ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: Continuous operating-effectiveness evidence-collection pipeline

Ouverte
#108 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
user-story
Langage dominant
Rust
Étoiles
1
Forks
2
Merge moyen
13 h 13 min
PR mergées (30 j)
110

Description

## Summary
Build a continuous evidence-collection pipeline that captures operating-effectiveness evidence for every mapped control over a rolling 6-12 month window, ahead of and through the eventual audit period.

## Intent / Source of truth
Type II specifically requires evidence that controls operated effectively over time, not a point-in-time snapshot; this pipeline is what makes that possible without manual scrambling at audit time. Part of [Epic] SOC 2 Type II readiness programme.

## Scope
- [ ] Automated evidence capture where possible (CI logs, access-review exports, audit-log excerpts from the audit-log epic)
- [ ] Manual evidence checklist/cadence for controls that can't be automated
- [ ] Central evidence repository with timestamped, immutable records

## Out of scope
- The external auditor's own evidence-sampling process

## Verification
Evidence exists continuously (not with gaps) for a full month-over-month sample once running; a dry-run "audit" walkthrough by an internal reviewer confirms every control in g1s1's mapping has corresponding evidence.

## Risk assessment
A gap in continuous evidence (e.g. a control not evidenced for even one month within the audit window) can force restarting the clock on the Type II observation period — this is the story most sensitive to being started late.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.