AM-03 Commissioning of Hardware
Approve hardware before it enters the production environment through a process that identifies, analyses and mitigates the risks its introduction creates, granting approval only after verifying that error handling, loggi
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Pre release configuration verification checklist naming the tester and recording each result · Source control / CI pipeline
periodic reviewEvidence produced at each review
- Signed commissioning approvals for hardware recently placed into production service · Document repository
governing documentDocuments that govern the control
- Risk analysis produced for the introduction of a new hardware type or model · Document repository
- Build or imaging standard applied to the device before handover to operations · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Source control / CI pipeline); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Equipment racked and cabled into production while the approval is completed retrospectively
- Verification limited to a functional test, leaving security settings unchecked
- Urgent capacity additions routed around the approval process entirely
- Approval signed by the requesting engineer with no independent verification
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAM-02 Acceptable Use and Safe Handling of Assets Policy · AM-04 Decommissioning of Hardware