EvidenceSheet

AIS-05 Automated Application Security Testing

Test applications for security before release against defined acceptance criteria covering new systems, upgrades and versions, automating the testing where the delivery pipeline allows.

4
artefacts
1
held by a system
2
at each review
moderate
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Pipeline configuration showing automated security tests · Source control / CI pipeline

periodic reviewEvidence produced at each review

  • Test results for recent releases, upgrades and new versions · Source control / CI pipeline
  • Records of releases blocked or accepted against the criteria · Document repository

governing documentDocuments that govern the control

  • The documented testing strategy with acceptance criteria for release · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Source control / CI pipeline); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

AIS-04 Secure Application Design and Development · AIS-06 Automated Secure Application Deployment