What to Provide
Information security policy.
The evidence should demonstrate:
Rules and requirements for the in-scope service environment
Roles and responsibilities of users supporting the in-scope service
Requirement for the policy to be reviewed and approved on an annual basis
Most recent review/approval date
Evidence Format
Exported word processing document in a common file type such as .docx or .pdf.
Associated Unified Control ID | Associated Framework Control |
CTRL-431 | LCL-25 |