EvidenceSheet

A.8.32 Change management

Put changes to facilities and systems through change management procedures.

12
artefacts
3
held by a system
3
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Submitted change request ticket · Ticketing / ITSM
  • Change request log extract · SIEM / log platform
  • Defect log for change · SIEM / log platform

periodic reviewEvidence produced at each review

  • Signed change approval matrix · Ticketing / ITSM
  • Change advisory board meeting minutes · Policy repository / GRC workspace
  • Post implementation review report · Document repository

governing documentDocuments that govern the control

  • Change request form · Policy repository / GRC workspace
  • Approval email chain · Document repository
  • Test plan document · Policy repository / GRC workspace
  • Test execution report · Document repository
  • Lessons learned register · Policy repository / GRC workspace
  • Verification checklist · Document repository

First move

Start with the 3 of 12 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.8.31 Separation of development, test and production environments · A.8.33 Test information