Skip to main content

Importing Control / Evidence Linking

This article describes how to use a CSV to quickly link Controls and Evidence

From Control Details

  1. Open the Details page of a Control

  2. Press the “Link / Unlink Evidence” button

  3. Press the small blue ‘Import’ button

  4. Prepare the CSV File for Import

  5. The CSV File should have a header for ‘Statement Number’ that corresponds to the unique Statement Number of a Compliance Control and one for ‘Evidence’, which needs to match the Name of an Evidence exactly

View Example Input

Statement Number

Evidence

1

Board Package (or delegated board committee report) and Meeting Minutes since last exam

1

Financial Institution's Policy, Standards and Guidelines specific to: Business Continuity Planning (BCP) and Disaster Recovery (DR)

1

Financial Institution's Policy, Standards and Guidelines specific to: Information Security

1

Information Technology (IT) Job Descriptions

1

Information Technology (IT) Organizational Chart

1

Information Technology (IT) Project Listing

1

Information Technology (IT) Steering Committee Minutes since last exam

2

Board Package (or delegated board committee report) and Meeting Minutes since last exam

2

Information Technology (IT) Steering Committee Minutes since last exam

3

Annually Report to the Board of Directors (or delegated board committee) on Information Security Program

3

Board Package (or delegated board committee report) and Meeting Minutes since last exam

3

Business Continuity Planning (BCP) and Disaster Recovery (DR) Test Results (if separate)

3

Information Technology (IT) Steering Committee Minutes since last exam

4

Cybersecurity Expenses

4

Financial Institution Budget

4

Information Technology (IT) Budget

4

Information Technology (IT) Strategy

4

Inventory of network security & monitoring tools (e.g. antivirus, firewall, IDS, SIEM, DLP, etc.)

5

Business Continuity Plan (including Business Impact Analysis, Risk Assessment, and Disaster Recovery Plan)

5

Business Continuity Planning (BCP) and Disaster Recovery (DR) Test Results (if separate)

5

Cybersecurity Risk Assessment (If separate from Information Security Risk Assessment)

6. Press Submit, wait for the file to process

7. Once it is complete, confirm the Linking. Some rows may not be able to process due to incorrect data, missing Controls, or missing Evidence

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.