Audit/Monitor Controls or Audit/Monitor BEFORE Control?
...monitoring and detection, comes last. It seems to be fairly in line with common sense: you audit the controls after you put them in place; you monitor after you have authentication and authorization taken care of and you detect the violations after you organized your administration
The paper even had the following picture, which is presented...
