10.1.2 Requirement 10 roles and responsibilities documented and assigned
Roles and responsibilities for performing the activities in Requirement 10 are documented, assigned and understood, so day-to-day accountability for logging and monitoring is allocated and personnel are accountable for t
5
artefacts
0
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Acknowledgement records where personnel accept their assigned responsibilities · Identity provider / directory
- Interview notes confirming personnel understand what they are responsible for · Identity provider / directory
governing documentDocuments that govern the control
- Documented descriptions of roles and responsibilities for Requirement 10 activities · Policy repository / GRC workspace
- Responsibility assignment matrix (RACI) or equivalent naming responsible and accountable parties · Policy repository / GRC workspace
- Named assignment of each Requirement 10 activity to a role or individual · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Responsibilities described generically as belonging to security with no named owner
- Log review assigned to a team that does not know it owns the task
- Matrix exists but was never communicated or acknowledged
- Assignments not updated after reorganisation or outsourcing
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet10.1.1 Requirement 10 policies and operational procedures documented and maintained · 10.2.1 Audit logs enabled on system components