CPS 230 para 25 Information and Technology Capability and Asset Health
The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monito
3
artefacts
1
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Asset age and health monitoring records including end of life tracking · SIEM / log platform
periodic reviewEvidence produced at each review
- Technology capability assessment against current and projected requirements · Document repository
- Evidence of CPS 234 compliance linkage · Document repository
governing documentDocuments that govern the control
none for this control
First move
Start with the 1 of 3 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Legacy asset age and health untracked
- Capability assessed against current needs only
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCPS 230 para 24 Management of the Full Range of Operational Risks · CPS 230 para 26 Assessment of Business and Strategic Decisions on the Risk Profile