A.8.33 Test information
Select, protect and manage test information appropriately.
12
artefacts
2
held by a system
3
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Audit logs showing test data access events · SIEM / log platform
- Disposal certificates for decommissioned test datasets · Data governance / DLP tooling
periodic reviewEvidence produced at each review
- User access request and approval records for test systems · Identity provider / directory
- Records of scheduled test data deletions · Data governance / DLP tooling
- Configuration screenshots showing encryption at rest for test storage · Cloud console / configuration management
governing documentDocuments that govern the control
- Data classification matrix for test environments · Policy repository / GRC workspace
- Labeling policy for test datasets · Policy repository / GRC workspace
- Sample classified test data inventory · Policy repository / GRC workspace
- Access control list for test data repositories · Policy repository / GRC workspace
- Retention schedule for test data · Policy repository / GRC workspace
- Encryption key management procedures for test data · Policy repository / GRC workspace
- Encryption validation reports for test data transfers · Document repository
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Treating test data like production data without classification
- Granting broad access to test data without documented approvals
- Retaining test data far beyond its purpose
- Failing to encrypt test data in non-production environments
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.32 Change management · A.8.34 Protection of information systems during audit testing