Monitoring of Security Controls under ISO 18788

Introduction

Security controls are the foundation of operational resilience in security companies. Whether preventive (e.g., access gates, cameras), detective (e.g., alarms, patrols), or corrective (e.g., incident response procedures), controls are only as effective as their ability to perform consistently in practice.

Clause 9.1 of ISO 18788 requires organizations to establish processes for monitoring the performance of security controls, ensuring that they remain effective, efficient, and aligned with risk treatment objectives. This is where the Control Catalogue becomes a living tool, moving beyond documentation into measurable assurance.

Why Monitoring is Critical

  1. Verification of Effectiveness - Ensures controls operate as designed and achieve their intended outcomes.
  2. Early Warning - Detects failing or weakened controls before they result in incidents.
  3. Risk Management - Provides input into tactical and strategic risk registers.
  4. Accountability - Creates an auditable record for compliance with ISO 18788 and client contracts.
  5. Resource Allocation - Demonstrates which controls are worth continued investment versus those requiring redesign or retirement.

Methods of Monitoring Security Controls

1. Operational Monitoring

  • Daily or shift-based checks of access points, patrol logs, equipment readiness.
  • Examples:
    • Reviewing CCTV feeds for coverage gaps.
    • Checking alarm system logs.
    • Guard post inspections.

2. Technical Monitoring

  • Use of systems and tools to capture performance metrics.
  • Examples:
    • Electronic key management logs.
    • Automated access card reports.
    • Incident management dashboards.

3. Internal Control Effectiveness (ICE) Assessment

  • Structured methodology to rate each control as:
    • Effective - Consistently achieves objectives.
    • Partially Effective - Works under some conditions but not all.
    • Ineffective - Does not achieve objectives or fails repeatedly.
  • ICE results feed directly into Combined Assurance Models, aligning tactical assurance testing with strategic reporting.

4. Performance Indicators (KPIs/KRIs)

  • Defining measurable indicators for controls.
  • Examples:
    • % of patrols completed on time.
    • % of access rejections for unauthorized persons.
    • % of incidents detected by surveillance systems vs. reported externally.

Link to the Control Catalogue

The Control Catalogue serves as the baseline for monitoring. Each control must have:

  • Unique Identifier: Control number/code.
  • Objective: What the control is meant to achieve.
  • Control Strategy: Preventive, detective, corrective.
  • Monitoring Method: Daily log, ICE assessment, system report, KPI.
  • Responsible Role: Guard, supervisor, manager.
  • Audit Evidence: Records demonstrating monitoring.

Example:

  • Control ID: PS-07 (Perimeter Surveillance).
  • Objective: Detect unauthorized entry attempts.
  • Strategy: Detective.
  • Monitoring Method: Daily review of CCTV coverage logs.
  • Responsible Role: Control room supervisor.
  • Audit Evidence: CCTV playback logs, supervisor sign-off.

Integration with Risk and Performance

  • Operational Level: Guards and supervisors monitor controls daily.
  • Tactical Level: Managers review aggregated monitoring results to identify weaknesses.
  • Strategic Level: Executives use monitoring data to evaluate whether risk treatment plans remain aligned with organizational objectives.

This creates a golden thread from control catalogue → monitoring results → risk registers → strategic decisions.

Documentation and Audit Evidence

Auditors will expect to see:

  • Control Catalogue with monitoring methods defined.
  • Monitoring Records: Daily logs, system reports, ICE assessments.
  • Trend Analysis Reports: Showing control performance over time.
  • Corrective Action Logs: Adjustments made based on monitoring findings.
  • Management Review Minutes: Evidence that results inform strategic decision-making.

Audit Evidence Reliability (AERM):

  • Most reliable: Automated system logs, CCTV playback, biometric reports.
  • Moderate: Supervisor checklists, ICE rating sheets.
  • Least reliable: Verbal assurance without documentation.

Conclusion

Monitoring of security controls is the first step in performance evaluation under Clause 9.1 of ISO 18788. It ensures that the Control Catalogue is not a static document but a dynamic system of assurance that provides measurable confidence to clients, regulators, and communities.

By embedding daily operational checks, technical monitoring, ICE assessments, and performance indicators, organizations create a structured way to evaluate, improve, and justify security controls.

This process turns monitoring into both a compliance requirement and a business intelligence tool, guiding investment decisions between reactive costs and proactive security measures.