SP-02 Review and Approval of Policies and Instructions
Have subject matter experts review the security policies and instructions for adequacy at least once a year, weighing organisational and technical changes in how the cloud service is delivered and legal or regulatory cha
4
artefacts
0
held by a system
3
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Review calendar listing every security document with its next review due date · Policy repository / GRC workspace
- Completed review forms naming the expert who performed the assessment and the outcome · Policy repository / GRC workspace
- Watch list of legal and regulatory developments considered during the review cycle · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Approval evidence dated before the effective date of each revised document · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Review date stamped but content untouched with no rationale for leaving it unchanged
- Revised instructions published into use and approved only afterwards
- Legal monitoring runs separately and never feeds the document review
- Reviews signed by owners who lack the technical knowledge to judge adequacy
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSP-01 Documentation, communication and provision of policies and instructions · SP-03 Exceptions from Existing Policies and Instructions