EvidenceSheet

SC-37 Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organization-defined]

Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organization-defined].

5
artefacts
0
held by a system
2
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Delivery records for the period, showing recipient verification · Document repository
  • Evidence of what happens when out-of-band delivery fails, and that fallback does not use the primary channel · Document repository

governing documentDocuments that govern the control

  • The defined out-of-band channels employed and the defined information they carry, such as keys, tokens or credentials · Policy repository / GRC workspace
  • The defined individuals or systems the information is delivered to · Document repository
  • Procedure showing the out-of-band channel is genuinely separate from the primary channel · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SC-36 Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined] · SC-38 Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]