Common Language in Controls and Application Controls
The output of any policy or process includes a list of quality measures. Quality is measured by a set of controls or tests; each designed to provide feedback or align our actions to those policies and procedures.
A "control" over process is characterized by an ability to:
- Communicates Repeatable Intention
- Executes As Planned (Implementation Plan)
- Measure (Risk Measurement & Impact Analysis)
- Record (Management Reporting & KPI)
- Respond (Thresholds)
- Archive (Defined Data Retention)
- Controls require a visible and recognized:
- Name
- Owner
- Method –(Automation or Manual)
- Program
- Frequency
- Test
- Activity Definition
- Location
- Test Evidence
- Information Processing Objective
- Sequence ID and method of tracking
Quarterly Reports



Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics