EvidenceSheet

A.5.1 Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

15
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Version control log with change descriptions · SIEM / log platform

periodic reviewEvidence produced at each review

  • Approved amendment minutes · Policy repository / GRC workspace

governing documentDocuments that govern the control

  • Enterprise Information Security Policy · Policy repository / GRC workspace
  • Data Classification Policy · Policy repository / GRC workspace
  • Access Control Policy · Policy repository / GRC workspace
  • Board meeting minutes approving the security policy · Policy repository / GRC workspace
  • Signature page of policy approval · Policy repository / GRC workspace
  • Email chain confirming senior management sign‑off · Policy repository / GRC workspace
  • Distribution register showing recipients and dates · Policy repository / GRC workspace
  • Employee acknowledgment receipts · Policy repository / GRC workspace
  • Internal portal access logs for policy page · Policy repository / GRC workspace
  • Annual policy review calendar · Policy repository / GRC workspace
  • Documented review procedure · Policy repository / GRC workspace
  • Meeting agenda for scheduled policy review · Policy repository / GRC workspace
  • Change request form for policy amendment · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.5.2 Information security roles and responsibilities