Appendix A: Examination Procedures

Internal or independent tests or reviews of controls (e.g., penetration tests, business continuity reviews, and third-party management reviews). Regulatory and audit reports on service providers. Review management’s response to issues raised during, or since, the last examination. Consider the following: Adequacy and timing of corrective action. ................
................