EvidenceSheet

SA-4 Acquisition process

Requires acquisition contracts for the system, component or service to include, directly or by reference and using standardised contract language, the security and privacy functional requirements, strength of mechanism a

4
artefacts
0
held by a system
1
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Documented acceptance criteria and the acceptance decision record · Document repository

governing documentDocuments that govern the control

  • Contract or purchase agreement containing the required security and privacy requirement sets · Vendor register / contract repository
  • Standardised contract language or clause library used in acquisition · Vendor register / contract repository
  • Allocation of control responsibility between the organization and the supplier · Vendor register / contract repository

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SA-3 System development life cycle · SA-5 System documentation