Civitas EPI Rail
Civitas Analytica — Engineered truth
trust_audit / vendor_security / acme / eng42

Trust Audit

Civitas Analytica — Engineered truth.

Executive Summary

Severity-weighted score0.0%
Total controls80
Met0
Partial0
Gap80

Key Gaps

Full Controls Table

control_idtitleobjectiveevidence expectationsstatusseverityevidence_count
VS-001Vendor Security Control 001Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-002Vendor Security Control 002Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-003Vendor Security Control 003Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-004Vendor Security Control 004Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-005Vendor Security Control 005Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-006Vendor Security Control 006Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-007Vendor Security Control 007Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-008Vendor Security Control 008Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-009Vendor Security Control 009Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-010Vendor Security Control 010Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-011Vendor Security Control 011Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-012Vendor Security Control 012Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-013Vendor Security Control 013Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-014Vendor Security Control 014Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-015Vendor Security Control 015Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-016Vendor Security Control 016Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-017Vendor Security Control 017Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-018Vendor Security Control 018Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-019Vendor Security Control 019Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-020Vendor Security Control 020Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-021Vendor Security Control 021Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-022Vendor Security Control 022Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-023Vendor Security Control 023Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-024Vendor Security Control 024Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-025Vendor Security Control 025Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-026Vendor Security Control 026Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-027Vendor Security Control 027Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-028Vendor Security Control 028Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-029Vendor Security Control 029Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-030Vendor Security Control 030Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-031Vendor Security Control 031Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-032Vendor Security Control 032Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-033Vendor Security Control 033Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-034Vendor Security Control 034Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-035Vendor Security Control 035Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-036Vendor Security Control 036Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-037Vendor Security Control 037Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-038Vendor Security Control 038Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-039Vendor Security Control 039Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-040Vendor Security Control 040Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-041Vendor Security Control 041Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-042Vendor Security Control 042Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-043Vendor Security Control 043Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-044Vendor Security Control 044Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-045Vendor Security Control 045Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-046Vendor Security Control 046Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-047Vendor Security Control 047Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-048Vendor Security Control 048Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-049Vendor Security Control 049Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-050Vendor Security Control 050Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-051Vendor Security Control 051Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-052Vendor Security Control 052Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-053Vendor Security Control 053Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-054Vendor Security Control 054Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-055Vendor Security Control 055Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-056Vendor Security Control 056Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-057Vendor Security Control 057Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-058Vendor Security Control 058Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-059Vendor Security Control 059Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-060Vendor Security Control 060Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-061Vendor Security Control 061Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-062Vendor Security Control 062Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-063Vendor Security Control 063Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-064Vendor Security Control 064Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-065Vendor Security Control 065Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-066Vendor Security Control 066Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-067Vendor Security Control 067Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-068Vendor Security Control 068Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-069Vendor Security Control 069Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-070Vendor Security Control 070Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-071Vendor Security Control 071Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-072Vendor Security Control 072Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-073Vendor Security Control 073Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-074Vendor Security Control 074Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-075Vendor Security Control 075Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.gap50
VS-076Vendor Security Control 076Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.gap10
VS-077Vendor Security Control 077Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.gap20
VS-078Vendor Security Control 078Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.gap30
VS-079Vendor Security Control 079Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.gap40
VS-080Vendor Security Control 080Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.gap50

