ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: Continuous operating-effectiveness evidence-collection pipeline

Aperta
#108 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
user-story
Lingua principale
Rust
Stelle
1
Fork
2
Merge medio
14h 36m
PR unite (30g)
107

Descrizione

## Summary
Build a continuous evidence-collection pipeline that captures operating-effectiveness evidence for every mapped control over a rolling 6-12 month window, ahead of and through the eventual audit period.

## Intent / Source of truth
Type II specifically requires evidence that controls operated effectively over time, not a point-in-time snapshot; this pipeline is what makes that possible without manual scrambling at audit time. Part of [Epic] SOC 2 Type II readiness programme.

## Scope
- [ ] Automated evidence capture where possible (CI logs, access-review exports, audit-log excerpts from the audit-log epic)
- [ ] Manual evidence checklist/cadence for controls that can't be automated
- [ ] Central evidence repository with timestamped, immutable records

## Out of scope
- The external auditor's own evidence-sampling process

## Verification
Evidence exists continuously (not with gaps) for a full month-over-month sample once running; a dry-run "audit" walkthrough by an internal reviewer confirms every control in g1s1's mapping has corresponding evidence.

## Risk assessment
A gap in continuous evidence (e.g. a control not evidenced for even one month within the audit window) can force restarting the clock on the Type II observation period — this is the story most sensitive to being started late.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reviewing g1s1's control mapping and the three in-scope evidence sources: CI logs, access-review exports, and audit-log excerpts. Define the automated and manual collection cadence and repository requirements; done means a month-over-month dry run shows continuous evidence for every mapped control.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Ambito
devops, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.