EvidenceSheet

8.12 Data leakage prevention

Requires data leakage prevention measures across systems, networks and any other device that processes, stores or transmits sensitive information.

5
artefacts
1
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Configuration of the leakage prevention measures per channel, covering email, web and cloud upload, removable media and endpoint · Endpoint management (MDM / EDR)

periodic reviewEvidence produced at each review

  • Evidence of the detection rules used and how they were tuned to the organisation's own data · Document repository
  • Records of detections, the review of them and the action taken, distinguishing blocked from monitored · Document repository
  • Evidence of governance over the monitoring itself, including privacy and legal review · SIEM / log platform

governing documentDocuments that govern the control

  • Identification of the sensitive information to be protected and of the channels through which it could leave · Document repository

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.11 Data masking · 8.13 Information backup