Arcfield A.8 · Technological audit
Source: Arcfield EN Companion · Volume 1 audit + OSCAL assessment plan (AP) / assessment results (AR) · oscal/assessment-plan.md, oscal/assessment-results.md · HITL: oscal-guide.md · SIMULATION
How this report is elaborated
Scope is the Volume 1 A.8 · Technological audit. Identities are the applicable ISO clauses or Annex A controls in this prefix. Process topics remain the operational evidence (certification, assets).
The process we followed is ISO 27001 → Policies → Processes and Systems → Protected Assets → Objects needed by the process → Evidences. Standard vs policy examines whether a policy covers the cited clause or control. Policy vs evidence tests the join from policy rule to recorded evidence.
How to read this report
Start with Results at a glance, then how this category is set up. Glance is Conformity (share without an NC) plus Defined / Implemented / Effectiveness. An NC is recorded when there is no policy and no implementation evidence (Requirement ↔ evidence), when a measure is implemented without effectiveness evidence (Requirement ↔ evidence), or when the kernel join FAILs (Policy ↔ evidence, default minor). Standard vs policy stays HITL. Presence is not Defined = yes as a coverage PASS. UNKNOWN is not an NC.
Results at a glance
Conformity is the share of applicable identities without an NC. Companion Contract/Example unchanged. This is not a certification statement.
How A.8 · Technological is set up
Upper row is documented information. Lower row is operating evidence. Green is installed here. Dashed is named, not packed. The subject is the clause or control.
Named documented evidence. Not in this pack.
Documented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Named implemented evidence. Not in this pack.
Implemented evidence in this pack. Not a certification PASS.
Topic reports remain the process evidence: certification, assets.
Nonconformities
Nonconformities this pack can show. Kernel FAIL is Policy ↔ evidence, default minor — not an automatic major. No policy and no implementation, or implementation without effectiveness evidence, is Requirement ↔ evidence. UNKNOWN is not an NC. Assessment Results stay the kernel SSOT. How to fix is the follow-up, not a customer ticket.
| Requirement | Statement | Grade | Path | Detail |
|---|---|---|---|---|
| A.8.1 User endpoint devices | A.8.1 User endpoint devices has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.10 Information deletion | A.8.10 Information deletion is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
| A.8.11 Data masking | A.8.11 Data masking has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.12 Data leakage prevention | A.8.12 Data leakage prevention has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.13 Information backup | A.8.13 Information backup has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.14 Redundancy of information processing facilities | A.8.14 Redundancy of information processing facilities has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.15 Logging | A.8.15 Logging is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
| A.8.16 Monitoring activities | A.8.16 Monitoring activities is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
| A.8.17 Clock synchronization | A.8.17 Clock synchronization has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.18 Use of privileged utility programs | A.8.18 Use of privileged utility programs has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.2 Privileged access rights | A.8.2 Privileged access rights has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.20 Networks security | A.8.20 Networks security has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.21 Security of network services | A.8.21 Security of network services has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.22 Segregation of networks | A.8.22 Segregation of networks has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.23 Web filtering | A.8.23 Web filtering has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.24 Use of cryptography | A.8.24 Use of cryptography has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.25 Secure development life cycle | A.8.25 Secure development life cycle has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.26 Application security requirements | A.8.26 Application security requirements has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.27 Secure system architecture and engineering principles | A.8.27 Secure system architecture and engineering principles has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.28 Secure coding | A.8.28 Secure coding has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.29 Security testing in development and acceptance | A.8.29 Security testing in development and acceptance has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.3 Information access restriction | A.8.3 Information access restriction is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
| A.8.31 Separation of development, test and production environments | A.8.31 Separation of development, test and production environments has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.32 Change management | A.8.32 Change management has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.33 Test information | A.8.33 Test information has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.34 Protection of information systems during audit testing | A.8.34 Protection of information systems during audit testing is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
| A.8.4 Access to source code | A.8.4 Access to source code has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.5 Secure authentication | A.8.5 Secure authentication has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.6 Capacity management | A.8.6 Capacity management has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.7 Protection against malware | A.8.7 Protection against malware has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.8 Management of technical vulnerabilities | A.8.8 Management of technical vulnerabilities has no policy and no implementation evidence in this pack. | minor | Requirement ↔ evidence | NC-A8-not-implemented |
| A.8.9 Configuration management | A.8.9 Configuration management is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI. | minor | Requirement ↔ evidence | NC-A8-missing-evidence |
ISO 27001 norms and controls
Cited clauses and Annex A controls for this category. Defined is a cited policy (HOW). Standard vs policy stays HITL: Defined = yes does not score that the text covers the control. Implemented is in-pack or named operating evidence. Effective is the kernel join or HITL effectiveness. No policy and no implementation is an NC. Implementation without effectiveness evidence is an NC. Ratings are yes, no, or partially. DK or NA when this pack has no data.
