EvidenceSheet

Art.32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and pur

5
artefacts
0
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation · Policy repository / GRC workspace
  • The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out · Vulnerability scanner / patch tooling

governing documentDocuments that govern the control

  • Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate · Policy repository / GRC workspace
  • Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome · Policy repository / GRC workspace
  • Evidence the measures were reassessed after material change in processing, technology or threat · Document repository

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

Art.31 Cooperation with the supervisory authority · Art.33 Notification of a personal data breach to the supervisory authority