A.5.32 Intellectual property rights
Implement procedures to protect intellectual property and respect licensing.
20
artefacts
2
held by a system
5
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Software Asset Management Tool Export · Policy repository / GRC workspace
- IP Infringement Incident Log · SIEM / log platform
periodic reviewEvidence produced at each review
- License Compliance Audit Report · Policy repository / GRC workspace
- Third-Party Risk Assessment Report · Vendor register / contract repository
- Employee IP Awareness Training Attendance Sheet · HR system / LMS
- Annual Refresher Training Schedule · HR system / LMS
- Management Review Minutes on IP Incidents · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Enterprise Software License Register · Policy repository / GRC workspace
- License Renewal Calendar · Policy repository / GRC workspace
- Intellectual Property Protection Policy · Policy repository / GRC workspace
- Acceptable Use Policy Addendum · Policy repository / GRC workspace
- Data Classification Scheme for Proprietary Code · Policy repository / GRC workspace
- Policy Change Log · Policy repository / GRC workspace
- Vendor Contract with IP Clauses · Vendor register / contract repository
- Non-Disclosure Agreement Template · Vendor register / contract repository
- Software-as-a-Service Subscription Agreement · Vendor register / contract repository
- E-learning Completion Certificates · HR system / LMS
- Training Materials on Licensing · HR system / LMS
- Root Cause Analysis Report for Unauthorized Use · Document repository
- Corrective Action Plan for License Violation · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your Policy repository / GRC workspace on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Missing up-to-date license inventory
- No documented process for reviewing third-party contracts
- Inadequate employee training on IP obligations
- Failure to record IP breach incidents
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.31 Legal, statutory, regulatory and contractual requirements · A.5.33 Protection of records