Evidence Register¶
Purpose. The live index of every piece of evidence Soon collects to prove its ISMS controls operate — one row per item, with the owner, frequency, where to capture it, and status. It is the map an ISO 27001 auditor browses (keyed by clause / Annex A control); it points at the artefacts held in the S3 evidence store. The SOC 2 Trust Services Criteria cross-walk is maintained separately (see flag 5). Governed by the Evidence Collection and Management Procedure (ISMS-DOC-07-7); satisfies 7.5 / A.5.33.
Status: DRAFT — nothing collected yet. The rows below are the plan of what to collect, grounded in Soon's real stack (AWS eu-west-1, GitHub, WorkOS, Google Workspace, Stripe, Intercom, Sentry, CloudWatch, Aikido, GetAgency pentest). As evidence is captured, update Last collected and Status and link the manifest. Review quarterly and before every audit.
Where artefacts live: the S3 evidence store, keyed
<year>/<ref>/<YYYY-MM-DD>__<ref>__<desc>__<capturer>.<ext> (see ISMS-DOC-07-7 §4.5).
The repo holds only this index + the per-item manifests.
Automated vs manual: rows are captured either manually (per ISMS-DOC-07-7) or automatically by the home-grown GRC collectors — see the Continuous Control Monitoring & GRC Architecture (ISMS-DOC-09-6) and its Check Catalog (ISMS-FORM-09-6). Automated collectors open PRs that update the rows below.
Status legend: ⬜ not yet · 🟡 partial / in progress · ✅ current · ⚠️ overdue.
⚠️ Flags for the owner to resolve¶
- Owners. Owners below use the founder team (Olaf = ISM; Melvin = backups/infra;
Thomas = platform/access) per OPEN-QUESTIONS.md Q3/Q5/Q6.
TODO(owner: Olaf): confirm each control owner. - The store isn't live yet. Every "S3" location depends on standing up the bucket (ISMS-DOC-07-7 §9). Until then, capture to a holding location and migrate.
- Restore test (A.8.13). A backup restore has reportedly never been tested (Q5) — the first restore-test record is the single highest-priority evidence item.
- Nil-returns count. For on-event controls (incidents, breaches), a "none this quarter" record is itself evidence — don't leave the row blank.
- SOC 2 cross-walk. This register is ISO-keyed (clauses / Annex A). A SOC 2
examiner navigates by Trust Services Criteria (CC-series, etc.), not Annex A refs.
TODO(owner): for the GetAgency SOC 2 Type 1, add a TSC column or a companion cross-walk mapping each row to its criteria (most map to the CC common-criteria).
A. Mandatory ISMS records (clauses 4–10)¶
These are the records ISO 27001 requires explicitly; auditors will look for every one.
| Ref | Evidence needed | Owner | Frequency | Where to capture it | Last collected | Status |
|---|---|---|---|---|---|---|
| 4.3 | ISMS scope statement (the audit boundary) | Olaf | Annual + major change | This repo — Context & Scope | — | 🟡 |
| 5.2 | Approved Information Security Policy + Executive Support Letter | Olaf | On change; re-approve annually | This repo (git) — ISMS-DOC-05-4 | — | ⬜ |
| 6.1.2 / 6.1.3 | Risk Assessment Report, Risk Treatment Plan, SoA | Olaf | Annual + major change | This repo — SoA, Risk report | — | 🟡 |
| 6.2 | Information Security Objectives + measurement of them | Olaf | Set annually; measure per 9.1 | This repo — ISMS-DOC-06-1 | — | ⬜ |
| 7.2 / A.6.3 | Training & awareness completions; onboarding records; certificates | Olaf | Quarterly refresher; on joining | Training Log via /isms:onboard |
— | ⬜ |
| 7.5 | Documented information under control (this repo, register, git history) | Olaf | Continuous | GitHub SoonHQ/isms — REGISTER.md |
— | 🟡 |
| 8.1 | Operational planning & control: change PRs, deployment records, runbooks | Thomas | Continuous | GitHub (soon-server, IaC) | — | ⬜ |
| 9.1 | Monitoring & measurement results (ISMS metrics, uptime, error rates) | Olaf / Thomas | Monthly / quarterly | CloudWatch, Sentry, ISMS-DOC-09-1 | — | ⬜ |
| 9.2 | Internal Audit programme + Internal Audit Report | Andrea | At least annual | This repo + S3 — ISMS-DOC-09-2 | — | ⬜ |
| 9.3 | Management Review minutes (inputs, decisions, actions) | Olaf | At least annual (Thursday syncs feed it) | meeting-log | — | 🟡 |
| 10.1 / 10.2 | Nonconformity & Corrective Action (CAPA) log + action tickets | Olaf | On event | This repo — ISMS-DOC-10-1 + Linear | — | ⬜ |
B. Annex A control evidence¶
Key applicable controls from the SoA that produce sample-able evidence. (Physical A.7 controls are mostly inherited from AWS — evidence = AWS's certifications on file under A.5.23.)
