Skip to content

Walk-Through

What is Walk-Through?

An audit procedure in which the auditor traces a single transaction from initiation through final recording to verify that controls are in place and operating as described. Walk-throughs are used to understand and document business processes.

Audit

Each of these is named in at least one of the same controls as walk-through. The number is how many controls name both.

What the standards actually require on walk-through

Requirements naming walk-through across 5 standards, quoted from the control text.

A replay/purple-teaming workshop is held where the red and blue teams walk through the attack scenarios together to maximise learning.

TIBER-3.3 · Replay and purple teaming workshop

HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.

HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

Chapter 4 establishes passenger + baggage screening requirements. 4.3 Measures Relating to Passengers + Cabin Baggage - each State shall establish measures to ensure originating passengers of international flights + their cabin baggage are screened + prevented...

ICAO-ANX17-Chap4-PassengerScreening-CabinBaggage-HoldBaggage-100Percent-EDS · ICAO Annex 17 Chapter 4 - Passenger Screening + Cabin Baggage + Hold Baggage 100 Percent + Explosive Detection Systems (EDS)

Requirements for verification methods including reviews, inspections, walk-throughs, and testing.

ISO-26262-8-9 · Verification

Questions people ask about walk-through

What is Walk-Through?
An audit procedure in which the auditor traces a single transaction from initiation through final recording to verify that controls are in place and operating as described. Walk-throughs are used to understand and document business processes.
Why is Walk-Through important for compliance?
Walk-Through is a key concept in Audit. Understanding walk-through helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Walk-Through?
Walk-Through appears in the requirement text of ECB TIBER-EU Framework, HKMA Cyber Resilience Assessment Framework (C-RAF), ICAO Annex 17 - Aviation Security (AVSEC), ISO 26262:2018 - Functional Safety for Road Vehicles, Japan FSA Cybersecurity Guidelines for Financial Institutions. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Walk-Through?
Explore our compliance framework pages to see how walk-through applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Walk-Through applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.