Complete the remaining evidence requirements to be audit-ready
Overview
By this stage of our Vanta Velocity Playbook, you should have connected your systems, generated and loaded your policies, completed the risk assessment and vendor risk activities. Now it's time to complete the remaining audit checklist of evidence items.
Sample Requirements
Type 1: If you are working to a Type 1 audit, you can provide any one example of the control, or a template or mock-up if a live example has not been performed yet.
Type 2: If you are conducting a Type 2 audit, AssuranceLab will provide you the sample selections from the populations in Vanta. For each of the selected samples, provide the evidence listed below in the table.
Audit checklist
The remaining items for the audit are described in the table below per Vanta control. The requirement column explains the expected audit evidence. You can click the control title to read more including the minimum expectations, better practices, and further explanation of each compliance control.
Title | Ref | Requirement |
PRM-1 | Evidence of standard terms of service (website) or a contract template that's used to agree terms with customers and users. | |
Incident Response Plan Tested |
IRO-1 | Meeting minutes or documented test results from the incident response test. |
Penetration Testing | IAO-2 | The latest penetration test report or SOW for planned penetration test (Type I only) |
Performance Evaluations Conducted | HRS-6 | The completed performance evaluation evidence for the Sampled Employees. |
Risk Assessment Performed |
RSK-2 | The latest risk assessment in the form of the risk register, meeting minutes, and/or a risk report. |
Background Checks Performed | HRS-1 | The background checks conducted for the Sampled New Hires. |
Continuity and Disaster Recovery Plans Tested | BCD-2 | Documented tests conducted and results for the business continuity and disaster recovery review exercises. |
Board of Directors Charter | GOV-2 | Documented Board of Director terms of reference, responsibilities and/or scope. |
Board of Directors Meeting | GOV-4 | The latest Board meeting agenda and minutes, with evidence of briefing on information security. |
Control Self-Assessments Conducted | IAO-1 | Records of review of the controls in Vanta by the control owners, including any corrective actions or modifications identified. |
Cybersecurity Insurance Maintained | BCD-3 | The certificate of currency or cyber insurance policy details. |
Incident Management Procedures Followed | IRO-3 | Evidence of incident logging, classification, resolution and lessons learned devised for the Sampled Incidents. |
Roles and Responsibilities Defined | GOV-10 | The documented job descriptions for the Sampled Employees. |
Organizational Structure Documented | GOV-8 | The documented organization chart with roles and reporting lines. |
Access Reviews Conducted | IAC-7 | The latest access control review that confirms user access to critical systems is appropriate, or modified accordingly. |
Vulnerabilities Scanned and Remediated | VPM-2 | The latest vulnerability scan report(s) or system record showing when they were conducted and the results. |
Security Awareness Training | SAT-1 | Confirm security training is tracked in Vanta, or manually upload evidence for the Sampled New Joiners. |
Access Requests Required | IAC-9 | The completed onboarding checklist or access approval for the Sampled New Joiners. |
Access Revoked Upon Termination | IAC-8 | The completed exit checklist or other confirmation of access removal for the Sampled Terminated Employees. |
Added Processing Integrity or Privacy to you audit scope? Contact us for guidance on the additional scope areas.