sxsphinxstack

Skills / Working / Build a controls evidence map

Working Data skill

Build a controls evidence map

Connect control claims to owners, systems, tests, and current evidence.

Make control claims testable. Policy text can support intent, but operating effectiveness needs evidence from the systems and people performing the control.

Procedure

  1. Define framework, scope, period, entities, environments, assertion owner, and intended audience.
  2. Normalize overlapping requirements into control objectives without losing source traceability.
  3. For each objective, document risk, control activity, frequency, population, performer, reviewer, and enforcement point.
  4. Distinguish manual, automated, inherited, complementary, detective, preventive, and compensating controls.
  5. Attach evidence sources with period, collection method, owner, retention, sensitivity, and integrity checks.
  6. Define design and operating tests, including sample logic and exception handling.
  7. Reconcile claimed populations to authoritative inventories before selecting samples.
  8. Mark evidence as current, stale, incomplete, contradictory, planned, or unavailable.
  9. Track gaps to remediation or time-bounded risk acceptance; never backdate missing performance.
  10. Refresh the map after scope, system, owner, control, or requirement changes.

Guardrails

  • Do not claim compliance merely because every requirement has a row.
  • Protect credentials, personal data, security findings, and vendor confidential material.
  • Screenshots need source, date, scope, and corroboration where state can change.
  • Separate evidence collection from independent evaluation when assurance rules require it.