EvidenceSheet

6.6.4 System and application access control

System and application access control must restrict access to information, provide secure log on, manage passwords, constrain privileged utilities and protect source code, and where the customer requires it the organizat

5
artefacts
3
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Access restriction configuration for applications holding personal data · Identity provider / directory
  • Secure log on mechanisms, including any capability offered to customers for accounts they control · Identity provider / directory
  • Record of customer requirements for log on capability and how they were met · Identity provider / directory

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Password management and privileged utility controls · Policy repository / GRC workspace
  • Source code access controls · Policy repository / GRC workspace

First move

Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

6.6.3 User responsibilities · 6.7.1 Cryptographic controls