12.9.1 TPSP written acknowledgement of responsibility (SP)
Additional requirement for service providers: TPSPs acknowledge in writing to customers that they are responsible for the security of account data they possess or otherwise store, process, or transmit on behalf of the cu
5
artefacts
2
held by a system
1
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Distribution log to customers · SIEM / log platform
- Customer queries log · SIEM / log platform
periodic reviewEvidence produced at each review
- Legal sign-off records · HR system / LMS
governing documentDocuments that govern the control
- Standard customer acknowledgement letter or contract clause · HR system / LMS
- Acknowledgement renewal schedule · HR system / LMS
First move
Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Acknowledgement not distributed
- Language too narrow
- No renewal cycle
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet12.8.5 Responsibility matrix with TPSPs · 12.9.2 TPSP supports customer requests for compliance info (SP)