8.6.1 If accounts used by systems or applications can be used for interactive login, they are managed as follows: • Interactive use is prevented unless needed for an exceptional circumstance. • Interactive use is limited
If accounts used by systems or applications can be used for interactive login, they are managed as follows: • Interactive use is prevented unless needed for an exceptional circumstance. • Interactive use is limited.
system holds itEvidence a system already holds
- Ticket records · Ticketing / ITSM
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Priority guide · Policy repository / GRC workspace
- Resolution reports · Policy repository / GRC workspace
First move
Common gaps auditors find
- Priority not based on impact and urgency
- Major incidents handled ad-hoc
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.5.1 MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by · 8.6.2 Passwords/passphrases for any application and system accounts that can be used for interactive login are not hard coded in scripts, configuration/property files, or bespoke and custom source code