The demonstration of the operation of measures

Can you prove that security arrangements are actually being implemented?

Internal control information security connects risks, measures, owners, controls, evidence and reporting in a fixed improvement cycle. Kynexis Information Security helps to set up this structure in practice, so that the board and executive management can control the operation and those responsible know what they are doing and demonstrate.

Do you recognize this?
  • Policies and measures have been established, but owners and controls are not clear everywhere.
  • Evidence is only collected when an audit, customer or supervisor asks for it.
  • Derogations and actions are in separate overviews without permanent escalation and follow-up.
  • the board and management receive progress information that says little about actual operation.

What are the risks? Without permanent internal control, agreements remain dependent on persons and moments. Deviations become visible late and detection takes unnecessary time.

Our promise of service

A workable management cycle with clear responsibility

Internal control information security brings risks, measures, controls, evidence and reporting together in a rhythm that suits the organisation.

  • Clear risk and control owners
  • Practical evidence and follow-up
  • Board-level reporting on operation and residual risk

Internal control

What is Internal Control?

Internal control information security connects risks, measures, owners, controls, evidence and reporting in a fixed improvement cycle. Kynexis Information Security helps to set up this structure in practice, so that the board and executive management can control the operation and those responsible know what they are doing and demonstrate.

FOR WHOMFor the board and executive management
WHENA manageable basis for continuing information security
RESULTView of what has been agreed, executed and proven

When does this service fit?

A manageable basis for continuing information security

This service is appropriate when policies and measures are in place, but consistency, ownership, periodic checks or reporting are not yet sufficiently developed. The device can connect to an existing ISMS, integrated risk management or internal control function.

For the board and executive managementFor CISO, risk and qualityFor demonstrable assurance

Practiceal booking

What does working bond look like?

The IT manager can draw the improvement cycle, while management and process owners make decisions on priorities, budget and residual risk. Annual review makes it visible whether agreements have been executed and measures still work.

Management cycle

A identifiable line of risk by decision and evidence

The structure remains proportionate and fits in with existing roles, consultation moments and systems.

Frameworks and risk appetite

Define objectives, policies, standards and board-level limits for risk acceptance.

Risks and measures

Linking risks to appropriate controls, owners and expected operation.

Control and evidence

Determine how operation is monitored and what records or evidence are required.

Derogations and actions

Unique recording and monitoring of deficiencies, incidents and improvement actions.

Management Information

Report clearly key risks, progress, deviations and decision points.

Evaluation and improvement

Periodic assessment of whether risks, measures and priorities are still in line with practice.

Your result

View of what has been agreed, executed and proven

The organisation will have one coherent approach to risks, controls and follow-up. Normity or an equivalent environment can help keep owners, actions and evidence centrally available.

  • Clear control framework and ownership
  • Control calendar and need for proof
  • Unique monitoring of deviations
  • Administratively useful reporting
  • Cyclic evaluation and demonstrable improvement
KYNEXISInternal control
24Controls Followed6Actions open2Decisions necessary
FocusOperation, proof and adjustmentRisk-driven and enforceable

Clear roles

Structure, implementation and independent assessment reinforce each other

Internal control is the way it works. The CISO helps to execute it; Trusted Advisor can periodically indicate the progress and operation independently.

ASSESS

Trusted Advisor

Brings periodically independent reflection and board-level contradiction.

See this route →

How we work

Setting up on the basis of the organisation that is already there

  1. 01

    Inventory

    Bring together frameworks, risks, measures, roles and existing reporting.

  2. 02

    Design

    Controls, owners, control frequency, evidence and escalation logically capture.

  3. 03

    Getting started

    Support the responsible and run the first control cycle.

  4. 04

    Evaluate

    Discuss results administratively and improve the working method in a targeted way.

Policy and evidence

Internal control makes the improvement cycle visible

The organisation shall link risks and decisions to implementation, control and adjustment.

01 FRAMEWORK

Policies and risks

Setting objectives, limits and priorities.

02 CONTROL

Measures and owners

Capture expected operation and responsibility.

04 REPORTING

Board-level interpretation

Clarify derogations, progress and decisions.

05 IMPROVEMENT

Update

Update risks, controls and priorities periodically.

Make your next step concreteStructurally organize internal control?

Discuss how risks, controls, evidence, ownership and reporting can come together in one workable cycle.

Schedule an intake call

Frequently Asked Questions

Practical answers on Internal control

What is internal control of information security?

Internal control is the coherent approach whereby an organisation controls and can be shown to monitor risks, measures, responsibilities, controls, evidence, deviations and improvement.

Is internal control the same as an ISMS?

An ISMS is an information security management system and provides a formal framework. Internal control describes more broadly how measures, controls and reporting work in the daily organisation. Both can be fully connected.

What's the difference with CISO as a Service?

Internal control is the structure and cycle. CISO as a Service is a role that can help set up, execute and monitor this structure. The organisation remains the owner of risks and decisions.

Can Normity be used for internal control?

Yes. Normity can centralise risks, measures, owners, actions and evidence. An equivalent GRC or management environment may also be used.

Wouter Parent

Policy without owner, control and evidence is a plan. Therefore, make visible who performs, who tests and how abnormalities are followed.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates