Audit-log export
A scoped, time-bounded export of system events with provenance sufficient to connect actions, actors and affected objects.
Likely owner: security lead
Evidence, with its limits visible
A policy, an implementation record and evidence that a control operated are not interchangeable. These entries help you describe the artifact you actually have.
A scoped, time-bounded export of system events with provenance sufficient to connect actions, actors and affected objects.
Likely owner: security lead
A dated record showing that selected backup data was restored, checked against defined criteria and followed by recorded actions.
Likely owner: infrastructure lead
A preserved record of the population reviewed, accountable reviewers, decisions, exceptions and completed follow-up actions.
Likely owner: system owner
A dated record connecting a worker’s departure or role change to approved tasks, responsible owners, completion and exceptions.
Likely owner: people lead
A scoped export of identities, account status, groups or assigned applications from a central identity provider at a recorded time.
Likely owner: IT administrator
A dated record of an incident scenario, participants, decisions, observations, actions and follow-up from a tabletop or operational exercise.
Likely owner: security lead
A controlled summary of an authorized security test, including scope, dates, method, high-level findings and remediation status.
Likely owner: security lead
A record that a defined person or population received and acknowledged a particular version of a security policy.
Likely owner: people lead
A dated system report showing the assigned population, training module, completion status and relevant exceptions.
Likely owner: people lead
A maintained list of third parties that process relevant personal data, with service, location, purpose and change information.
Likely owner: privacy lead