Skip to content
Last updated: Sep 25, 2026

Evidence Register ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. For each control, the artifact that demonstrates it operates, its location, and its freshness. Supports audit preparation and identifies controls that are asserted but not yet evidenced.

How to read ​

Evidence is ranked by audit strength (strongest first):

  1. Automated — CI results, configuration queries.
  2. System-generated — logs, tickets, scan reports.
  3. Manual — screenshots, attestations.

Each entry ties to a control and carries a collection cadence and last-collected date. Controls whose evidence is past its cadence are flagged as stale.

Register ​

ControlEvidence artifactTypeCadenceLast collectedState
D7-06Cross-tenant access CI test resultAutomatedContinuous—🔴
CTL-…—————

Register to be completed alongside controls.yml.

Source of detail ​

Entries link to the source artifact — CI run, configuration export, or tracking issue. This register indexes where proof is held; it does not reproduce the proof.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial structure.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.