A.5.6 Contact with special interest groups
Stay plugged into security forums and specialist groups for early warning and shared practice.
16
artefacts
1
held by a system
8
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Action item log tracking mitigation actions derived from group discussions · SIEM / log platform
periodic reviewEvidence produced at each review
- Signed membership agreement for ISACA chapter · Vendor register / contract repository
- Proof of attendance at OWASP conference · HR system / LMS
- Meeting minutes from monthly threat intelligence forum · SIEM / log platform
- Attendance register for quarterly cyber security roundtable · SIEM / log platform
- Webinar attendance certificate for NIST risk workshop · SIEM / log platform
- Record of contributed best practice article to security blog · Document repository
- Quarterly risk register update citing insights from special interest group · Policy repository / GRC workspace
- Management review slide deck referencing external forum findings · Policy repository / GRC workspace
governing documentDocuments that govern the control
- List of subscribed security mailing lists · Document repository
- Renewal invoice for SANS community · Document repository
- Email thread summarizing discussion with industry CERT · Policy repository / GRC workspace
- Shared vulnerability analysis report with industry peers · Policy repository / GRC workspace
- Received early warning bulletin from sector-specific ISAC · Document repository
- Internal memo distributing threat intel from special interest group · Document repository
- Executive summary of emerging threats sourced from specialist community · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Memberships not documented
- Participation limited to passive receipt of emails
- No evidence of internal use of shared information
- Updates not linked to risk assessments
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet