Local decision and evidence register

Do not enter secrets, personal data, production data, or undisclosed vulnerability details. Answers stay in this browser until you export them.

Reviewed: 0/60Gaps: 0Blockers: 11
  1. Scope and governance

    Define the systems, environments, organizations and data included in this review.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  2. Scope and governance · blocking

    Name the person accountable for accepting security evidence and residual risk.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  3. Scope and governance

    Record the review method, evidence cutoff and next review trigger.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  4. Architecture and data flows

    Maintain a current system-context and data-flow diagram.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  5. Architecture and data flows · blocking

    Mark trust boundaries, external services and privileged paths.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  6. Architecture and data flows

    Trace one sensitive business flow through storage, logs, queues and integrations.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  7. Tenancy and isolation

    List every tenant and organization scope boundary used by the application.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  8. Tenancy and isolation · blocking

    Provide tests for cross-tenant and cross-organization read and write isolation.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  9. Tenancy and isolation

    Review custom queries, workers and exports for scope propagation.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  10. Identity and sessions

    Document admin, employee, customer and service identities separately.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  11. Identity and sessions · blocking

    Review session lifetime, revocation, recovery and privileged reauthentication.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  12. Identity and sessions

    Test account lifecycle, invitation and termination paths.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  13. Authorization and RBAC

    Map each role to the minimum required feature grants.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  14. Authorization and RBAC · blocking

    Test wildcard permissions and denial paths in UI, API, commands and workers.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  15. Authorization and RBAC

    Review who can change roles, ACL grants and organization membership.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  16. Input and API security

    Inventory public, authenticated and privileged endpoints.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  17. Input and API security · blocking

    Provide validation, authorization and rate-limit evidence for exposed inputs.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  18. Input and API security

    Test file, URL, redirect and webhook inputs against abuse cases.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  19. Encryption and key management

    Classify data requiring encryption in transit and at rest.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  20. Encryption and key management · blocking

    Document key custody, access, rotation, revocation and recovery.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  21. Encryption and key management

    Verify encrypted-field behavior in reads, search, exports and backups.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  22. Secrets management

    Inventory application, database, provider and signing secrets.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  23. Secrets management · blocking

    Confirm secrets are excluded from source, logs, exports and client bundles.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  24. Secrets management

    Document rotation and emergency revocation for every production secret class.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  25. Logging and audit evidence

    Define security-relevant events and required context fields.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  26. Logging and audit evidence · blocking

    Verify logs avoid secrets and unnecessary personal data.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  27. Logging and audit evidence

    Test audit access, retention, integrity and investigation retrieval.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  28. Privacy and data lifecycle

    Map purposes, lawful bases, data categories and processors.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  29. Privacy and data lifecycle · blocking

    Test retention, deletion, export and correction procedures.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  30. Privacy and data lifecycle

    Record privacy-impact decisions for custom fields, AI and integrations.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  31. Custom code and secure SDLC

    Define review and test gates for security-sensitive changes.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  32. Custom code and secure SDLC

    Trace one custom module from requirement through threat review and tests.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  33. Custom code and secure SDLC

    Document separation of duties for code, deployment and approval.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  34. Dependencies and updates

    Inventory direct, transitive, container and runtime dependencies.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  35. Dependencies and updates

    Define vulnerability triage, patch timing and exception ownership.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  36. Dependencies and updates

    Rehearse framework and dependency upgrades against custom modules.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  37. Integrations and webhooks

    Inventory credentials, endpoints, scopes and systems of record.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  38. Integrations and webhooks

    Verify signing, replay protection, idempotency, retries and reconciliation.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  39. Integrations and webhooks

    Define safe behavior for provider outage, duplicate and partial delivery.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  40. Infrastructure and network

    Document production topology, ingress, egress and administrative access.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  41. Infrastructure and network

    Verify database, Redis, search and worker services are not unintentionally exposed.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  42. Infrastructure and network

    Record hardening, patching and configuration-drift controls.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  43. Backup and recovery

    Define backup scope, retention, encryption, RPO and RTO.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  44. Backup and recovery

    Provide a dated restore test including attachments and dependent services.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  45. Backup and recovery

    Document recovery authority, communications and evidence preservation.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  46. Monitoring and incident response

    Define alerts for authentication, authorization, data access and delivery failures.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  47. Monitoring and incident response

    Name on-call ownership and escalation for each critical alert.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  48. Monitoring and incident response

    Run and record an incident exercise from detection through recovery.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  49. Vulnerability and patch handling

    Define intake and severity rules for reports and scanner findings.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  50. Vulnerability and patch handling

    Record remediation owners, due dates, retest evidence and exceptions.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  51. Vulnerability and patch handling

    Verify emergency patch and rollback procedures.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  52. Suppliers and processors

    Inventory hosting, model, email, payment, storage and support suppliers.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  53. Suppliers and processors

    Record data, region, subprocessor, access and exit implications.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  54. Suppliers and processors

    Review contractual and technical evidence before supplier approval.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  55. Verification evidence

    Map threat and control claims to tests or review evidence.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  56. Verification evidence

    Independently review high-risk custom code and configuration.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  57. Verification evidence

    Track failed tests, limitations and remediation to closure.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  58. Exceptions, residual risk and sign-off

    List unresolved gaps with business impact and compensating controls.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  59. Exceptions, residual risk and sign-off

    Name the role authorized to accept each residual risk.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.

  60. Exceptions, residual risk and sign-off · blocking

    Record the decision date, expiry or review trigger and go-live consequence.

    Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.