| Index | Name | Kind | Defined | Implemented | Effective |
|---|---|---|---|---|---|
| A.8.1 | User endpoint devices | control | no | no | DK |
| A.8.2 | Privileged access rights | control | no | no | DK |
| A.8.3 | Information access restriction | control | no | yes | no |
| A.8.4 | Access to source code | control | no | no | DK |
| A.8.5 | Secure authentication | control | no | no | DK |
| A.8.6 | Capacity management | control | no | no | DK |
| A.8.7 | Protection against malware | control | no | no | DK |
| A.8.8 | Management of technical vulnerabilities | control | no | no | DK |
| A.8.9 | Configuration management | control | yes | yes | no |
| A.8.10 | Information deletion | control | no | yes | no |
| A.8.11 | Data masking | control | no | no | DK |
| A.8.12 | Data leakage prevention | control | no | no | DK |
| A.8.13 | Information backup | control | no | no | DK |
| A.8.14 | Redundancy of information processing facilities | control | no | no | DK |
| A.8.15 | Logging | control | yes | yes | no |
| A.8.16 | Monitoring activities | control | yes | yes | no |
| A.8.17 | Clock synchronization | control | no | no | DK |
| A.8.18 | Use of privileged utility programs | control | no | no | DK |
| A.8.19 | Installation of software on operational systems | control | yes | no | DK |
| A.8.20 | Networks security | control | no | no | DK |
| A.8.21 | Security of network services | control | no | no | DK |
| A.8.22 | Segregation of networks | control | no | no | DK |
| A.8.23 | Web filtering | control | no | no | DK |
| A.8.24 | Use of cryptography | control | no | no | DK |
| A.8.25 | Secure development life cycle | control | no | no | DK |
| A.8.26 | Application security requirements | control | no | no | DK |
| A.8.27 | Secure system architecture and engineering principles | control | no | no | DK |
| A.8.28 | Secure coding | control | no | no | DK |
| A.8.29 | Security testing in development and acceptance | control | no | no | DK |
| A.8.31 | Separation of development, test and production environments | control | no | no | DK |
| A.8.32 | Change management | control | no | no | DK |
| A.8.33 | Test information | control | no | no | DK |
| A.8.34 | Protection of information systems during audit testing | control | no | yes | no |
What we found
What this pack actually cited for this clause or control identity. Counts are from this pack. Presence is not a PASS. No ISO shall-text.
A.8.1 User endpoint devices
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.1 User endpoint devices has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.2 Privileged access rights
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.2 Privileged access rights has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.3 Information access restriction
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: ACM. Nonconformities recorded: A.8.3 Information access restriction is named in this pack, but there is no effectiveness evidence. Cited implementation: ACM.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.4 Access to source code
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.4 Access to source code has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.5 Secure authentication
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.5 Secure authentication has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.6 Capacity management
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.6 Capacity management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.7 Protection against malware
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.7 Protection against malware has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.8 Management of technical vulnerabilities
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.8 Management of technical vulnerabilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.9 Configuration management
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.9 Configuration management is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.10 Information deletion
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: RRS. Nonconformities recorded: A.8.10 Information deletion is named in this pack, but there is no effectiveness evidence. Cited implementation: RRS.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.11 Data masking
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.11 Data masking has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.12 Data leakage prevention
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.12 Data leakage prevention has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.13 Information backup
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.13 Information backup has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.14 Redundancy of information processing facilities
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.14 Redundancy of information processing facilities has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.15 Logging
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.15 Logging is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.16 Monitoring activities
Quantitative
- Defined / Implemented / Effective = yes: 2/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 6.
Qualitative
Cited artefacts in this pack: CSS, MDR, DR, RRS, AI, UAI. Nonconformities recorded: A.8.16 Monitoring activities is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: MDR, DR, RRS, AI, UAI.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.17 Clock synchronization
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.17 Clock synchronization has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.18 Use of privileged utility programs
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.18 Use of privileged utility programs has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.19 Installation of software on operational systems
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 0.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: AMP. No nonconformity is recorded for this identity in this pack. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.20 Networks security
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.20 Networks security has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.21 Security of network services
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.21 Security of network services has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.22 Segregation of networks
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.22 Segregation of networks has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.23 Web filtering
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.23 Web filtering has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.24 Use of cryptography
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.24 Use of cryptography has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.25 Secure development life cycle
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.25 Secure development life cycle has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.26 Application security requirements
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.26 Application security requirements has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.27 Secure system architecture and engineering principles
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.27 Secure system architecture and engineering principles has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.28 Secure coding
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.28 Secure coding has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.29 Security testing in development and acceptance
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.29 Security testing in development and acceptance has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.31 Separation of development, test and production environments
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.31 Separation of development, test and production environments has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.32 Change management
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.32 Change management has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.33 Test information
Quantitative
- Defined / Implemented / Effective = yes: 0/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 0.
Qualitative
This pack cites no companion artefacts on this identity. Nonconformities recorded: A.8.33 Test information has no policy and no implementation evidence in this pack.. Other-book files stay on acquire pages. This chapter does not invent their content.
A.8.34 Protection of information systems during audit testing
Quantitative
- Defined / Implemented / Effective = yes: 1/3 (DK/NA not counted as yes).
- Nonconformities (major/minor) on this identity: 1.
- Cited artefact IDs: 1.
Qualitative
Cited artefacts in this pack: IAP. Nonconformities recorded: A.8.34 Protection of information systems during audit testing is named in this pack, but there is no effectiveness evidence. Cited implementation: IAP.. Other-book files stay on acquire pages. This chapter does not invent their content.
