Providing Evidence
Evidence helps demonstrate that a control, treatment, or remediation action has been implemented as described.
What makes evidence useful
Strong evidence is:
- relevant — it addresses the specific claim or request,
- current — it reflects the period or implementation being assessed,
- attributable — the source and context can be understood,
- complete enough — it shows the important part of the control without requiring guesswork,
- appropriately scoped — it avoids unrelated sensitive information.
Common evidence examples
Depending on the request, useful evidence may include:
- approved policies or procedures,
- configuration screenshots,
- access review records,
- vulnerability or patch reports,
- change records,
- backup or restore results,
- logging or alert examples,
- training completion records,
- architecture diagrams,
- implementation tickets,
- test results,
- management approvals.
Before uploading
Ask:
- Does this file actually support the requested claim?
- Is the date or environment visible enough to understand it?
- Does it contain passwords, secrets, private keys, tokens, or unnecessary personal data?
- Can irrelevant sensitive information be removed or redacted?
- Is there a more direct artifact that would be easier to evaluate?
Do not upload credentials, private keys, authentication tokens, recovery codes, or other secrets as evidence.
Add context
A short description can dramatically improve evidence quality.
Explain:
- what the artifact is,
- what system or control it relates to,
- the relevant date or period,
- what the reviewer should notice.
Evidence requests
When responding to a specific evidence request, use the request’s scope as your guide. If the requested artifact does not exist, say so and provide the best available alternative rather than manufacturing a document solely to satisfy the request.
Guided evidence collection
Where guided evidence features are enabled, the application may help you understand what to provide or capture. These features assist collection; they do not replace reviewer judgment.
After submission
Cyber Op Source may:
- accept the evidence,
- ask for clarification,
- request a stronger artifact,
- determine that the evidence supports only part of the claim,
- use it with other evidence during verification.