EvidenceSheet

SI-15 Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [organization-defined]

Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [organization-defined].

5
artefacts
4
held by a system
1
at each review
easy
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • The defined software programs and applications whose output is validated · Document repository
  • Definition of the expected content that output is validated against · Document repository
  • Configuration of the validation mechanism and its behaviour when output does not match · Cloud console / configuration management
  • Evidence validation covers all output paths from the named applications, including files and interfaces as well as screens · Document repository

periodic reviewEvidence produced at each review

  • Records of outputs rejected or flagged during the period · Document repository

governing documentDocuments that govern the control

none for this control

First move

Automate the pull from your Document repository. Version-controlled document with owner, approval and review date as metadata.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SI-14 Non-persistence. Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined] · SI-16 Memory protection