SC-41 Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined]
Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined].
5
artefacts
2
held by a system
2
at each review
moderate
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- The defined connection ports or input output devices to be disabled or removed, and the systems or components in scope · Endpoint management (MDM / EDR)
- Configuration evidence showing the ports or devices are disabled or physically removed · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Records of any exception, with approval and compensating control · Document repository
- Verification such as inspection or scan output confirming the state on live systems · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Change control preventing re-enablement without approval · Document repository
First move
Start with the 2 of 5 artefacts that already live in a system (Endpoint management (MDM / EDR)); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Ports disabled in the build image while systems in the field, imaged earlier, remain enabled
- Software disablement that a local administrator can reverse, where physical removal was intended
- No verification, so the disabled state is assumed from policy rather than confirmed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC-40 Wireless Link Protection. Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined] · SC-42 Sensor Capability and Data. Prohibit [organization-defined] ; and Provide an explicit indication of sensor use to [organization-defined]