EvidenceSheet

SI-23 Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organization-defined]

Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organ.

5
artefacts
0
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • The defined circumstances on which fragmentation is based, such as a threat assessment or risk trigger · Document repository
  • The defined systems or components across which fragments are distributed, with evidence of the actual distribution · Document repository
  • Evidence that no single location holds enough fragments to reconstruct the information · Document repository

governing documentDocuments that govern the control

  • The defined information fragmented and the fragmentation method used · Document repository
  • Reconstitution procedure and evidence it has been tested · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SI-22 Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of · SR-1 Policy and procedures for supply chain risk management