Gap Register

control_idtitlestatusseverityevidence_countmissing_evidenceevidence expectations
VS-001Vendor Security Control 001gap102Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-002Vendor Security Control 002gap202Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-003Vendor Security Control 003gap302Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-004Vendor Security Control 004gap402Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-005Vendor Security Control 005gap502Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-006Vendor Security Control 006gap103Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-007Vendor Security Control 007gap203Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-008Vendor Security Control 008gap302Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-009Vendor Security Control 009gap403Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-010Vendor Security Control 010gap503Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-011Vendor Security Control 011gap102Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-012Vendor Security Control 012gap202Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-013Vendor Security Control 013gap302Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-014Vendor Security Control 014gap402Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-015Vendor Security Control 015gap502Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-016Vendor Security Control 016gap102Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-017Vendor Security Control 017gap202Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-018Vendor Security Control 018gap303Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-019Vendor Security Control 019gap403Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-020Vendor Security Control 020gap502Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-021Vendor Security Control 021gap103Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-022Vendor Security Control 022gap203Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-023Vendor Security Control 023gap302Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-024Vendor Security Control 024gap402Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-025Vendor Security Control 025gap502Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-026Vendor Security Control 026gap102Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-027Vendor Security Control 027gap202Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-028Vendor Security Control 028gap302Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-029Vendor Security Control 029gap402Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-030Vendor Security Control 030gap503Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-031Vendor Security Control 031gap103Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-032Vendor Security Control 032gap202Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-033Vendor Security Control 033gap303Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-034Vendor Security Control 034gap403Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-035Vendor Security Control 035gap502Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-036Vendor Security Control 036gap102Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-037Vendor Security Control 037gap202Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-038Vendor Security Control 038gap302Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-039Vendor Security Control 039gap402Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-040Vendor Security Control 040gap502Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-041Vendor Security Control 041gap102Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-042Vendor Security Control 042gap203Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-043Vendor Security Control 043gap303Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-044Vendor Security Control 044gap402Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-045Vendor Security Control 045gap503Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-046Vendor Security Control 046gap103Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-047Vendor Security Control 047gap202Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-048Vendor Security Control 048gap302Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-049Vendor Security Control 049gap402Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-050Vendor Security Control 050gap502Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-051Vendor Security Control 051gap102Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-052Vendor Security Control 052gap202Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-053Vendor Security Control 053gap302Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-054Vendor Security Control 054gap403Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-055Vendor Security Control 055gap503Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-056Vendor Security Control 056gap102Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-057Vendor Security Control 057gap203Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-058Vendor Security Control 058gap303Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-059Vendor Security Control 059gap402Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-060Vendor Security Control 060gap502Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-061Vendor Security Control 061gap102Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-062Vendor Security Control 062gap202Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-063Vendor Security Control 063gap302Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-064Vendor Security Control 064gap402Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-065Vendor Security Control 065gap502Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-066Vendor Security Control 066gap103Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-067Vendor Security Control 067gap203Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-068Vendor Security Control 068gap302Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.
VS-069Vendor Security Control 069gap403Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.
VS-070Vendor Security Control 070gap503Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.
VS-071Vendor Security Control 071gap102Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.
VS-072Vendor Security Control 072gap202Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.
VS-073Vendor Security Control 073gap302Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.
VS-074Vendor Security Control 074gap402Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
VS-075Vendor Security Control 075gap502Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-076Vendor Security Control 076gap102Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.
VS-077Vendor Security Control 077gap202Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.
VS-078Vendor Security Control 078gap303Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.
VS-079Vendor Security Control 079gap403Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.
VS-080Vendor Security Control 080gap502Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

Evidence Appendix

VS-001 - Vendor Security Control 001

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-002 - Vendor Security Control 002

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-003 - Vendor Security Control 003

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-004 - Vendor Security Control 004

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-005 - Vendor Security Control 005

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-006 - Vendor Security Control 006

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-007 - Vendor Security Control 007

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-008 - Vendor Security Control 008

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-009 - Vendor Security Control 009

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-010 - Vendor Security Control 010

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-011 - Vendor Security Control 011

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-012 - Vendor Security Control 012

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-013 - Vendor Security Control 013

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-014 - Vendor Security Control 014

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-015 - Vendor Security Control 015

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-016 - Vendor Security Control 016

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-017 - Vendor Security Control 017

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-018 - Vendor Security Control 018

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-019 - Vendor Security Control 019

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-020 - Vendor Security Control 020

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-021 - Vendor Security Control 021

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-022 - Vendor Security Control 022

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-023 - Vendor Security Control 023

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-024 - Vendor Security Control 024

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-025 - Vendor Security Control 025

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-026 - Vendor Security Control 026

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-027 - Vendor Security Control 027

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-028 - Vendor Security Control 028

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-029 - Vendor Security Control 029

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-030 - Vendor Security Control 030

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-031 - Vendor Security Control 031

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-032 - Vendor Security Control 032

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-033 - Vendor Security Control 033

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-034 - Vendor Security Control 034

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-035 - Vendor Security Control 035

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-036 - Vendor Security Control 036

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-037 - Vendor Security Control 037

