Audit evidence pack export
None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example audit_evidence_pack, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: audit evidence, evidence pack, audit export, auditor pack, evidence export, audit pack, evidence pack.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| ISO 27001 | no clock | ISO 27001 5.28 Collection of evidence |
| PCI DSS | no clock | PCI DSS 10.5.1 Audit log retention 12 monthstwelve months retained |
| SOX 404 / ICFR named reference | no clock | SOX 404 ENT-8 Internal Audit Functionquoted below |
Named reference beside this class, SOX 404 ENT-8 Internal Audit Function: Internal audit reports functionally to the audit committee and executes risk-based audit plan covering ICFR.
Questions this page answers
How often does ISO/IEC 27001:2022 require audit evidence pack export?
The held text of ISO 27001 5.28 (Collection of evidence) sets no fixed period: no period set by the text. Have procedures to identify, collect, acquire and preserve evidence related to security events.
How often does PCI DSS v4.0 require audit evidence pack export?
The held text of PCI DSS 10.5.1 (Audit log retention 12 months) sets no fixed period: twelve months retained. Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.
What does the register ask the owner of a audit evidence pack export job?
Can this pack be produced for any month of the last twelve without a restore?
The clauses in full
Have procedures to identify, collect, acquire and preserve evidence related to security events.
Guidance beside it, ISO 27002 5.28: Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.
What an assessor asks to see: evidence_collection_policy; incident_response_log; forensic_preservation_report; chain_of_custody_form. Where it usually falls short: Procedures not aligned with legal requirements
Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.
What an assessor asks to see: SIEM retention policy configuration; Hot storage configuration for last 3 months; Cold storage location and accessibility evidence; Sample log restoration test results. Where it usually falls short: Retention below 12 months
Internal audit reports functionally to the audit committee and executes risk-based audit plan covering ICFR.
What an assessor asks to see: IA charter; annual audit plan; audit reports; issue tracker. Where it usually falls short: Internal Audit plan not refreshed for changes in risk or business operations
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register