AC-22 Publicly accessible content
Requires named individuals to be authorized and trained to publish information publicly, content to be reviewed for nonpublic information before it is posted, and published content to be re-reviewed on a defined frequenc
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- List of individuals authorized to publish, with evidence of the training they received · Identity provider / directory
- Pre-publication review records showing sign-off before posting · Identity provider / directory
- Periodic sweep results of live public content against the defined review frequency · Identity provider / directory
- Removal or takedown records for nonpublic information found on public surfaces · Identity provider / directory
governing documentDocuments that govern the control
none for this control
First move
Common gaps auditors find
- Marketing and product teams publish directly with no review step
- Review covers the website but not public code repositories, file shares or open storage buckets
- Periodic re-review never scheduled, so old pages retain information that later became sensitive
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAC-21 Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organization-defined] ; and Employ [organization-defined] to assist users in making information · AC-23 Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining