Skip to content

[pull] main from CPAtoCybersecurity:main - #38

Merged
pull[bot] merged 4 commits into
ericrihm:mainfrom
CPAtoCybersecurity:main
Jul 29, 2026
Merged

[pull] main from CPAtoCybersecurity:main#38
pull[bot] merged 4 commits into
ericrihm:mainfrom
CPAtoCybersecurity:main

Conversation

@pull

@pull pull Bot commented Jul 29, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

ElRonEl and others added 4 commits July 27, 2026 15:52
PROC-incident-response-playbook.md lists "Evidence Preservation Guide -
ALMA-SOP-2025-010b" in its Related Documents table, and both RS.AN-06
and RS.AN-07 ask the assessor to verify chain-of-custody and provenance
documentation exists -- but ALMA-SOP-2025-010b was never written.

Adds the guide as the sibling procedure the playbook already points
to, under Nadia Khan (Detection & Response Lead, matching the
playbook's own ownership), covering evidence collection priority
(volatile-first), chain of custody, integrity/hashing controls, and
retention -- grounded in Alma's actual stack (SentinelOne, GuardDuty,
CloudTrail, ServiceNow), not a generic template.

Links RS.AN-06 and RS.AN-07's Evidence Requests checklists to the new
guide so both test procedures point at something real. Regenerates
communityProcedures.json to match (generate-procedure-bank.mjs --check
was failing before this).

Closes #45
Add Evidence Preservation Guide artifact for RS.AN (#45)
Clarified retention of evidence related to ServiceNow incidents and removed reference to the playbook's Related Documents table.
…tch-9

Update evidence retention guidelines in PROC-evidence-preservation-guide
@pull pull Bot locked and limited conversation to collaborators Jul 29, 2026
@pull pull Bot added the ⤵️ pull label Jul 29, 2026
@pull
pull Bot merged commit 22de07a into ericrihm:main Jul 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants