Skip to main content

Providing Evidence

Evidence helps demonstrate that a control, treatment, or remediation action has been implemented as described.

What makes evidence useful

Strong evidence is:
  • relevant — it addresses the specific claim or request,
  • current — it reflects the period or implementation being assessed,
  • attributable — the source and context can be understood,
  • complete enough — it shows the important part of the control without requiring guesswork,
  • appropriately scoped — it avoids unrelated sensitive information.

Common evidence examples

Depending on the request, useful evidence may include:
  • approved policies or procedures,
  • configuration screenshots,
  • access review records,
  • vulnerability or patch reports,
  • change records,
  • backup or restore results,
  • logging or alert examples,
  • training completion records,
  • architecture diagrams,
  • implementation tickets,
  • test results,
  • management approvals.

Before uploading

Ask:
  1. Does this file actually support the requested claim?
  2. Is the date or environment visible enough to understand it?
  3. Does it contain passwords, secrets, private keys, tokens, or unnecessary personal data?
  4. Can irrelevant sensitive information be removed or redacted?
  5. Is there a more direct artifact that would be easier to evaluate?
Do not upload credentials, private keys, authentication tokens, recovery codes, or other secrets as evidence.

Add context

A short description can dramatically improve evidence quality. Explain:
  • what the artifact is,
  • what system or control it relates to,
  • the relevant date or period,
  • what the reviewer should notice.

Evidence requests

When responding to a specific evidence request, use the request’s scope as your guide. If the requested artifact does not exist, say so and provide the best available alternative rather than manufacturing a document solely to satisfy the request.

Guided evidence collection

Where guided evidence features are enabled, the application may help you understand what to provide or capture. These features assist collection; they do not replace reviewer judgment.

After submission

Cyber Op Source may:
  • accept the evidence,
  • ask for clarification,
  • request a stronger artifact,
  • determine that the evidence supports only part of the claim,
  • use it with other evidence during verification.