11.5.2 Change detection mechanism (FIM)
A change-detection mechanism (e.g., file integrity monitoring) is deployed to alert personnel to unauthorized modification of critical files, with comparisons performed at least weekly.
5
artefacts
2
held by a system
1
at each review
moderate
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- FIM tool configuration and critical file inventory · Source control / CI pipeline
- Sample alerts and triage tickets · SIEM / log platform
periodic reviewEvidence produced at each review
- Weekly comparison reports · Source control / CI pipeline
governing documentDocuments that govern the control
- Coverage matrix across CDE · Policy repository / GRC workspace
- Procedure for change validation · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (Source control / CI pipeline); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- FIM not deployed
- Scope misses critical files
- Weekly cadence not met
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet11.5.1.1 Covert malware channel detection (SP) · 11.6.1 Payment page change and tamper detection