EvidenceSheet

8.8 Management of technical vulnerabilities

Requires information about technical vulnerabilities in the information systems in use to be obtained, the organisation's exposure to them to be evaluated, and appropriate measures to be taken. Older source material sets

5
artefacts
2
held by a system
1
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Scan results and vulnerability inventory for the period, with authenticated scanning where applicable · Vulnerability scanner / patch tooling
  • Records of alternative measures where no patch exists, and the audit log of actions taken · Vulnerability scanner / patch tooling

periodic reviewEvidence produced at each review

  • Risk assessment records weighing the vulnerability against the risk of applying the patch, and evidence of testing before deployment · Vulnerability scanner / patch tooling

governing documentDocuments that govern the control

  • Defined roles and information sources for vulnerability identification, and the asset scope they cover · Policy repository / GRC workspace
  • The defined reaction timeline by severity, and measurement of actual remediation against it · Policy repository / GRC workspace

First move

Start with the 2 of 5 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.7 Protection against malware · 8.9 Configuration management