EvidenceSheet

7.10 Storage media

Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older sou

5
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Disposal records showing the method used per media type and per classification, with certificates where destruction was outsourced · Vendor register / contract repository

periodic reviewEvidence produced at each review

  • Evidence of protection in transit, including packaging, carrier selection and receipt confirmation · Data governance / DLP tooling
  • Evidence of technical controls over removable media use, such as port restriction and enforced encryption · Data governance / DLP tooling

governing documentDocuments that govern the control

  • Procedures covering media across acquisition, use, transportation and disposal, tied to the classification scheme · Policy repository / GRC workspace
  • The media register or tracking record for removable and archival media, showing location and content classification · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Vendor register / contract repository on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

7.9 Security of assets off-premises · 7.11 Supporting utilities