Jump to Navigation

 

3.3.12 Provide Account Control Objectives

Unique to accountability, this set of control objectives addresses the privileged communication instrument between the accountor and the accountees, and is the means of demonstrating accountability.

 

Identifier

Control Objective

Lifecycle Phase

3.06

Produce an account reflecting the analysis linking obligations with actual controls must be produced and made available to stakeholders.

3 - Analyse and Design

5.08

Build and distribute an account for the incident, which in particular attributes the failure corresponding to the incident

5 - Handling Exceptions

6.04

Collect the material and perform the analysis which will allow to prepare updated accounts, to include actual indicators of effectiveness.

6 - Audit and Validate

6.05

Perform external audits as dictated by internal criteria, regulations of each domain of accountability, or customer contractual provisions. Certifications or attestations might be used as effective substitutes for client-directed audits

6 - Audit and Validate

 

Table 15: Provide account control objectives.