EvidenceSheet

8.3.1 All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you

All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you.

5
artefacts
1
held by a system
2
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • For each type of authentication factor, observation or configuration evidence that access is authenticated using it · Identity provider / directory

periodic reviewEvidence produced at each review

  • Evidence no access path permits access without authentication · Identity provider / directory
  • Records for non-console and console access alike · Identity provider / directory

governing documentDocuments that govern the control

  • Documentation describing the authentication factors used for user and administrator access to system components · Policy repository / GRC workspace
  • Inventory of in scope system components and the authentication method for each · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.2.8 Session idle timeout · 8.3.2 Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components