What to Provide
An export (or screenshots) demonstrating all active production resources.
Evidence Format
Screenshots or exported images in a common image file type, such as .jpg, .png, or .pdf., exported data table or spreadsheet in a common data file type such as .xlsx or .cvs.
Additional Guidance
Evidence should demonstrate:
Whether or not the resource is related to production or development
Whether that asset stores or accesses customer or sensitive data
How the production inventory was produced
Formal system inventories are used to effectively assign ownership of assets and ensure that all in-scope production systems follow your security policies and standards.
If you use a CSP, you can use your CSP to generate a list of your in-scope production system assets.
For example, AWS allows users to make API calls to generate an asset list of their AWS resources (e.g., EC2 instances, VPCs, datastores).
Example Evidence
AWS (EC2 Instances and RDS)
Associated Unified Control ID | Associated Framework Control |
CTRL-435 | LCL-39 |