Methods.
Start with the claim that must be trusted and design the system required to support it.
Define the claim
Identify who relies on it and what happens if it is false.
Map the system
Actors, decisions, data, vendors, dependencies, and failure pathways.
Design controls
Specify conduct, boundaries, authority, and intervention points.
Engineer evidence
Define what must be captured, retained, tested, and reviewed.
Operate assurance
Monitor, challenge, escalate, report, and reassess as conditions change.
Working disciplines.
Methods are selected according to the claim, operating context, and consequence of failure.
Claim-to-source validation
Control design and testing
Responsibility mapping
Process and data-flow mapping
Failure-mode analysis
Scenario and stress testing
Red-team and challenge exercises
Evidence architecture
Independent review design
Crosswalks among laws, standards, policies, and controls