Skip to content

Evidence request lists

C2M2

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

C2M2 Domain: Asset, Change and Configuration Management (ASSET)

ASSET-1
Manage IT and OT Asset Inventory

ASSET domain. Establish and maintain an inventory of IT and OT assets (hardware, software, information) within the function, prioritised by importance, as the basis for cybersecurity activities.

Artefacts an auditor will ask for
  • IT and OT asset inventory with ownership and criticality
  • Process to keep the inventory current
  • Prioritisation of assets by importance to the function
Where this commonly fails
  • OT assets omitted from inventory
  • Inventory stale
  • Assets not prioritised
ASSET-2
Manage Asset Configuration and Changes

ASSET domain. Establish and maintain configuration baselines for assets and manage changes to assets through a defined change-management process.

Artefacts an auditor will ask for
  • Configuration baselines for IT/OT assets
  • Change-management process and records
  • Review of changes for cybersecurity impact
Where this commonly fails
  • No configuration baselines
  • Changes made without change control
  • OT change constraints ignored

C2M2 Domain: Cybersecurity Architecture (ARCHITECTURE)

ARCH-1
Establish a Cybersecurity Architecture Strategy

ARCHITECTURE domain. Establish and maintain a cybersecurity architecture strategy and program to guide the secure design of IT and OT systems.

Artefacts an auditor will ask for
  • Documented cybersecurity architecture strategy/program
  • Secure-design standards for IT/OT
  • Architecture review of new systems
Where this commonly fails
  • No architecture strategy
  • No secure-design standards
  • Architecture not reviewed
ARCH-2
Implement Network Protections

ARCHITECTURE domain. Implement network protections including segmentation between IT and OT, boundary protection, and network monitoring.

Artefacts an auditor will ask for
  • Network segmentation between IT, OT and external networks
  • Boundary protection (firewalls, DMZ) configurations
  • Network monitoring
Where this commonly fails
  • No IT/OT segmentation
  • Weak boundary protection
  • No network monitoring
ARCH-3
Implement Data Security

ARCHITECTURE domain. Implement data security protections including data protection, integrity, and cryptography for data at rest and in transit.

Artefacts an auditor will ask for
  • Data protection and classification
  • Encryption of data at rest and in transit
  • Key management
Where this commonly fails
  • Data not protected by classification
  • No encryption
  • No key management

C2M2 Domain: Cybersecurity Program Management (PROGRAM)

PROGRAM-1
Establish and Maintain the Cybersecurity Program

PROGRAM domain. Establish and maintain an enterprise cybersecurity program with governance, sponsorship, resourcing and periodic management review, and an information-sharing capability.

Artefacts an auditor will ask for
  • Board/executive-sponsored cybersecurity program
  • Program governance, funding and management review
  • Participation in information-sharing forums (e.g. ISACs)
Where this commonly fails
  • No program governance/sponsorship
  • Program not reviewed
  • No information sharing

C2M2 Domain: Event and Incident Response, Continuity of Operations (RESPONSE)

RESPONSE-1
Detect and Analyze Cybersecurity Events

RESPONSE domain. Detect cybersecurity events and analyse them to determine whether they are incidents requiring response.

Artefacts an auditor will ask for
  • Event detection and triage procedures
  • Criteria for declaring incidents
  • Records of event analysis
Where this commonly fails
  • Events not detected/triaged
  • No incident-declaration criteria
  • Analysis not recorded
RESPONSE-2
Respond to and Recover from Cybersecurity Incidents

RESPONSE domain. Establish and maintain incident response capabilities to respond to, recover from, and report cybersecurity incidents, including coordination with authorities.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Incident records, post-incident reviews and reporting to authorities
  • Exercises/drills (including OT scenarios)
Where this commonly fails
  • No incident response plan
  • Incidents not reported
  • No exercises
RESPONSE-3
Plan for Continuity of Operations

RESPONSE domain. Establish and maintain continuity of operations plans to sustain or restore the function's operations following a cybersecurity incident or disruption.

Artefacts an auditor will ask for
  • Continuity of operations / disaster recovery plans
  • Recovery objectives (RTO/RPO) and backups
  • Continuity testing records
Where this commonly fails
  • No continuity plan
  • Recovery objectives undefined
  • Continuity untested

C2M2 Domain: Identity and Access Management (ACCESS)

ACCESS-1
Establish and Maintain Identities

ACCESS domain. Establish and maintain identities for personnel, services and devices, governing the identity lifecycle (provisioning, change, de-provisioning).

Artefacts an auditor will ask for
  • Identity lifecycle (joiner/mover/leaver) process and records
  • Identity inventory for personnel/services/devices
  • De-provisioning on separation
Where this commonly fails
  • Identities not lifecycle-managed
  • Orphan/stale identities
  • De-provisioning delayed
ACCESS-2
Control Logical and Physical Access

ACCESS domain. Control logical and physical access to assets commensurate with risk, including least privilege, privileged access management and remote access controls.

Artefacts an auditor will ask for
  • Least-privilege and segregation-of-duties controls
  • Privileged access management
  • Logical and physical access reviews
Where this commonly fails
  • Excessive privilege
  • Privileged access uncontrolled
  • Access not reviewed

C2M2 Domain: Risk Management (RISK)

RISK-1
Establish a Cyber Risk Management Strategy and Program

RISK domain. Establish and maintain a cyber risk management strategy and program, including governance, risk appetite/tolerance, and integration with enterprise risk management.

