8.34 Protection of information systems during audit testing
Requires audit tests and other assurance activities that assess operational systems to be planned and agreed in advance between the tester and the appropriate management.
5
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Logging and monitoring of the tester's activity, and evidence access was revoked at the end · SIEM / log platform
periodic reviewEvidence produced at each review
- Evidence of read only access where feasible, and of controls where the test required more than read access · Policy repository / GRC workspace
- Records of any operational impact caused by testing and the handling of it · Policy repository / GRC workspace
governing documentDocuments that govern the control
- The procedure requiring audit and assurance tests on operational systems to be planned and agreed with appropriate management in advance · Policy repository / GRC workspace
- Agreements for tests performed in the period, showing scope, timing, method, access granted and the limits placed on the tester · Vendor register / contract repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Testing agreed verbally with no scope document, so the tester and the system owner disagree about what was permitted
- Auditor accounts created with broad access and never removed after the engagement
- Automated scanning run against production with no agreement, causing outage of the system it was meant to assure
- Tester activity unlogged, so the actions taken during the test cannot be separated from anything else that happened
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet