EvidenceSheet

COS-05 Networks for administration

Run infrastructure administration and management consoles on networks held physically or logically apart from customer networks and reachable only with multi-factor authentication, and likewise separate the networks used

4
artefacts
2
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Configuration of the segment carrying virtual machine creation and migration traffic · Cloud console / configuration management
  • Rule set blocking routing between management and tenant segments · Policy repository / GRC workspace

periodic reviewEvidence produced at each review

  • Access path evidence requiring more than one factor to reach a management console · Policy repository / GRC workspace

governing documentDocuments that govern the control

  • Topology drawing showing management networks distinct from tenant-facing segments · Policy repository / GRC workspace

First move

Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

COS-04 Cross-network access · COS-06 Segregation of data traffic in jointly used network environments