EvidenceSheet

8.18 Use of privileged utility programs

Requires the use of utility programs capable of overriding system and application controls to be restricted and tightly controlled.

5
artefacts
1
held by a system
3
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Logs of utility program use and evidence those logs are reviewed · Identity provider / directory

periodic reviewEvidence produced at each review

  • Evidence of restriction, showing who may use them and how that is enforced, including removal from systems where they are not needed · Identity provider / directory
  • Authorisation records for each permitted use, and evidence use is time limited where appropriate · Identity provider / directory
  • Segregation evidence keeping utility use apart from ordinary application use · Identity provider / directory

governing documentDocuments that govern the control

  • Identification of the utility programs capable of overriding system or application controls, per platform · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.17 Clock synchronization · 8.19 Installation of software on operational systems