GRC-05 Information Security Program
Operate an information security programme that covers all the domains of the control framework rather than a chosen subset.
4
artefacts
0
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Programme governance records such as reporting and reviews · Document repository
governing documentDocuments that govern the control
- The information security programme description and its domain coverage · Document repository
- A coverage map from programme components to framework domains · Document repository
- Resourcing and ownership per domain · Document repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Programme strong on technical domains and absent on supply chain or privacy
- Coverage asserted with no map, so gaps are invisible
- Domains named with nobody accountable for them
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGRC-04 Policy Exception Process · GRC-06 Governance Responsibility Model