| System boundary |
Defined in writing with hardware/software list |
Validated against network diagrams and data flows |
| Security requirements |
Derived from data classification and applicable regulation |
Traced to a recognised control catalogue (e.g., NIST SP 800-53) |
| Control status |
In place / planned noted per control |
Evidence referenced, implementation dates tracked |
| Ownership |
Single responsible person per control |
Escalation path and review cycle documented |
| Interconnections |
List of connected systems |
Interface agreements and data-sharing agreements in place |
| Review cadence |
Annual review |
Triggered by system change, incident, or audit finding |