EvidenceSheet

RA-6 Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined]

Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].

5
artefacts
0
held by a system
5
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • The defined locations and the defined frequency or events at which a technical surveillance countermeasures survey is employed · Policy repository / GRC workspace
  • Survey reports for the period, produced by the surveying party · Policy repository / GRC workspace
  • Findings raised by surveys and the remediation of each · Policy repository / GRC workspace
  • Evidence of survey trigger events such as post construction or post visitor access · Physical access / facilities
  • Handling and distribution controls over the survey reports themselves · Policy repository / GRC workspace

governing documentDocuments that govern the control

none for this control

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

RA-5 Vulnerability monitoring and scanning · RA-7 Risk response