menu
{ "item_title" : "Control Decay in the Digital Enterprise", "item_author" : [" Ravi Sharma "], "item_description" : "Your last audit was clean. So was the one before that. And then something happened anyway.In modern enterprises, controls do not always fail outright. They continue to operate, pass their tests, and produce their evidence. What changes is the world that the controls were designed to govern, and it moves faster than assurance cycles were built to follow. This book introduces Control Decay: what happens when a control continues to operate and pass its tests even though the assumptions that once made it reliable no longer match current conditions.Developed through an analysis of consequential cases, including the Silicon Valley Bank collapse, the CrowdStrike outage of July 2024, and the Boeing 737 MAX MCAS case, the book presents C-DRAFT, a diagnostic framework that names six recurring forces that explain how Control Decay develops and remains hidden: Change Velocity, Dependency Drift, Role Dilution, Automation Opacity, Framework Lag, and Testing Illusion.Established standards help organizations design, monitor, and test controls. They leave each organization to determine whether a control's assumptions still fit the environment it governs, and what to do if they do not. C-DRAFT addresses that specific gap. Rather than replacing established standards such as COSO, COBIT, NIST, or ISO, or the security, engineering, and risk management frameworks organizations rely on day to day, C-DRAFT provides a shared lens through which audit, security, technology, engineering, and risk can read the same control environment. The focus is relevance, not compliance expansion. Control Decay can arise in any environment that changes. What it has lacked is a unified framework that can diagnose and respond to it.What You Will LearnHow to detect Control Decay before failure makes it visible, using C-DRAFT - a diagnostic method that existing frameworks do not supplyHow cloud, AI, automation, and third-party dependencies accelerate Control Decay, and how to govern them without expanding complianceHow audit, security, technology, and risk can read the same control environment through a shared lens and reduce duplicated effortWho This Book is ForThis book is written for professionals responsible for evaluating, designing, or relying on controls in modern enterprises. Internal auditors, technology auditors, cybersecurity professionals, risk managers, GRC leaders, assurance advisors, and control owners will find practical guidance, as will technology and security leaders who rely on audit and risk outcomes to judge whether controls still provide the assurance expected of them.", "item_img_path" : "https://covers2.booksamillion.com/covers/bam/9/79/886/883/9798868830525_b.jpg", "price_data" : { "retail_price" : "39.99", "online_price" : "39.99", "our_price" : "39.99", "club_price" : "39.99", "savings_pct" : "0", "savings_amt" : "0.00", "club_savings_pct" : "0", "club_savings_amt" : "0.00", "discount_pct" : "10", "store_price" : "" } }
Control Decay in the Digital Enterprise|Ravi Sharma

Control Decay in the Digital Enterprise : Why Organizations Pass Audits and Still Fail to Manage Risk

PRE-ORDER NOW:
local_shippingShip to Me
Preorder. This item will be available on February 26, 2027 .
FREE Shipping for Club Members help

Overview

Your last audit was clean. So was the one before that. And then something happened anyway.

In modern enterprises, controls do not always fail outright. They continue to operate, pass their tests, and produce their evidence. What changes is the world that the controls were designed to govern, and it moves faster than assurance cycles were built to follow. This book introduces Control Decay: what happens when a control continues to operate and pass its tests even though the assumptions that once made it reliable no longer match current conditions.

Developed through an analysis of consequential cases, including the Silicon Valley Bank collapse, the CrowdStrike outage of July 2024, and the Boeing 737 MAX MCAS case, the book presents C-DRAFT, a diagnostic framework that names six recurring forces that explain how Control Decay develops and remains hidden: Change Velocity, Dependency Drift, Role Dilution, Automation Opacity, Framework Lag, and Testing Illusion.

Established standards help organizations design, monitor, and test controls. They leave each organization to determine whether a control's assumptions still fit the environment it governs, and what to do if they do not. C-DRAFT addresses that specific gap. Rather than replacing established standards such as COSO, COBIT, NIST, or ISO, or the security, engineering, and risk management frameworks organizations rely on day to day, C-DRAFT provides a shared lens through which audit, security, technology, engineering, and risk can read the same control environment. The focus is relevance, not compliance expansion. Control Decay can arise in any environment that changes. What it has lacked is a unified framework that can diagnose and respond to it.

What You Will Learn

  • How to detect Control Decay before failure makes it visible, using C-DRAFT - a diagnostic method that existing frameworks do not supply
  • How cloud, AI, automation, and third-party dependencies accelerate Control Decay, and how to govern them without expanding compliance
  • How audit, security, technology, and risk can read the same control environment through a shared lens and reduce duplicated effort

Who This Book is For

This book is written for professionals responsible for evaluating, designing, or relying on controls in modern enterprises. Internal auditors, technology auditors, cybersecurity professionals, risk managers, GRC leaders, assurance advisors, and control owners will find practical guidance, as will technology and security leaders who rely on audit and risk outcomes to judge whether controls still provide the assurance expected of them.

Details

  • ISBN-13: 9798868830525
  • ISBN-10: 9798868830525
  • Publisher: Apress
  • Publish Date: February 2027

Related Categories

You May Also Like...

    1

BAM Customer Reviews