> For the complete documentation index, see [llms.txt](https://docs.glesys.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.glesys.com/security/security-measures/methods-to-assess-effectiveness-of-cybersecurity-risk-management-measures.md).

# Methods to assess effectiveness of cybersecurity risk management measures

Glesys uses monitoring, internal and external audits to evaluate whether controls are implemented and effective.

### Key elements:

* **Internal audits:** IMS internal audits are performed using a structured audit approach, reporting findings and tracking corrective actions.
* **Control monitoring:** Examples include endpoint compliance checks and log review routines, backup monitoring and restore testing, and supplier performance/security follow-ups based on supplier criticality.
