EvidenceSheet

4.2.1 Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks: • Only trusted keys and certificates are accepted. • Certificates used to safeguard PAN during transmission

Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks: • Only trusted keys and certificates are accepted. • Certificates used to safeguard P.

5
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Captured transmission samples or scan output confirming PAN is not sent in the clear on any open public network path · Vulnerability scanner / patch tooling

periodic reviewEvidence produced at each review

  • Evidence of certificate validity checking, including expiry and revocation status, at the point of transmission · Document repository

governing documentDocuments that govern the control

  • Documented policies and procedures defining trusted keys and certificates, and the protocol and cipher suites accepted · Policy repository / GRC workspace
  • System configurations for each PAN transmission endpoint showing the strong cryptography and protocols implemented · Policy repository / GRC workspace
  • Inventory of trusted keys and certificates in use for safeguarding PAN · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Vulnerability scanner / patch tooling on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

4.1.2 Roles and responsibilities for performing activities in Requirement 4 are documented, assigned, and understood · 4.2.1.1 Inventory of trusted keys and certificates