EvidenceSheet

SI-10 Information input validation

Requires the validity of organization-defined information inputs to be checked, so that data entering the system is verified for syntax, type and value before it is processed.

4
artefacts
0
held by a system
2
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Design or code evidence of server side validation rules · Cloud console / configuration management
  • Test results including negative testing with malformed input · Source control / CI pipeline

governing documentDocuments that govern the control

  • Documented list of information inputs subject to validation · Document repository
  • Handling procedure for inputs that fail validation · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SI-8 Spam Protection. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and Update spam protection mechanisms when new releases are available in accordance with organizational configuration · SI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined]