An auditor observes a service organization's access provisioning process and notices that the approval form requires manager sign-off, but three of ten sampled tickets lack any approval documentation. The control is designed correctly, but it is not operating effectively. That distinction drives every finding in a security assessment.
AICPA Representative Tasks (verbatim). 1. Application, Perform procedures to obtain an understanding how the entity communicates information to improve security knowledge and awareness and to model appropriate security behaviors to employees through a security awareness training program. 2. Application, Provide input into a security assessment report by documenting the issues, findings and recommendations identified while performing tests of controls. 3.
Security Awareness Training Evaluation
HIGH-FREQUENCY: Security awareness programs are preventive controls targeting the human layer, often the weakest link in security architecture. The exam tests whether you can evaluate program effectiveness, not just confirm that training exists.
Effective evaluation covers three dimensions:
KEY: Completion rates alone do not demonstrate effectiveness. A 100% completion rate with a 40% phishing simulation click rate indicates the training is not changing behavior.
Common mistakes
- Confusing design deficiency with operating deviation. Design asks "would this work if followed?" Operating asks "was it followed?" A control that requires manager approval but allows bypass is a design deficiency. A control that requires manager approval and was not obtained in three of ten samples is an operating deviation. Remediation differs: redesign versus enforcement.
- Testing existence rather than effectiveness. Confirming that a policy document exists is not testing. Testing requires evidence that the policy is implemented and followed. "The organization has a security awareness policy" is not a finding; "12% of employees did not complete required training" is a finding.
- Accepting training completion rates as proof of awareness. Completion metrics measure exposure, not learning. Phishing simulation results, incident report rates, and interview responses measure whether training changed behavior.
Bottom line
- Security awareness training must be evaluated for communication clarity, leadership behavior modeling, and coverage of all access-holding populations, not just completion rates.
- Security assessment findings use a five-part structure: condition (what exists), criteria (what should exist), cause, effect, and recommendation, each specific and evidence-based.
- Walkthroughs trace a single transaction from initiation through completion, comparing observed procedures against documented policy to identify gaps.
- SOC 2 engagements evaluate controls against the Trust Services Criteria; security is always in scope, and the other four (availability, processing integrity, confidentiality, privacy) depend on service commitments.
Exam shortcut
Design vs. Operating mnemonic: "Would it work? Did it work?" Two questions, two possible failures, two different remediations. Five-part finding structure: "C-C-C-E-R." Condition, Criteria, Cause, Effect, Recommendation. If your finding is missing any element, it is incomplete. Condition without criteria is an observation without context; criteria without recommendation leaves management without a path forward. Excluded populations = design gap.
The full lesson (about 2,972 words, 20 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- II.B3
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.