EvidenceSheet

CP-12 Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined]

Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined].

5
artefacts
1
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Design and configuration evidence showing safe mode entry is automatic on the defined conditions · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • Test record of safe mode entry and of the return to normal operation · Document repository

governing documentDocuments that govern the control

  • The defined conditions that trigger entry into safe mode · Document repository
  • The defined restrictions that apply while in safe mode, and what functions remain available · Document repository
  • Operator procedure covering who authorises exit from safe mode and what must be verified first · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Cloud console / configuration management on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CP-11 Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations · CP-13 Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or compromised