About this interactive
Administrative controls are the paper side of security: the documentation, policies, standards, procedures and guidelines that say what the organization does; the framework it builds them from; the policies and agreements that bind employees, customers, vendors and partners; the awareness program that makes people know and follow them; and the laws and regulations the whole program has to meet.
This audit draws on the whole module. A process that lives in one person's head. A procedure that is not a set of steps, and a requirement filed as a guideline. A framework used word for word. A payment standard treated as optional because it is not a law. Policies missing for the people who need them. A rule posted but never announced. Training completion mistaken for awareness. A sector-specific law ignored.
Some lines look odd and are exactly right: a guideline that leaves a judgment call to the team, an MSA signed years ago and still in force, an MOU signed before the contract, phishing tests that pretend to come from HR, and GDPR applying to a U.S. company with customers in Europe.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →