EvidenceSheet

CC6.8 Controls to prevent or detect unauthorized or malicious software

Implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.

5
artefacts
1
held by a system
3
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Controls preventing or detecting introduction of unauthorised or malicious software, covering endpoints, servers and, where relevant, the build pipeline · Endpoint management (MDM / EDR)

periodic reviewEvidence produced at each review

  • Evidence of restriction on installation of unauthorised software, such as removal of administrative rights or application allow listing · Identity provider / directory
  • Detection records for the period and evidence of the action taken · Identity provider / directory
  • Evidence of controls over software introduced through the supply chain, including third party components · Identity provider / directory

governing documentDocuments that govern the control

  • Coverage reporting for protective software, showing devices covered, devices not covered and definition currency · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CC6.7 Transmission of data is restricted to authorized users · CC7.1 Detection and monitoring procedures for security events are in place