EvidenceSheet

SP-02 Review and Approval of Policies and Instructions

Have subject matter experts review the security policies and instructions for adequacy at least once a year, weighing organisational and technical changes in how the cloud service is delivered and legal or regulatory cha

4
artefacts
0
held by a system
3
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Review calendar listing every security document with its next review due date · Policy repository / GRC workspace
  • Completed review forms naming the expert who performed the assessment and the outcome · Policy repository / GRC workspace
  • Watch list of legal and regulatory developments considered during the review cycle · Policy repository / GRC workspace

governing documentDocuments that govern the control

  • Approval evidence dated before the effective date of each revised document · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SP-01 Documentation, communication and provision of policies and instructions · SP-03 Exceptions from Existing Policies and Instructions