The company formally requires that evidence of security controls is collected and maintained for audit purposes
Stating in writing which controls require retained evidence and how long it is kept extends this control's record-protection principle to the audit evidence itself.
This policy control states in writing which controls require retained evidence, where it lives and how long it is kept, the evidence standard A.5.36's compliance checking is built on.
https://sekit.ai/api/mcp/crosswalk