It would be nice to be able to add (supporting) evidence (e.g. linking a policy, ME or AC) to a control. E.g. “We’d like to map POL-04 as evidence under 12.1.1 PCI DSS control, to have the Acceptable Use section also visible for the PCI DSS audit. That's what our auditor knows from the past and was asking for. Sure, having the POL-02 linked to it is the generic approach and totally correct. The POL-04 would simply make it more concrete.”
Please authenticate to join the conversation.
Open
Feature Request
2 days ago

Frank Tiex
Get notified by email when there are changes.
Open
Feature Request
2 days ago

Frank Tiex
Get notified by email when there are changes.