Security Controls in ISO 18788: Measurable Assurance through ICE and Combined Assurance

Introduction

In security operations, controls are the backbone of risk management. Clause 6 of ISO 18788:2015 requires organizations to establish and maintain controls to mitigate risks, protect human rights, and deliver professional, ethical, and lawful security services. While ISO 27002 provides structured categories of controls for information security, the same principles can be adapted to the security operations environment.

To move beyond “tick-box compliance,” security controls must be verifiable, repeatable, and validated. This is achieved by applying Internal Control Effectiveness (ICE) to measure performance and embedding controls into a Combined Assurance Model (CAM) to demonstrate reliability to boards, clients, regulators, and communities.

Security Controls in the ISO 18788 Environment

Drawing from ISO 27002 control families but tailoring them to security operations, controls in the SOMS may include:

  1. People Controls (Human Resources & Competence)
    • Vetting, background checks, training, and competence assessments.
    • Ethical awareness and human rights training.
  2. Process Controls (Policies & Procedures)
    • Security policies, SOPs, deployment procedures, and incident management protocols.
    • Use of force guidelines, grievance mechanisms, escalation processes.
  3. System Controls (Operational Management Systems)
    • Rostering, deployment, and incident reporting systems.
    • Risk registers and compliance tracking platforms.
  4. Tools & Equipment Controls
    • Radios, vehicles, personal protective equipment (PPE), firearms, and body-worn cameras.
    • Maintenance and calibration processes.
  5. Technology Controls
    • CCTV with AI analytics, access control systems, drone surveillance.
    • Automated reporting and monitoring technologies.
  6. Compliance & Governance Controls
    • Licensing, legal obligations, contractual compliance, and audits.
    • Alignment with the Montreux Document, ICoC, and human rights frameworks.

Measuring Control Effectiveness with ICE

The Internal Control Effectiveness (ICE) methodology provides structured measurement of each control's effectiveness:

  • Excellent (90%+) - Fully effective, no further treatment needed.
  • Very Good (80%) - Strong control, minor improvements possible.
  • Good (70%) - Majority of risk exposure controlled.
  • Satisfactory (60%) - Basic control in place but not fully managed.
  • Weak to Ineffective (≤ 50%) - Controls exist but major deficiencies remain.
  • No Control (0%) - No evidence of mitigating measures.

Each Management Control (MC) is linked to a Contributing Factor (CF) in the risk register and assessed with ICE. The resulting percentage gives a Level of Assurance (LoA) and helps determine the residual Level of Risk (LoR).

This ensures that security risks are not managed through assumptions or “Fear, Uncertainty, and Doubt (FUD),” but through quantifiable evidence of control performance.

Combined Assurance Mapping of Controls

A Combined Assurance Model (CAM) integrates ICE results into a holistic framework, ensuring that all levels of assurance are addressed:

  • Management (1st Line) - Responsible for implementing controls.
  • Risk & Compliance (2nd Line) - Monitors and validates control effectiveness.
  • Internal Audit (3rd Line) - Provides independent assurance.
  • External Assurance (4th Line) - Certification bodies and regulators.
  • Clients & Stakeholders (5th Line) - External verification through contracts, SLA compliance, and feedback.
  • Community & Society (6th Line) - Human rights, ethical assurance, and social license to operate.

By mapping security controls through these six lines of assurance, organizations can demonstrate transparency, accountability, and stakeholder confidence.

Benefits of Using ICE and Combined Assurance for Security Controls

  1. Objectivity - Provides measurable evidence of control effectiveness.
  2. Traceability - Links each control to specific risks, objectives, and assurance providers.
  3. Transparency - Builds trust with clients, regulators, and communities.
  4. Strategic Decision-Making - Guides leadership on where to strengthen, treat, or redesign controls.
  5. Audit Readiness - Provides structured evidence for certification under ISO 18788 and alignment with ISO 31000 and ISO 37301.

Conclusion

Security controls under ISO 18788 must go beyond being listed in policies—they must be measured and validated. By adopting structured control families (inspired by ISO 27002), applying the ICE methodology for effectiveness measurement, and embedding them into a Combined Assurance Model, organizations can create a powerful, evidence-based framework.

This approach assures clients, regulators, and communities that controls are real, effective, and aligned with international best practice. It also empowers leadership with reliable insights, ensuring that the SOMS is not only compliant but also resilient, ethical, and performance-driven.