or completion of administrative tasks. Implementation evidence should be sufficient to identify unequal consequences and assign corrective responsibility."]},{"heading":"Scope and application of evidence across delivery settings for cyber resilience","paragraphs":["Relevant evidence for cyber resilience will normally include incident response and notification records, role-based access and access reviews, retention and secure disposal evidence, data-quality and correction controls, and lawful authority and consent records where relevant. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. An unresolved contradiction is a limitation on the conclusion and should be reported as such.","The stated reference—the growing dependence on digital education infrastructure—establishes the contemporaneous context. Assurance concerning the assurance question should state the scope examined, evidence relied upon and any condition preventing a complete conclusion. Unsupported elements should remain open. Decision-makers should state which matters are evidenced, which express policy and which require authorised judgement.","In practical terms, the control should be reviewed against a stated method rather than general assurance. The analysis of the control proceeds on the basis that the subject should be examined as a connected system of policy, people, resources, decisions and evidence. Transfer of decisions or records can expose weaknesses not visible in separate reviews of individual controls. The method, assumptions and limitations should be stated in terms suitable for responsible decision-making.","A narrow control over the relevant requirement may create false assurance. In the present context, retention beyond an identified need, uncontrolled supplier access or transfer and inaccurate data affecting decisions may produce acceptable aggregate reporting while individual learners remain exposed to material disadvantage."]},{"heading":"Evidence required","paragraphs":["Implementation of cyber resilience should be organised around a decision that can be tested. For the control, conformity should not be inferred from a policy document alone; operating records and outcomes should show that the stated arrangements are in use. Oversight requires a traceable line from the approved objective through responsible action to evidence of outcome.","The control, governing bodies should receive a concise account of the intended result, affected scope, principal risks, evidence limitations and unresolved exceptions. In relation to evidence across delivery settings for cyber resilience, the action record should identify who is responsible and when implementation is due. An action may be complete while the underlying condition remains, and the two determinations should be recorded separately.","Records relating to the control should preserve both the conclusion and its limits. The correction record should state what the new evidence changes and which earlier conclusions or decisions require review. The correction process should identify prior users and decisions where published information has had material effect."],"bullets":["Provide accessible correction and complaint routes.","Assign accountable data owners before it is relied on for a decision with material effect.","Verify accuracy where information affects learners.","Control third-party processing.","Test incident and recovery arrangements."]},{"heading":"Decision criteria and exceptions","paragraphs":["Implementation of cyber resilience can be tested without imposing unnecessary reporting. A competent review of the assurance question should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. Review should determine whether correction can remain case-specific or must extend across the system. Information should not be treated as sufficient merely because it is already available; its relevance to the present question must be established.","Interpretation of the issue under review should produce a test that another competent reviewer can apply to comparable evidence.","Any conclusion on the issue under review should remain within the scope supported by the evidence. In reviewing the assurance question, security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. Oversight of the stated expectation should reflect the principle that an isolated example cannot establish consistent operation, and an isolated failure should be evaluated for materiality, recurrence and systemic effect. Limitations should be prominent wherever the finding may influence a consequential decision.","The appropriate response to the control is therefore one of controlled implementation and review. The decision record should connect the stated objective to suitable evidence and the position of those affected. Where evidence cannot support assurance, the limitation should be reported and corrective work should remain open."]}],"word_count":785,"content_hash":"sha256-b70721f8fe34805d5c8dd4ff3a067a1dbd7012dbf6b57a736627473d02ca667c","seo_keywords":["evidence across delivery settings for cyber resilience","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
