EvidenceSheet

CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner

Evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.

5
artefacts
1
held by a system
3
at each review
hard
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • The deficiency or findings log for the period, with owner, severity, target date and status · SIEM / log platform

periodic reviewEvidence produced at each review

  • Evidence of communication of deficiencies to the parties responsible for corrective action and, where appropriate, to senior management and the board · SIEM / log platform
  • Evidence of timeliness, showing the interval between identification and communication · SIEM / log platform
  • Evidence of remediation and of verification that the corrective action was effective · SIEM / log platform

governing documentDocuments that govern the control

  • The process for evaluating identified deficiencies, including how severity is determined · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations · CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks