Controls that prove they work.
Having a control is not the same as the control working. Most compliance programs can show a policy and a screenshot; few can show a tested verdict — this control was checked, on this date, against this sample, and it held.
NIS2 names the gap directly: policies and procedures to assess the effectiveness of your risk-management measures are a required measure in their own right. TruSecure makes effectiveness a first-class property of every control — a scheduled review, a recorded verdict, a tracked remediation when the verdict is weak.
How it works
- Schedule
Every control carries an effectiveness-review cycle matched to its criticality. The schedule is tracked; a missed review is itself a gap.
- Test
Reviews are performed and recorded against the control: operating as designed, partially effective, or failed — with the method and sample attached, not just the conclusion.
- Remediate
A weak verdict becomes a tracked remediation with an owner and a date, linked to the control it weakens.
- Report
Effectiveness posture rolls up into board reporting continuously, so “are our controls working?” is answered from live state, not from last year’s audit.
What an effectiveness review looks like
- Verdict
- operating as designed
- Method
- sample test · 25 accounts
- Exceptions found
- 1 · remediated
- Citations
- NIS2 21(2)(f) · ISO A.5.35
- Next review
- 2027-03-01
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Policies and procedures to assess effectiveness of measures | Art. 21(2)(f) |
| ISO 27001 | Independent review; compliance with policies assessed | A.5.35 + A.5.36 |
| SOC 2 | Ongoing and separate evaluations of control performance | CC4.1 |
Effectiveness reviews draw on the same evidence automation that feeds everything else — a review starts from the control’s current evidence, so the reviewer’s effort goes into judgment, not into gathering.
This is the clause that separates a compliance program from a paper trail. When every control carries a dated, evidenced verdict, the audit stops being a reconstruction exercise — and the board’s confidence in the dashboard has something underneath it.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.