A.5.4 Management responsibilities
Require every staff member to actually apply the policies and procedures, not just acknowledge them.
16
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Change‑management tickets with approval signatures · SIEM / log platform
periodic reviewEvidence produced at each review
- Compliance dashboard screenshots summarizing departmental compliance metrics · Cloud console / configuration management
governing documentDocuments that govern the control
- Signed acknowledgment forms for each security policy · HR system / LMS
- Electronic acknowledgment audit trail from the policy portal · Policy repository / GRC workspace
- Distribution list showing dates policies were sent to staff · HR system / LMS
- Version control register linking acknowledgments to policy revisions · HR system / LMS
- Attendance sheets for mandatory policy training sessions · HR system / LMS
- E‑learning completion certificates with timestamps · HR system / LMS
- Competency assessment results tied to policy responsibilities · HR system / LMS
- Annual training plan mapping staff roles to required policy modules · Policy repository / GRC workspace
- System access logs demonstrating actions required by the policy · Policy repository / GRC workspace
- Work order records confirming execution of policy‑driven tasks · Policy repository / GRC workspace
- Incident handling logs showing adherence to response procedures · Policy repository / GRC workspace
- Manager performance review notes referencing policy compliance · Policy repository / GRC workspace
- Internal audit reports on staff adherence to policies · Policy repository / GRC workspace
- Corrective action reports issued for non‑compliance findings · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Relying on one‑time acknowledgment without ongoing verification
- Missing records of actual policy execution
- No supervisory follow‑up on compliance
- Training not linked to specific policy responsibilities
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.3 Segregation of duties · A.5.5 Contact with authorities