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-038 - Vendor Security Control 038

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-039 - Vendor Security Control 039

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-040 - Vendor Security Control 040

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-041 - Vendor Security Control 041

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-042 - Vendor Security Control 042

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-043 - Vendor Security Control 043

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-044 - Vendor Security Control 044

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-045 - Vendor Security Control 045

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-046 - Vendor Security Control 046

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-047 - Vendor Security Control 047

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-048 - Vendor Security Control 048

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-049 - Vendor Security Control 049

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-050 - Vendor Security Control 050

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-051 - Vendor Security Control 051

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-052 - Vendor Security Control 052

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-053 - Vendor Security Control 053

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-054 - Vendor Security Control 054

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-055 - Vendor Security Control 055

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-056 - Vendor Security Control 056

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-057 - Vendor Security Control 057

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-058 - Vendor Security Control 058

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-059 - Vendor Security Control 059

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-060 - Vendor Security Control 060

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-061 - Vendor Security Control 061

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-062 - Vendor Security Control 062

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-063 - Vendor Security Control 063

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-064 - Vendor Security Control 064

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-065 - Vendor Security Control 065

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-066 - Vendor Security Control 066

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-067 - Vendor Security Control 067

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-068 - Vendor Security Control 068

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-069 - Vendor Security Control 069

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for VENDOR/THIRD_PARTY/RISK with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VENDOR/THIRD_PARTY/RISK governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VENDOR/THIRD_PARTY/RISK.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-033 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-070 - Vendor Security Control 070

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for GOVERNANCE/POLICY/AUDIT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating GOVERNANCE/POLICY/AUDIT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for GOVERNANCE/POLICY/AUDIT.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-010 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-022 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-034 - governance policy audit controls evidence owner review register policy log

tags: governance, policy, audit | hits: 0

No direct evidence hits for this query.

VS-071 - Vendor Security Control 071

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for TRAINING/AWARENESS/PEOPLE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating TRAINING/AWARENESS/PEOPLE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for TRAINING/AWARENESS/PEOPLE.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-011 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-023 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-035 - training awareness people controls evidence owner review register policy log

tags: training, awareness, people | hits: 0

No direct evidence hits for this query.

VS-072 - Vendor Security Control 072

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for VULNERABILITY/PATCHING/OPERATIONS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating VULNERABILITY/PATCHING/OPERATIONS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for VULNERABILITY/PATCHING/OPERATIONS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-012 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-024 - vulnerability patching operations controls evidence owner review register policy log

tags: vulnerability, patching, operations | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-073 - Vendor Security Control 073

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for IDENTITY/ACCESS/MFA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTITY/ACCESS/MFA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTITY/ACCESS/MFA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-025 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-074 - Vendor Security Control 074

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for PRIVILEGED/REVIEW/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PRIVILEGED/REVIEW/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PRIVILEGED/REVIEW/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-001 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-002 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-013 - identity access mfa controls evidence owner review register policy log

tags: identity, access, mfa | hits: 0

No direct evidence hits for this query.

VS-Q-014 - privileged review access controls evidence owner review register policy log

tags: privileged, review, access | hits: 0

No direct evidence hits for this query.

VS-075 - Vendor Security Control 075

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for LOGGING/MONITORING/RETENTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating LOGGING/MONITORING/RETENTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for LOGGING/MONITORING/RETENTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-003 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-015 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-027 - logging monitoring retention controls evidence owner review register policy log

tags: logging, monitoring, retention | hits: 0

No direct evidence hits for this query.

VS-076 - Vendor Security Control 076

gap | severity 1 | evidence_count 0

Ensure Vendor Security control coverage for SIEM/ALERTING/DETECTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating SIEM/ALERTING/DETECTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for SIEM/ALERTING/DETECTION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-004 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-016 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-028 - siem alerting detection controls evidence owner review register policy log

tags: siem, alerting, detection | hits: 0

No direct evidence hits for this query.