| Ref | Evidence needed | Owner | Frequency | Where to capture it | Last collected | Status |
|---|---|---|---|---|---|---|
| A.5.15–5.18 | Quarterly access reviews (user/role lists exported + reviewed) | Thomas | Quarterly | AWS IAM, GitHub, WorkOS, Google Workspace | — | ⬜ |
| A.5.16–5.17 | MFA-enforced config; SSO/SAML config | Thomas | Annual + on change | AWS, GitHub, WorkOS | — | ⬜ |
| A.5.18 | Joiner/mover/leaver records (access granted/revoked) | Thomas | On event | User Access Mgmt, Linear | — | ⬜ |
| A.5.19–5.23 | Sub-processor register; DPAs on file; supplier SOC 2 reports (AWS, Stripe); annual supplier review | Olaf | Annual + new supplier | Google Drive + this repo | — | ⬜ |
| A.5.24–5.28 | Incident records / tickets; #security Slack threads; post-incident reviews; nil-return |
Olaf | On event; quarterly nil-return | Linear, Slack, Incident Response | — | ⬜ |
| A.5.31 / A.5.34 | RoPA; DPA register; privacy policy; Intercom EU migration (S-303) | Olaf | Annual + on change | Google Drive, Linear S-303 | — | ⬜ |
| A.5.5 | AWS security alternate contact set on every account, so AWS can reach us about a security issue | Olaf | Annual + on new account | AWS Account Management (get-alternate-contact) |
2026-08-13 | ✅ |
| A.5.33 | Evidence store config exports (BPA, SSE-KMS, Object Lock, SCP guardrail) — proves this system | Olaf | Annual re-export + on change | Captured 2026-08-13 to s3://soon-isms-evidence/2026/A.5.33/ (SHA-256 3244e76e…) |
2026-08-13 | ✅ |
| A.6.1 / A.6.2 / A.6.6 | Screening records; signed employment terms; signed NDAs | Olaf | On joining | HR store (Google Drive) | — | ⬜ |
| A.6.5 | Offboarding checklist completed (access returned/revoked) | Olaf | On leaving | Termination checklist | — | ⬜ |
| A.7.7 | Clear-desk / clear-screen acknowledgement (home working) | Olaf | Annual | Policy acknowledgements | — | ⬜ |
| A.8.7 | Endpoint protection (anti-malware) config per device (BYOD) | Thomas | Quarterly | Endpoints | — | ⬜ |
| A.8.8 | Aikido vulnerability scans; GitHub dependency alerts; GetAgency pentest report + remediation | Thomas | Monthly (scans); per pentest | Aikido, GitHub, GetAgency | — | ⬜ |
| A.8.9 | Configuration baselines / IaC state | Thomas | On change | GitHub (IaC) | — | ⬜ |
| A.8.13 | RDS automated-backup config; restore test record | Melvin | Config on change; restore test ≥ annual | AWS RDS — Backup Policy | — | ⬜ |
| A.8.15 / A.8.16 | Logging & monitoring config + retention; sample alerts | Thomas | Quarterly | CloudWatch, Sentry | — | ⬜ |
| A.8.20–8.22 | VPC / security-group exports; network segregation (prod/staging/dev) | Thomas | Annual + on change | AWS | — | ⬜ |
| A.8.24 | TLS 1.2+ scan; AES-256-at-rest evidence (RDS/S3 encryption); KMS config | Thomas | Annual | AWS, SSL Labs — Cryptographic Policy | — | ⬜ |
| A.8.25 / A.8.28 / A.8.29 | Branch protection; PR peer-review; CI test runs; code scanning; pentest | Thomas | Continuous + per pentest | GitHub, GetAgency | — | ⬜ |
| A.8.32 | Change-management trail: PR history, CI/CD logs, deployment approvals | Thomas | Continuous | GitHub — Change Mgmt | — | ⬜ |
How a row gets updated¶
- Capture + log the artefact per the Evidence Collection and Management Procedure §6.
- Set Last collected to the capture date and Status to ✅ (or 🟡 if partial).
- Link the manifest; PR the change to
main. - A row goes ⚠️ overdue when the frequency has lapsed — chase the owner.
Related documents¶
- Evidence Collection and Management Procedure (ISMS-DOC-07-7)
- Evidence Capture Manifest (ISMS-FORM-07-3)
- Statement of Applicability (ISMS-FORM-06-2)
- Records Retention and Protection Policy (A.5.33)
- ROADMAP.md · OPEN-QUESTIONS.md
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-07-12 | ISMS | First draft — seeded index of mandatory ISMS records (clauses 4–10) and key Annex A control evidence, mapped to Soon's real stack with owner, frequency, source and status. Nothing collected yet. |