Evidence of Logins to All In-Scope Production Systems
Provide system screenshots of the login page for each of your in-scope production systems.
For each system, the evidence should demonstrate:
The process used to gain access to the console/backend/operating system of any production resource
How user logins are authenticated (i.e., unique usernames and passwords, secure shell keys)
Additional Guidance
Ensure that your requirements for each in-scope production system align with what you stated in your policy.
Related Articles
Associated Unified Control ID | Associated Framework Control |
CTRL-319 | REQ-25 |