Skip to content

Evidence Register

Purpose. The live index of every piece of evidence Soon collects to prove its ISMS controls operate — one row per item, with the owner, frequency, where to capture it, and status. It is the map an ISO 27001 auditor browses (keyed by clause / Annex A control); it points at the artefacts held in the S3 evidence store. The SOC 2 Trust Services Criteria cross-walk is maintained separately (see flag 5). Governed by the Evidence Collection and Management Procedure (ISMS-DOC-07-7); satisfies 7.5 / A.5.33.

Status: DRAFT — nothing collected yet. The rows below are the plan of what to collect, grounded in Soon's real stack (AWS eu-west-1, GitHub, WorkOS, Google Workspace, Stripe, Intercom, Sentry, CloudWatch, Aikido, GetAgency pentest). As evidence is captured, update Last collected and Status and link the manifest. Review quarterly and before every audit.

Where artefacts live: the S3 evidence store, keyed <year>/<ref>/<YYYY-MM-DD>__<ref>__<desc>__<capturer>.<ext> (see ISMS-DOC-07-7 §4.5). The repo holds only this index + the per-item manifests.

Automated vs manual: rows are captured either manually (per ISMS-DOC-07-7) or automatically by the home-grown GRC collectors — see the Continuous Control Monitoring & GRC Architecture (ISMS-DOC-09-6) and its Check Catalog (ISMS-FORM-09-6). Automated collectors open PRs that update the rows below.

Status legend: ⬜ not yet · 🟡 partial / in progress · ✅ current · ⚠️ overdue.


⚠️ Flags for the owner to resolve

  1. Owners. Owners below use the founder team (Olaf = ISM; Melvin = backups/infra; Thomas = platform/access) per OPEN-QUESTIONS.md Q3/Q5/Q6. TODO(owner: Olaf): confirm each control owner.
  2. The store isn't live yet. Every "S3" location depends on standing up the bucket (ISMS-DOC-07-7 §9). Until then, capture to a holding location and migrate.
  3. Restore test (A.8.13). A backup restore has reportedly never been tested (Q5) — the first restore-test record is the single highest-priority evidence item.
  4. Nil-returns count. For on-event controls (incidents, breaches), a "none this quarter" record is itself evidence — don't leave the row blank.
  5. SOC 2 cross-walk. This register is ISO-keyed (clauses / Annex A). A SOC 2 examiner navigates by Trust Services Criteria (CC-series, etc.), not Annex A refs. TODO(owner): for the GetAgency SOC 2 Type 1, add a TSC column or a companion cross-walk mapping each row to its criteria (most map to the CC common-criteria).

A. Mandatory ISMS records (clauses 4–10)

These are the records ISO 27001 requires explicitly; auditors will look for every one.

Ref Evidence needed Owner Frequency Where to capture it Last collected Status
4.3 ISMS scope statement (the audit boundary) Olaf Annual + major change This repo — Context & Scope 🟡
5.2 Approved Information Security Policy + Executive Support Letter Olaf On change; re-approve annually This repo (git) — ISMS-DOC-05-4
6.1.2 / 6.1.3 Risk Assessment Report, Risk Treatment Plan, SoA Olaf Annual + major change This repo — SoA, Risk report 🟡
6.2 Information Security Objectives + measurement of them Olaf Set annually; measure per 9.1 This repo — ISMS-DOC-06-1
7.2 / A.6.3 Training & awareness completions; onboarding records; certificates Olaf Quarterly refresher; on joining Training Log via /isms:onboard
7.5 Documented information under control (this repo, register, git history) Olaf Continuous GitHub SoonHQ/ismsREGISTER.md 🟡
8.1 Operational planning & control: change PRs, deployment records, runbooks Thomas Continuous GitHub (soon-server, IaC)
9.1 Monitoring & measurement results (ISMS metrics, uptime, error rates) Olaf / Thomas Monthly / quarterly CloudWatch, Sentry, ISMS-DOC-09-1
9.2 Internal Audit programme + Internal Audit Report Andrea At least annual This repo + S3 — ISMS-DOC-09-2
9.3 Management Review minutes (inputs, decisions, actions) Olaf At least annual (Thursday syncs feed it) meeting-log 🟡
10.1 / 10.2 Nonconformity & Corrective Action (CAPA) log + action tickets Olaf On event This repo — ISMS-DOC-10-1 + Linear

B. Annex A control evidence

Key applicable controls from the SoA that produce sample-able evidence. (Physical A.7 controls are mostly inherited from AWS — evidence = AWS's certifications on file under A.5.23.)

