CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
Evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.
5
artefacts
1
held by a system
3
at each review
hard
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- The deficiency or findings log for the period, with owner, severity, target date and status · SIEM / log platform
periodic reviewEvidence produced at each review
- Evidence of communication of deficiencies to the parties responsible for corrective action and, where appropriate, to senior management and the board · SIEM / log platform
- Evidence of timeliness, showing the interval between identification and communication · SIEM / log platform
- Evidence of remediation and of verification that the corrective action was effective · SIEM / log platform
governing documentDocuments that govern the control
- The process for evaluating identified deficiencies, including how severity is determined · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Findings tracked in a spreadsheet with due dates long passed and no escalation
- Deficiencies reported to the team that owns them and never aggregated for senior management or the board
- Severity assigned informally, so a significant deficiency and a minor observation are treated the same
- Remediation marked complete on assertion with no verification
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations · CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks