{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-84d9fe32e0ca9720","slug":"2024-05-09-cyber-resilience-what-constitutes-adequate-evidence","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2024-05-09","last_modified_date":"2024-05-09","title":"Cyber resilience: what constitutes adequate evidence","summary":"Sets out the scope, decision criteria and evidential basis relevant to cyber resilience: what constitutes adequate evidence, including the treatment of material limitations.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Growing dependence on digital education infrastructure","reference_authority":"Relevant public authorities and official international sources","sections":[{"heading":null,"paragraphs":["In 2024, consideration of cyber resilience must take account of the growing dependence on digital education infrastructure and the responsibilities it places before education systems. For the relevant requirement, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope.","A narrow control applied to the relevant process may create false assurance. In the present context, retention beyond an identified need, secondary use without adequate authority and inaccurate data affecting decisions may produce acceptable aggregate reporting while individual learners remain exposed to material disadvantage. The test should deliberately include exceptions and cases in which the expected outcome was not achieved."]},{"heading":"Applicable scope","paragraphs":["Responsibility for cyber resilience should be visible at the point where consequential decisions are made. For the issue under review, a provider should be able to trace the expectation from approved policy through implementation, monitoring, identified exceptions and corrective action. In relation to cyber resilience, incomplete evidence, unmanaged conflict, absent learner groups or material learner impact require a higher level of review.","The reference point is the growing dependence on digital education infrastructure. Assurance concerning the issue under review should state the scope examined, evidence relied upon and any condition preventing a complete conclusion. Unsupported elements should remain open. That distinction should remain visible in the decision record, public reporting and later review.","A focused examination of the assurance question requires a clear analytical discipline. The analysis of the issue under review proceeds on the basis that evidence should be relevant to the stated requirement, sufficiently complete for the affected scope, current for the decision period and attributable to a source with knowledge or control of the matter. Volume does not cure a gap in relevance. A formally complete record is not reliable if its scope or measure does not correspond to the decision being made."],"bullets":["Test incident and recovery arrangements.","Control third-party processing.","Assign accountable data owners, identifying the accountable function and affected scope.","Limit and review access.","Minimise collection."]},{"heading":"Implementation and evidence","paragraphs":["Proportionality in relation to cyber resilience does not mean reduced protection for learners exposed to greater risk. The analysis of the control proceeds on the basis that security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. A decision concerning the assurance question should recognise that an isolated example cannot establish consistent operation, and an isolated failure should be evaluated for materiality, recurrence and systemic effect. In relation to cyber resilience, no exception should continue without a documented basis, accountable approval and scheduled review.","Relevant evidence for cyber resilience will normally include lawful authority and consent records where relevant, a register of information assets and purposes, incident response and notification records, retention and secure disposal evidence, and supplier and transfer arrangements. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. An unresolved contradiction is a limitation on the conclusion and should be reported as such.","Decisions concerning the issue under review should remain traceable to the information available for the stated reference period. Without this distinction, a reporting change may be mistaken for improvement or deterioration in educational practice."]},{"heading":"Assessment of conformity","paragraphs":["Implementation of cyber resilience can be tested without imposing unnecessary reporting. A competent review of the assurance question should define the proposition to be established, identify the minimum combination of records, test authenticity and reconcile contradictions. Expand the sample where an exception, complaint or material unexplained variation indicates that the initial evidence may not be representative. Reuse of existing information is appropriate only where its purpose, scope and reliability correspond to the decision under review.","The final record on the control should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. Departure from an illustrative method may be justified where equivalent outcome and evidence are established. A limitation preventing a complete conclusion should remain visible and unresolved until suitable evidence is obtained."],"bullets":["Does it cover the material scope?","What would require expanded testing?","What fact must be established?","Is the evidence current and attributable?","Do independent sources agree?"]},{"heading":"Review and corrective action","paragraphs":["For cyber resilience, the public interest is not confined to institutional compliance. For the control, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.","Accountability for the assurance question should follow decision-making authority. Relevant evidence should reach the body authorised to commit resources, amend policy or accept residual risk, and its judgement should be recorded. Where work is delegated, the record should continue to identify who is accountable for material consequences to learners.","The appropriate response to the assurance question is therefore one of controlled implementation and review. A clear objective, proportionate evidential basis and account of affected learners are required. The decision record should state the unsupported element and the further work required."]}],"word_count":831,"content_hash":"sha256-2806fa87ecc687b72507591105c5ae507a63fdba691fc127a31d6719e3a071e2","seo_keywords":["cyber resilience","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
