ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance
[Story]: Continuous operating-effectiveness evidence-collection pipeline
- Langage dominant
- Rust
- Étoiles
- 1
- Forks
- 2
- Merge moyen
- 13 h 13 min
- PR mergées (30 j)
- 110
Description
## Summary
Build a continuous evidence-collection pipeline that captures operating-effectiveness evidence for every mapped control over a rolling 6-12 month window, ahead of and through the eventual audit period.
## Intent / Source of truth
Type II specifically requires evidence that controls operated effectively over time, not a point-in-time snapshot; this pipeline is what makes that possible without manual scrambling at audit time. Part of [Epic] SOC 2 Type II readiness programme.
## Scope
- [ ] Automated evidence capture where possible (CI logs, access-review exports, audit-log excerpts from the audit-log epic)
- [ ] Manual evidence checklist/cadence for controls that can't be automated
- [ ] Central evidence repository with timestamped, immutable records
## Out of scope
- The external auditor's own evidence-sampling process
## Verification
Evidence exists continuously (not with gaps) for a full month-over-month sample once running; a dry-run "audit" walkthrough by an internal reviewer confirms every control in g1s1's mapping has corresponding evidence.
## Risk assessment
A gap in continuous evidence (e.g. a control not evidenced for even one month within the audit window) can force restarting the clock on the Type II observation period — this is the story most sensitive to being started late.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.