EvidenceSheet

SI-12 Information management and retention

Requires information held in the system and information produced as output to be managed and retained in line with applicable laws, directives, regulations, policies, standards, guidelines and operational needs, covering

4
artefacts
1
held by a system
2
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Configuration or process evidence implementing retention and disposal · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • Disposal records for information that reached the end of its retention period · Data governance / DLP tooling
  • Coverage evidence for system outputs such as reports, extracts and archives · Document repository

governing documentDocuments that govern the control

  • Retention schedule mapping information types to retention periods and their legal basis · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined] · SI-13 Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provide substitute system components and a means to exchange active and standby