The Evidence Principle
Evidence proves your controls exist and work. Without it, you're just claiming compliance.
What Counts as Evidence
Strong Evidence
•System-generated logs (access logs, change management records)
•Screenshots with timestamps
•Signed documents with dates
•Configuration exports from tools
•Training completion records from your LMS
•Automated scan reports
Weak Evidence
•Self-assessments without supporting data
•Policies without proof of communication
•Meeting agendas without minutes or decisions
•"We do this" without proof
Not Evidence
•Plans to implement something
•Good intentions
•A policy nobody has read
Organising Evidence
By Control
Map evidence to specific Annex A controls. One piece of evidence can support multiple controls.
Keep It Current
Evidence should demonstrate ongoing compliance, not just point-in-time. Aim for:
•Monthly or quarterly samples for operational controls
•Annual evidence for governance controls
•Continuous evidence from automated tools
What Auditors Look For
•Consistency Does evidence match what policies claim?
•Timeliness Is evidence recent and representative?
•Completeness Are all applicable controls covered?
•Authenticity Can you show this wasn't fabricated?
Pro Tip
Start collecting evidence from day one. The biggest pain in certification prep is backfilling evidence that should have been captured months ago.