EvidenceSheet

OIS-05 Contact with Relevant Government Agencies and Interest Groups

Maintain working contact with relevant authorities and security interest groups to obtain current threat and vulnerability intelligence, and feed what is received into the risk handling and vulnerability handling procedu

4
artefacts
1
held by a system
0
at each review
moderate
to go live
Ticketing / ITSM
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Advisories received during the period traced to the tickets or register entries they triggered · Ticketing / ITSM

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Membership confirmations or subscriptions for security interest groups and advisory feeds · Document repository
  • Register of named authority contacts showing the date of the last exchange with each · Policy repository / GRC workspace
  • Notes from information exchange meetings or briefings attended by provider staff · Document repository

First move

Start with the 1 of 4 artefacts that already live in a system (Ticketing / ITSM); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

OIS-04 Segregation of Duties · OIS-06 Risk Management Policy