The Evidence page helps you collect and organise the artifacts that prove your controls are operating effectively.

Evidence types

TypeExamples
DocumentPolicies, procedures, process documentation
ScreenshotConfiguration screenshots, dashboard captures
ConfigFirewall rules, GPO exports, Intune policies
ReportVulnerability scan reports, audit reports
CertificateExisting certifications, vendor compliance certificates

Evidence status

  • Current — Up to date and valid
  • Stale — Needs refreshing (e.g., screenshot older than review period)
  • Missing — Required but not yet collected
  • Archived — Historical, no longer the current version

Each evidence item can be linked to a specific control, making it easy to demonstrate coverage during an assessment.