Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC4.1Selects, develops, and performs ongoing and separate evaluationsSOC 2Monitoring Activities

Official Requirement

COSO Principle 16: The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

You have a systematic process for verifying that controls actually work, not just that they exist. This includes continuous automated monitoring (GRC platform checks, SIEM alerts) and periodic manual evaluations (internal audits, penetration tests, control testing). The combination is what gives you and your auditor confidence that the program is operating, not just documented.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Continuous automated control monitoring via GRC platform

Implementation steps

  1. Deploy vulnerability/configuration management agents on all production servers to continuously monitor for security policy violations, configuration drift, and new vulnerabilities
  2. Configure SIEM rules to alert on high-risk events: failed root login attempts, privileged account use outside business hours, file integrity changes on critical system paths
  3. Run weekly CIS benchmark scans for Tier 1 systems; review the output and open remediation tickets for any new failures
  4. Schedule a monthly control review meeting where the security team reviews your SIEM/monitoring platform alerts, your IDS/network monitoring platform IDS events, and any open control deficiencies

Tools / systems

Evidence artifacts

Evidence frequency: Continuous monitoring; weekly scans (Tier 1); monthly review meetings

Annual penetration test and vulnerability assessment

Implementation steps

  1. Conduct an annual external and internal penetration test; include network, infrastructure, and application layers in scope, with DAST testing against web applications
  2. The pen test report becomes a primary piece of CC4.1 evidence, auditors will review the report, scope, and how findings were remediated
  3. Run DAST scans (OWASP ZAP, Nikto) against staging or pre-production environments on a recurring basis to catch web application vulnerabilities between annual pen tests
  4. Track all findings in the work order system with owner, severity, target date, and closure confirmation
  5. Run vulnerability scans weekly (Tier 1) as a continuous internal evaluation between annual pen tests

Tools / systems

Evidence artifacts

Evidence frequency: Annual pen test; weekly internal scans (Tier 1); finding remediation tracked per SLA