EvidenceSheet

SI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined]

Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined].

5
artefacts
3
held by a system
1
at each review
easy
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Documentation of the structure and content of error messages generated by the system · Document repository
  • The defined personnel or roles to whom error messages are revealed, and the configuration enforcing that · Identity provider / directory
  • Test evidence showing error output at the user boundary under failure conditions · Document repository

periodic reviewEvidence produced at each review

  • Evidence error messages carry what is needed for corrective action without revealing exploitable detail such as stack traces, queries or paths · Policy repository / GRC workspace

governing documentDocuments that govern the control

  • Retention and access rules for the detailed error information kept for diagnosis · Policy repository / GRC workspace

First move

Automate the pull from your Document repository. Version-controlled document with owner, approval and review date as metadata.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SI-10 Information input validation · SI-12 Information management and retention