Security controls are regularly tested to verify they work as intended
Defining which controls get tested, how often and by whom turns independent review from an occasional exercise into a planned obligation.
This policy control defines in writing which controls get tested, how often and by whom, the testing programme A.5.36's compliance verification depends on.
This Sekit policy defines which controls get tested, how often and by whom, giving security testing before release the planned structure this ISO control requires.