ExportableProof — Routines today. Proof tomorrow.

Arcfield A.8 · Technological audit

Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION

How this report is elaborated

Scope is the Volume 1 A.8 · Technological audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (certification, assets).

The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.

How to read this report

Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.

Results at a glance

3 %Conformity32/33 NC. Share without an NC. DK/NA are out of the denominator. Not a certification statement.
12 %Defined4/33 yes. Defined = yes / rated artefacts or identities. partially is not yes.
18 %Implemented6/33 yes. Implemented = yes / rated artefacts or identities. partially is not yes.
0 %Effectiveness0/6 yes. Effective = yes / rated artefacts or identities. partially is not yes.

Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.

How A.8 · Technological is set up

Contract Security Schedule
Vol. 2not installeddocumentedPremium

Named documented evidence. Not in this pack.

Artefact

Asset Management Policy
Vol. 1installeddocumentedPremium

Documented evidence in this pack. Not a certification PASS.

Artefact

Access Control Matrix
Vol. 2Vol. 3not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Mandatory Documents and Records Register
Vol. 2not installedimplementedBasic

Named implemented evidence. Not in this pack.

Artefact

Document Register
Vol. 1Vol. 2installedimplementedPremium

Implemented evidence in this pack. Not a certification PASS.

Artefact

Records Retention Schedule
Vol. 2not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Asset Inventory
Vol. 1Vol. 2Vol. 3installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Users and Access Inventory
Vol. 2Vol. 3not installedimplementedPremium

Named implemented evidence. Not in this pack.

Artefact

Internal Audit Plan
Vol. 1Vol. 2installedimplementedBasic

Implemented evidence in this pack. Not a certification PASS.

Artefact

Topic reports remain the process evidence: certification, assets.

Nonconformities

Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.

RequirementStatementGradePathDetail
A.8.1 User endpoint devicesA.8.1 User endpoint devices has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.10 Information deletionA.8.10 Information deletion is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.minorRequirement ↔ evidenceNC-A8-missing-evidence
A.8.11 Data maskingA.8.11 Data masking has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.12 Data leakage preventionA.8.12 Data leakage prevention has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.13 Information backupA.8.13 Information backup has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.14 Redundancy of information processing facilitiesA.8.14 Redundancy of information processing facilities has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.15 LoggingA.8.15 Logging is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A8-missing-evidence
A.8.16 Monitoring activitiesA.8.16 Monitoring activities is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A8-missing-evidence
A.8.17 Clock synchronizationA.8.17 Clock synchronization has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.18 Use of privileged utility programsA.8.18 Use of privileged utility programs has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.2 Privileged access rightsA.8.2 Privileged access rights has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.20 Networks securityA.8.20 Networks security has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.21 Security of network servicesA.8.21 Security of network services has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.22 Segregation of networksA.8.22 Segregation of networks has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.23 Web filteringA.8.23 Web filtering has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.24 Use of cryptographyA.8.24 Use of cryptography has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.25 Secure development life cycleA.8.25 Secure development life cycle has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.26 Application security requirementsA.8.26 Application security requirements has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.27 Secure system architecture and engineering principlesA.8.27 Secure system architecture and engineering principles has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.28 Secure codingA.8.28 Secure coding has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.29 Security testing in development and acceptanceA.8.29 Security testing in development and acceptance has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.3 Information access restrictionA.8.3 Information access restriction is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.minorRequirement ↔ evidenceNC-A8-missing-evidence
A.8.31 Separation of development, test and production environmentsA.8.31 Separation of development, test and production environments has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.32 Change managementA.8.32 Change management has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.33 Test informationA.8.33 Test information has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.34 Protection of information systems during audit testingA.8.34 Protection of information systems during audit testing is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.minorRequirement ↔ evidenceNC-A8-missing-evidence
A.8.4 Access to source codeA.8.4 Access to source code has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.5 Secure authenticationA.8.5 Secure authentication has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.6 Capacity managementA.8.6 Capacity management has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.7 Protection against malwareA.8.7 Protection against malware has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.8 Management of technical vulnerabilitiesA.8.8 Management of technical vulnerabilities has no policy and no implementation evidence in this pack.minorRequirement ↔ evidenceNC-A8-not-implemented
A.8.9 Configuration managementA.8.9 Configuration management is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.minorRequirement ↔ evidenceNC-A8-missing-evidence

ISO 27001 norms and controls

Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.

