EvidenceSheet

A.8.3 Information access restriction

Restrict access to information and assets per the access control policy.

15
artefacts
3
held by a system
4
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Privileged account activity log extracts · Identity provider / directory
  • Audit trail of privileged account changes · Identity provider / directory
  • HR termination notice cross‑referenced with IT ticket · Ticketing / ITSM

periodic reviewEvidence produced at each review

  • System configuration screenshots of role assignments · Identity provider / directory
  • Quarterly access review report · Identity provider / directory
  • Review sign‑off evidence from managers · Identity provider / directory
  • Evidence of disabled accounts after employee exit · Identity provider / directory

governing documentDocuments that govern the control

  • Documented access control policy · Policy repository / GRC workspace
  • Policy approval meeting minutes · Policy repository / GRC workspace
  • Distribution list showing recipients · Policy repository / GRC workspace
  • Role definitions with associated permission matrix · Policy repository / GRC workspace
  • Mapping of roles to business functions · Policy repository / GRC workspace
  • Exception handling register · Policy repository / GRC workspace
  • Index of privileged session recordings · Policy repository / GRC workspace
  • Termination checklist including access revocation steps · HR system / LMS

First move

Mostly documents and reviews. Pull the 3 system-held artefacts from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.8.2 Privileged access rights · A.8.4 Access to source code