Skip to main content
PLATFORM · CONTROL EFFECTIVENESS

Controls that prove they work.

Having a control is not the same as the control working. Most compliance programs can show a policy and a screenshot; few can show a tested verdict — this control was checked, on this date, against this sample, and it held.

NIS2 names the gap directly: policies and procedures to assess the effectiveness of your risk-management measures are a required measure in their own right. TruSecure makes effectiveness a first-class property of every control — a scheduled review, a recorded verdict, a tracked remediation when the verdict is weak.

How it works

  1. Schedule

    Every control carries an effectiveness-review cycle matched to its criticality. The schedule is tracked; a missed review is itself a gap.

  2. Test

    Reviews are performed and recorded against the control: operating as designed, partially effective, or failed — with the method and sample attached, not just the conclusion.

  3. Remediate

    A weak verdict becomes a tracked remediation with an owner and a date, linked to the control it weakens.

  4. Report

    Effectiveness posture rolls up into board reporting continuously, so “are our controls working?” is answered from live state, not from last year’s audit.

What an effectiveness review looks like

Effectiveness review · privileged MFASample data
Verdict
operating as designed
Method
sample test · 25 accounts
Exceptions found
1 · remediated
Citations
NIS2 21(2)(f) · ISO A.5.35
Next review
2027-03-01

Which regulations it maps to

Effectiveness obligations · by framework
FrameworkWhat it expectsCitation
NIS2Policies and procedures to assess effectiveness of measuresArt. 21(2)(f)
ISO 27001Independent review; compliance with policies assessedA.5.35 + A.5.36
SOC 2Ongoing and separate evaluations of control performanceCC4.1

Effectiveness reviews draw on the same evidence automation that feeds everything else — a review starts from the control’s current evidence, so the reviewer’s effort goes into judgment, not into gathering.

This is the clause that separates a compliance program from a paper trail. When every control carries a dated, evidenced verdict, the audit stops being a reconstruction exercise — and the board’s confidence in the dashboard has something underneath it.

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.