Ref Evidence needed Owner Frequency Where to capture it Last collected Status
A.5.15–5.18 Quarterly access reviews (user/role lists exported + reviewed) Thomas Quarterly AWS IAM, GitHub, WorkOS, Google Workspace
A.5.16–5.17 MFA-enforced config; SSO/SAML config Thomas Annual + on change AWS, GitHub, WorkOS
A.5.18 Joiner/mover/leaver records (access granted/revoked) Thomas On event User Access Mgmt, Linear
A.5.19–5.23 Sub-processor register; DPAs on file; supplier SOC 2 reports (AWS, Stripe); annual supplier review Olaf Annual + new supplier Google Drive + this repo
A.5.24–5.28 Incident records / tickets; #security Slack threads; post-incident reviews; nil-return Olaf On event; quarterly nil-return Linear, Slack, Incident Response
A.5.31 / A.5.34 RoPA; DPA register; privacy policy; Intercom EU migration (S-303) Olaf Annual + on change Google Drive, Linear S-303
A.5.5 AWS security alternate contact set on every account, so AWS can reach us about a security issue Olaf Annual + on new account AWS Account Management (get-alternate-contact) 2026-08-13
A.5.33 Evidence store config exports (BPA, SSE-KMS, Object Lock, SCP guardrail) — proves this system Olaf Annual re-export + on change Captured 2026-08-13 to s3://soon-isms-evidence/2026/A.5.33/ (SHA-256 3244e76e…) 2026-08-13
A.6.1 / A.6.2 / A.6.6 Screening records; signed employment terms; signed NDAs Olaf On joining HR store (Google Drive)
A.6.5 Offboarding checklist completed (access returned/revoked) Olaf On leaving Termination checklist
A.7.7 Clear-desk / clear-screen acknowledgement (home working) Olaf Annual Policy acknowledgements
A.8.7 Endpoint protection (anti-malware) config per device (BYOD) Thomas Quarterly Endpoints
A.8.8 Aikido vulnerability scans; GitHub dependency alerts; GetAgency pentest report + remediation Thomas Monthly (scans); per pentest Aikido, GitHub, GetAgency
A.8.9 Configuration baselines / IaC state Thomas On change GitHub (IaC)
A.8.13 RDS automated-backup config; restore test record Melvin Config on change; restore test ≥ annual AWS RDS — Backup Policy
A.8.15 / A.8.16 Logging & monitoring config + retention; sample alerts Thomas Quarterly CloudWatch, Sentry
A.8.20–8.22 VPC / security-group exports; network segregation (prod/staging/dev) Thomas Annual + on change AWS
A.8.24 TLS 1.2+ scan; AES-256-at-rest evidence (RDS/S3 encryption); KMS config Thomas Annual AWS, SSL Labs — Cryptographic Policy
A.8.25 / A.8.28 / A.8.29 Branch protection; PR peer-review; CI test runs; code scanning; pentest Thomas Continuous + per pentest GitHub, GetAgency
A.8.32 Change-management trail: PR history, CI/CD logs, deployment approvals Thomas Continuous GitHub — Change Mgmt

How a row gets updated

  1. Capture + log the artefact per the Evidence Collection and Management Procedure §6.
  2. Set Last collected to the capture date and Status to ✅ (or 🟡 if partial).
  3. Link the manifest; PR the change to main.
  4. A row goes ⚠️ overdue when the frequency has lapsed — chase the owner.

Change log

Version Date Author Comments
0.1 2026-07-12 ISMS First draft — seeded index of mandatory ISMS records (clauses 4–10) and key Annex A control evidence, mapped to Soon's real stack with owner, frequency, source and status. Nothing collected yet.