Evidence Register
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. For each control, the artifact that demonstrates it operates, its location, and its freshness. Supports audit preparation and identifies controls that are asserted but not yet evidenced.
How to read
Evidence is ranked by audit strength (strongest first):
- Automated — CI results, configuration queries.
- System-generated — logs, tickets, scan reports.
- Manual — screenshots, attestations.
Each entry ties to a control and carries a collection cadence and last-collected date. Controls whose evidence is past its cadence are flagged as stale.
Register
| Control | Evidence artifact | Type | Cadence | Last collected | State |
|---|---|---|---|---|---|
| D7-06 | Cross-tenant access CI test result | Automated | Continuous | — | 🔴 |
| CTL-… | — | — | — | — | — |
Register to be completed alongside controls.yml.
Source of detail
Entries link to the source artifact — CI run, configuration export, or tracking issue. This register indexes where proof is held; it does not reproduce the proof.
Related
- → Control Register — the controls this evidence supports
- → Audit & Assessment Log — assessments that generate evidence
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial structure. |
Finaisse Internal — Confidential. Not for external distribution.