Trust · Policies
DOC-29
Internal audit and management review
The internal audit programme and the management review, performed at the scope one person can honestly perform them at, with the limitation stated rather than designed around.
The limitation, first
Internal audit requires that auditors do not audit their own work. One person cannot satisfy that, and no amount of procedure makes it satisfiable. This document does not claim otherwise, and the internal audit rows on the register stay partial rather than being marked met on the strength of what follows.
What was available was a choice between three things: write a document asserting an audit programme that has never run, mark the clause excluded, or perform the parts that are genuinely performable and state exactly which part is missing. The first fails an audit faster than an open gap. The second is not available at all — the management system clauses of ISO/IEC 27001 are requirements, and only Annex A controls can be excluded through the Statement of Applicability. So the third, which is what this is.
Three Annex A controls are excluded, and those genuinely can be: segregation of duties, independent review of information security, and security awareness training. Each is excluded on the same ground — they presume more than one person — and each re-enters scope on the first hire. That justification is recorded on the register rows themselves, which is where a Statement of Applicability is read.
The internal audit programme
Frequency and method: a full pass over both standards every ninety days, and a targeted pass over any area a deployment changed, in the deployment that changed it. The method is evidence-first — a row is examined by opening the route it cites and checking that the route shows the control operating, not by asking whether the control is believed to work.
Criteria and scope: both standards in full, every clause and every Annex A control, against the running service at the deployed version. Nothing is sampled out. The register carries all 184 rows precisely so that a pass cannot quietly skip a section.
What was performed at this version: every evidence link on every row fetched and checked, including anchor resolution; every met row checked for a citable route; every status changed in this pass re-derived from the code or the record behind it rather than from the previous note; and the backup control tested by execution rather than by inspection, which is the test that found N-05.
What that pass is missing, precisely: objectivity. The person who checked the rows is the person who wrote them and the code beneath them. A reviewer with no stake would examine the same evidence with a motive this one structurally lacks, and would be more likely to notice a claim that reads well and does not quite hold. Nothing in this programme substitutes for that, and the register does not pretend it does.
The compensating property, offered as what it is: the evidence is public, machine-readable, and mechanically checkable by anyone. The checker is committed with the service. That does not make the audit independent — it makes it independently repeatable, which is a weaker thing and worth exactly what it is worth.
Management review
Performed at this version. Management review, unlike internal audit, does not require independence — it requires top management to review the system at planned intervals against defined inputs and to produce defined outputs. That is performable by one person, and it has been performed.
Inputs considered. Status of actions from the previous review: this is the first, so none. Changes in external and internal issues: none material; the service, its scope, its supplier and its single-person resourcing are unchanged. Performance: availability at 100 per cent for the server with no unscheduled downtime, metered spend well below the ceiling, no unscheduled outage, and the receipt chain verifying on every read. Nonconformities and corrective actions: five recorded, four closed, one — N-03 — corrected in its description with the underlying shortfall left open as R-12. Monitoring and measurement results: the evidence-link walk at 46 routes with no failures, and the restore drill passing on a digest comparison against the copy read back out of object storage. Audit results: as above, with the objectivity limitation. Feedback from interested parties: no security reports requiring action beyond receipting, and no player complaints received through any channel. Risk assessment results: twelve risks assessed, three left open — the unscanned dependencies, the missing erasure route, and the manual evidence walk. Opportunities for continual improvement: as below.
Outputs — decisions taken. First: the backup gap is closed and will not be reopened by treating the drill as optional; a failed scheduled copy is to be treated as an incident rather than as a retry. Second: dependency scanning stays open and is the next engineering item, ahead of further documentation, because the register is now closer to its documentation ceiling than to its engineering one. Third: the player erasure route is the item after that, and the leaderboard question it depends on is to be decided before the route is built rather than during. Fourth: the supplier certificates are to be obtained and held on file, because fourteen rows currently rest on an undischarged condition. Fifth: no change to the scope, the policy set's structure or the resourcing is required.
Changes needed to the management system: none structural. The suitability, adequacy and effectiveness of the system are judged sufficient for its scope, with the two named exceptions — audit objectivity and the undischarged supplier condition — which are limitations of the arrangement rather than defects in it.
Leadership and commitment
With one person, leadership is not demonstrated by delegation or by requiring others to comply. It is demonstrated by what was chosen when nobody was watching, and the evidence for it is on public routes.
The policy and objectives are established, published and compatible with the service's direction. Resources are provided to the limit that exists and the limit is stated rather than implied. The management system's requirements are integrated into the service's own processes to the point where they are the same processes — a control action cannot occur without a receipt, and a document cannot be published without a version.
The specific commitment worth pointing at: the register's honesty rule was written into the source of the register itself and has cost readiness percentage at every pass, including this one. Rows that could have been marked met on an assertion are marked partial, and a control that failed its first test has that failure on a public chain. Direction of that kind is cheap to claim and expensive to keep, and the record of keeping it is the register's own history.
Competence and awareness
Competence required, determined: the runtime and its storage model; the two standards well enough to read a clause and know what evidence it asks for; web security sufficient for the controls claimed — transport, content policy, authentication, input handling; and the specific competence that this design depends on, which is knowing the difference between a control that operates and a control that can be evidenced.
Competence held, and its basis: the service itself is the evidence, and it is an unusually direct one. The controls claimed are implemented and are demonstrable from public routes; the clause readings are visible in 184 rows an assessor can disagree with; and the errors made are on the record with their causes, which is a more useful competence record than a certificate would be. No formal qualification in either standard is held, and that is stated rather than left to be inferred.
Competence not held, and its consequences: no independent audit competence, which is the objectivity limitation above and not a training gap. No dependency-scanning tooling competence has been applied, because no such tooling is in use — that is a resourcing decision recorded as R-06, and it would be dishonest to record it as a gap in the person rather than in the system.
Awareness: the person doing the work is the person who wrote the policy, set the objectives and decided each control status. Awareness of the policy, of their contribution to the system's effectiveness, and of the implications of not conforming is therefore direct rather than communicated — the implication of not conforming being that the register becomes untrue, which is the failure this whole arrangement is built to prevent. Stated for completeness rather than because it needed establishing, and the corresponding Annex A training control is excluded rather than dressed up as satisfied.