Local decision and evidence register
Do not enter secrets, personal data, production data, or undisclosed vulnerability details. Answers stay in this browser until you export them.
Scope and governance
Define the systems, environments, organizations and data included in this review.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Scope and governance · blocking
Name the person accountable for accepting security evidence and residual risk.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Scope and governance
Record the review method, evidence cutoff and next review trigger.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Architecture and data flows
Maintain a current system-context and data-flow diagram.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Architecture and data flows · blocking
Mark trust boundaries, external services and privileged paths.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Architecture and data flows
Trace one sensitive business flow through storage, logs, queues and integrations.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Tenancy and isolation
List every tenant and organization scope boundary used by the application.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Tenancy and isolation · blocking
Provide tests for cross-tenant and cross-organization read and write isolation.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Tenancy and isolation
Review custom queries, workers and exports for scope propagation.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Identity and sessions
Document admin, employee, customer and service identities separately.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Identity and sessions · blocking
Review session lifetime, revocation, recovery and privileged reauthentication.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Identity and sessions
Test account lifecycle, invitation and termination paths.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Authorization and RBAC
Map each role to the minimum required feature grants.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Authorization and RBAC · blocking
Test wildcard permissions and denial paths in UI, API, commands and workers.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Authorization and RBAC
Review who can change roles, ACL grants and organization membership.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Input and API security
Inventory public, authenticated and privileged endpoints.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Input and API security · blocking
Provide validation, authorization and rate-limit evidence for exposed inputs.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Input and API security
Test file, URL, redirect and webhook inputs against abuse cases.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Encryption and key management
Classify data requiring encryption in transit and at rest.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Encryption and key management · blocking
Document key custody, access, rotation, revocation and recovery.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Encryption and key management
Verify encrypted-field behavior in reads, search, exports and backups.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Secrets management
Inventory application, database, provider and signing secrets.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Secrets management · blocking
Confirm secrets are excluded from source, logs, exports and client bundles.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Secrets management
Document rotation and emergency revocation for every production secret class.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Logging and audit evidence
Define security-relevant events and required context fields.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Logging and audit evidence · blocking
Verify logs avoid secrets and unnecessary personal data.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Logging and audit evidence
Test audit access, retention, integrity and investigation retrieval.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Privacy and data lifecycle
Map purposes, lawful bases, data categories and processors.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Privacy and data lifecycle · blocking
Test retention, deletion, export and correction procedures.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Privacy and data lifecycle
Record privacy-impact decisions for custom fields, AI and integrations.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Custom code and secure SDLC
Define review and test gates for security-sensitive changes.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Custom code and secure SDLC
Trace one custom module from requirement through threat review and tests.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Custom code and secure SDLC
Document separation of duties for code, deployment and approval.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Dependencies and updates
Inventory direct, transitive, container and runtime dependencies.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Dependencies and updates
Define vulnerability triage, patch timing and exception ownership.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Dependencies and updates
Rehearse framework and dependency upgrades against custom modules.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Integrations and webhooks
Inventory credentials, endpoints, scopes and systems of record.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Integrations and webhooks
Verify signing, replay protection, idempotency, retries and reconciliation.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Integrations and webhooks
Define safe behavior for provider outage, duplicate and partial delivery.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Infrastructure and network
Document production topology, ingress, egress and administrative access.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Infrastructure and network
Verify database, Redis, search and worker services are not unintentionally exposed.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Infrastructure and network
Record hardening, patching and configuration-drift controls.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Backup and recovery
Define backup scope, retention, encryption, RPO and RTO.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Backup and recovery
Provide a dated restore test including attachments and dependent services.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Backup and recovery
Document recovery authority, communications and evidence preservation.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Monitoring and incident response
Define alerts for authentication, authorization, data access and delivery failures.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Monitoring and incident response
Name on-call ownership and escalation for each critical alert.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Monitoring and incident response
Run and record an incident exercise from detection through recovery.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Vulnerability and patch handling
Define intake and severity rules for reports and scanner findings.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Vulnerability and patch handling
Record remediation owners, due dates, retest evidence and exceptions.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Vulnerability and patch handling
Verify emergency patch and rollback procedures.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Suppliers and processors
Inventory hosting, model, email, payment, storage and support suppliers.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Suppliers and processors
Record data, region, subprocessor, access and exit implications.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Suppliers and processors
Review contractual and technical evidence before supplier approval.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Verification evidence
Map threat and control claims to tests or review evidence.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Verification evidence
Independently review high-risk custom code and configuration.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Verification evidence
Track failed tests, limitations and remediation to closure.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Exceptions, residual risk and sign-off
List unresolved gaps with business impact and compensating controls.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Exceptions, residual risk and sign-off
Name the role authorized to accept each residual risk.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.
Exceptions, residual risk and sign-off · blocking
Record the decision date, expiry or review trigger and go-live consequence.
Expected evidence: Record a non-sensitive policy, diagram, test, report or ticket reference.