Artefacts an auditor will ask for
  • Documented cyber risk management strategy and program
  • Risk appetite/tolerance statements
  • Integration with enterprise risk management
Where this commonly fails
  • No risk strategy
  • Risk appetite undefined
  • Cyber risk not integrated with ERM
RISK-2
Identify and Analyze Cyber Risk

RISK domain. Identify and analyse cybersecurity risk to the function, considering threats, vulnerabilities, likelihood and impact.

Artefacts an auditor will ask for
  • Cyber risk register with analysed risks
  • Risk assessment methodology
  • Periodic reassessment
Where this commonly fails
  • Risks not identified/analysed
  • No methodology
  • Assessment not updated
RISK-3
Manage and Respond to Cyber Risk

RISK domain. Manage cybersecurity risk through prioritised risk responses (accept, mitigate, transfer, avoid) and monitoring of residual risk.

Artefacts an auditor will ask for
  • Documented risk responses and treatment plans
  • Residual risk monitoring
  • Risk acceptance approvals
Where this commonly fails
  • Risks not treated
  • Residual risk unmonitored
  • No documented acceptance

C2M2 Domain: Situational Awareness (SITUATION)

SITUATION-1
Perform Logging and Monitoring

SITUATION domain. Perform logging and monitoring of IT and OT to support detection of anomalies and cybersecurity events.

Artefacts an auditor will ask for
  • Logging configured across IT/OT where feasible
  • Monitoring/alerting for anomalies
  • Log retention and protection
Where this commonly fails
  • Inadequate logging (esp. OT)
  • No monitoring/alerting
  • Logs not retained/protected
SITUATION-2
Establish and Maintain a Common Operating Picture

SITUATION domain. Establish and maintain situational awareness through a common operating picture that aggregates monitoring, threat and status information for decision-making.

Artefacts an auditor will ask for
  • Aggregated situational-awareness/COP capability
  • Correlation of monitoring and threat data
  • Reporting to decision-makers
Where this commonly fails
  • No common operating picture
  • Data not correlated
  • Decision-makers not informed

C2M2 Domain: Third-Party Risk Management (THIRD-PARTIES)

THIRD-1
Identify and Manage Third-Party Risk

THIRD-PARTIES domain. Identify and manage cybersecurity risks arising from third parties and external dependencies (suppliers, service providers, vendors).

Artefacts an auditor will ask for
  • Inventory of third parties and external dependencies
  • Third-party cyber risk assessments
  • Security requirements in third-party agreements
Where this commonly fails
  • Third parties not inventoried
  • No third-party risk assessment
  • No security terms in agreements
THIRD-2
Manage Supplier Relationships and Incident Notification

THIRD-PARTIES domain. Manage ongoing supplier relationships, monitor third-party security, and require notification of third-party cybersecurity incidents affecting the function.

Artefacts an auditor will ask for
  • Ongoing third-party monitoring
  • Incident-notification clauses and records
  • Exit/transition arrangements for critical suppliers
Where this commonly fails
  • No ongoing monitoring
  • No incident-notification requirement
  • No exit planning

C2M2 Domain: Threat and Vulnerability Management (THREAT)

THREAT-1
Identify and Respond to Cyber Threats

THREAT domain. Establish and maintain a threat profile and the practices to identify, analyse and respond to cybersecurity threats relevant to the function.

Artefacts an auditor will ask for
  • Documented threat profile for the function
  • Threat intelligence sources and analysis
  • Threat-informed response actions
Where this commonly fails
  • No threat profile
  • No threat intelligence
  • Threats not acted upon
THREAT-2
Reduce Cybersecurity Vulnerabilities

THREAT domain. Establish and maintain practices to identify, analyse and reduce cybersecurity vulnerabilities (vulnerability assessment, remediation, and management).

Artefacts an auditor will ask for
  • Vulnerability assessment/scanning of IT and OT
  • Remediation tracking with risk-based prioritisation
  • Patch and mitigation records
Where this commonly fails
  • No vulnerability assessment
  • Vulnerabilities not remediated
  • OT vulnerabilities unmanaged

C2M2 Domain: Workforce Management (WORKFORCE)

WORKFORCE-1
Establish Cybersecurity Responsibilities and Workforce

WORKFORCE domain. Assign cybersecurity responsibilities and manage the cybersecurity workforce (roles, accountability, resourcing).

Artefacts an auditor will ask for
  • Defined cybersecurity roles and responsibilities
  • Workforce/resourcing plan for cybersecurity
  • Accountability assignments
Where this commonly fails
  • Responsibilities undefined
  • Cyber roles unstaffed
  • No accountability
WORKFORCE-2
Develop Cybersecurity Workforce and Awareness

WORKFORCE domain. Develop the cybersecurity workforce through training and conduct security awareness activities for all personnel.

Artefacts an auditor will ask for
  • Cybersecurity training program and completion records
  • Role-based training for cyber staff
  • Security awareness activities
Where this commonly fails
  • No training program
  • Awareness not delivered
  • Cyber staff not developed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.