SI-23 Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organization-defined]
Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organ.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- The defined circumstances on which fragmentation is based, such as a threat assessment or risk trigger · Document repository
- The defined systems or components across which fragments are distributed, with evidence of the actual distribution · Document repository
- Evidence that no single location holds enough fragments to reconstruct the information · Document repository
governing documentDocuments that govern the control
- The defined information fragmented and the fragmentation method used · Document repository
- Reconstitution procedure and evidence it has been tested · Policy repository / GRC workspace
First move
Common gaps auditors find
- Fragments distributed across systems that share one administrator, one key or one storage platform
- Reconstitution never tested, so availability of the fragmented information is unproven
- Fragmentation applied without an assessment of how many fragments actually reveal the content
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSI-22 Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of · SR-1 Policy and procedures for supply chain risk management