VS-077 - Vendor Security Control 077

gap | severity 2 | evidence_count 0

Ensure Vendor Security control coverage for ENCRYPTION/KEY_MANAGEMENT/DATA with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating ENCRYPTION/KEY_MANAGEMENT/DATA governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for ENCRYPTION/KEY_MANAGEMENT/DATA.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-005 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-017 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-029 - encryption key_management data controls evidence owner review register policy log

tags: encryption, key_management, data | hits: 0

No direct evidence hits for this query.

VS-078 - Vendor Security Control 078

gap | severity 3 | evidence_count 0

Ensure Vendor Security control coverage for NETWORK/TLS/SEGMENTATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating NETWORK/TLS/SEGMENTATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for NETWORK/TLS/SEGMENTATION.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-006 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-018 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-030 - network tls segmentation controls evidence owner review register policy log

tags: network, tls, segmentation | hits: 0

No direct evidence hits for this query.

VS-079 - Vendor Security Control 079

gap | severity 4 | evidence_count 0

Ensure Vendor Security control coverage for INCIDENT/RESPONSE/TABLETOP with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating INCIDENT/RESPONSE/TABLETOP governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for INCIDENT/RESPONSE/TABLETOP.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-007 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-019 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-031 - incident response tabletop controls evidence owner review register policy log

tags: incident, response, tabletop | hits: 0

No direct evidence hits for this query.

VS-080 - Vendor Security Control 080

gap | severity 5 | evidence_count 0

Ensure Vendor Security control coverage for BACKUP/RECOVERY/CONTINUITY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating BACKUP/RECOVERY/CONTINUITY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for BACKUP/RECOVERY/CONTINUITY.; Recent review evidence with remediation tracking where exceptions were found.

VS-Q-008 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-009 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-020 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

VS-Q-021 - vendor third_party risk controls evidence owner review register policy log

tags: vendor, third_party, risk | hits: 0

No direct evidence hits for this query.

VS-Q-032 - backup recovery continuity controls evidence owner review register policy log

tags: backup, recovery, continuity | hits: 0

No direct evidence hits for this query.

Query Log

query_idquery_texttagshits
VS-Q-001identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-002privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-003logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-004siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-005encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-006network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-007incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-008backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-009vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-010governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-011training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-012vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-013identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-014privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-015logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-016siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-017encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-018network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-019incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-020backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-021vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-022governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-023training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-024vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-025identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-026privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-027logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-028siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-029encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-030network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-031incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-032backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-033vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-034governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-035training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-036vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-037identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-038privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-039logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-040siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0

Query Log

query_idquery_texttagshits
VS-Q-001identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-002privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-003logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-004siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-005encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-006network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-007incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-008backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-009vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-010governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-011training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-012vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-013identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-014privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-015logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-016siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-017encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-018network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-019incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-020backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-021vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-022governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-023training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-024vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-025identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-026privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-027logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-028siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0
VS-Q-029encryption key_management data controls evidence owner review register policy logencryption, key_management, data0
VS-Q-030network tls segmentation controls evidence owner review register policy lognetwork, tls, segmentation0
VS-Q-031incident response tabletop controls evidence owner review register policy logincident, response, tabletop0
VS-Q-032backup recovery continuity controls evidence owner review register policy logbackup, recovery, continuity0
VS-Q-033vendor third_party risk controls evidence owner review register policy logvendor, third_party, risk0
VS-Q-034governance policy audit controls evidence owner review register policy loggovernance, policy, audit0
VS-Q-035training awareness people controls evidence owner review register policy logtraining, awareness, people0
VS-Q-036vulnerability patching operations controls evidence owner review register policy logvulnerability, patching, operations0
VS-Q-037identity access mfa controls evidence owner review register policy logidentity, access, mfa0
VS-Q-038privileged review access controls evidence owner review register policy logprivileged, review, access0
VS-Q-039logging monitoring retention controls evidence owner review register policy loglogging, monitoring, retention0
VS-Q-040siem alerting detection controls evidence owner review register policy logsiem, alerting, detection0