IndexNameKindDefinedImplementedEffective
A.8.1User endpoint devicescontrolnonoDK
A.8.2Privileged access rightscontrolnonoDK
A.8.3Information access restrictioncontrolnoyesno
A.8.4Access to source codecontrolnonoDK
A.8.5Secure authenticationcontrolnonoDK
A.8.6Capacity managementcontrolnonoDK
A.8.7Protection against malwarecontrolnonoDK
A.8.8Management of technical vulnerabilitiescontrolnonoDK
A.8.9Configuration managementcontrolyesyesno
A.8.10Information deletioncontrolnoyesno
A.8.11Data maskingcontrolnonoDK
A.8.12Data leakage preventioncontrolnonoDK
A.8.13Information backupcontrolnonoDK
A.8.14Redundancy of information processing facilitiescontrolnonoDK
A.8.15Loggingcontrolyesyesno
A.8.16Monitoring activitiescontrolyesyesno
A.8.17Clock synchronizationcontrolnonoDK
A.8.18Use of privileged utility programscontrolnonoDK
A.8.19Installation of software on operational systemscontrolyesnoDK
A.8.20Networks securitycontrolnonoDK
A.8.21Security of network servicescontrolnonoDK
A.8.22Segregation of networkscontrolnonoDK
A.8.23Web filteringcontrolnonoDK
A.8.24Use of cryptographycontrolnonoDK
A.8.25Secure development life cyclecontrolnonoDK
A.8.26Application security requirementscontrolnonoDK
A.8.27Secure system architecture and engineering principlescontrolnonoDK
A.8.28Secure codingcontrolnonoDK
A.8.29Security testing in development and acceptancecontrolnonoDK
A.8.31Separation of development, test and production environmentscontrolnonoDK
A.8.32Change managementcontrolnonoDK
A.8.33Test informationcontrolnonoDK
A.8.34Protection of information systems during audit testingcontrolnoyesno

What we found

What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.

A.8.1 User endpoint devices

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.1 User endpoint devices has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.2 Privileged access rights

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.2 Privileged access rights has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.3 Information access restriction

Quantitative

Qualitative

Cited artefacts in this pack: ACM. Nonconformities recorded: A.8.3 Information access restriction is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.4 Access to source code

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.4 Access to source code has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.5 Secure authentication

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.5 Secure authentication has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.6 Capacity management

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.6 Capacity management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.7 Protection against malware

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.7 Protection against malware has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.8 Management of technical vulnerabilities

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.8 Management of technical vulnerabilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.9 Configuration management

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.9 Configuration management is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.10 Information deletion

Quantitative

Qualitative

Cited artefacts in this pack: RRS. Nonconformities recorded: A.8.10 Information deletion is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.11 Data masking

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.11 Data masking has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.12 Data leakage prevention

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.12 Data leakage prevention has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.13 Information backup

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.13 Information backup has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.14 Redundancy of information processing facilities

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.14 Redundancy of information processing facilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.15 Logging

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.15 Logging is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.16 Monitoring activities

Quantitative

Qualitative

Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.16 Monitoring activities is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.17 Clock synchronization

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.17 Clock synchronization has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.18 Use of privileged utility programs

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.18 Use of privileged utility programs has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.19 Installation of software on operational systems

Quantitative

Qualitative

Cited artefacts in this pack: AMP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.20 Networks security

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.20 Networks security has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.21 Security of network services

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.21 Security of network services has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.22 Segregation of networks

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.22 Segregation of networks has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.23 Web filtering

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.23 Web filtering has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.24 Use of cryptography

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.24 Use of cryptography has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.25 Secure development life cycle

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.25 Secure development life cycle has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.26 Application security requirements

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.26 Application security requirements has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.27 Secure system architecture and engineering principles

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.27 Secure system architecture and engineering principles has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.28 Secure coding

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.28 Secure coding has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.29 Security testing in development and acceptance

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.29 Security testing in development and acceptance has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.31 Separation of development, test and production environments

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.31 Separation of development, test and production environments has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.32 Change management

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.32 Change management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.33 Test information

Quantitative

Qualitative

This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.33 Test information has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.

A.8.34 Protection of information systems during audit testing

Quantitative

Qualitative

Cited artefacts in this pack: IAP. Nonconformities recorded: A.8.34 Protection of information systems during audit testing is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.. Other-book files stay on acquire pages. This chapter does not invent their content.

Tags in this report

Volume

Vol. 1Vol. 2Vol. 3

Presence

installednot installed

Kind

operational-targetpolicyevidenceassetassessment

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…