Evidence & audit readiness
Vendor-neutral guidance for founders, CTOs, and compliance owners on the artifacts that evidence security controls — what to keep, where each one lives, how long to retain it, and what makes it sufficient. Not legal advice. Does not determine your obligations.
What security evidence should your company keep?
The eight categories of security evidence to keep — access, change, vulnerability, logging, training, incident, vendor, policy — and what each proves. Not legal advice.
How long should you keep each security evidence artifact?
A security evidence retention checklist: artifact, owner, source system, retention window, and the requirement driving it. Legal minimums separated from best practice.
Which GitHub artifacts count as security evidence?
Which GitHub artifacts evidence access, change, and vulnerability controls — rulesets, required reviews, code and secret scanning, Dependabot, audit log. Not legal advice.
Which GitLab artifacts count as security evidence?
Which GitLab artifacts evidence access, change, and vulnerability controls — protected branches, MR approval rules, security scanning, audit events. Not legal advice.
Which AWS artifacts count as security evidence?
Which AWS services evidence security controls — CloudTrail, Config, IAM, GuardDuty, Security Hub, KMS — and where the shared-responsibility line sits. Not legal advice.
Which Azure artifacts count as security evidence?
Which Azure services evidence security controls — Entra ID, diagnostic logs, Defender for Cloud, Azure Policy, Key Vault — and where responsibility splits. Not legal advice.
Which GCP artifacts count as security evidence?
Which Google Cloud services evidence security controls — Cloud Audit Logs, IAM and Policy Analyzer, Security Command Center, Cloud KMS, VPC Service Controls. Not legal advice.
Which CI/CD pipeline artifacts count as audit evidence?
Which CI/CD artifacts evidence secure build and controlled deployment — required checks, provenance, signing, deploy approvals, pipeline logs. SLSA labelled best practice.
Which IAM artifacts prove access control works?
Which identity and access artifacts prove access control works — joiner and leaver records, access reviews, MFA enforcement, privileged access. Not legal advice.
What vulnerability management evidence do auditors expect?
What vulnerability management evidence auditors expect — scan coverage, prioritisation, remediation SLA tracking, risk acceptance. KEV, EPSS and CVSS as best practice.
Which SBOM artifacts count as audit evidence?
Which SBOM artifacts count as evidence — per-release inventories, formats, storage, signing — and where SBOM is a legal requirement rather than best practice. Not advice.
Which dependency artifacts prove supply-chain hygiene?
Which dependency artifacts prove supply-chain hygiene — lockfiles, update records, remediation, licence inventory, transitive risk. Licence duties are legal; cadence is not.
What penetration testing evidence do auditors accept?
What penetration testing evidence auditors and customers accept — scope and rules of engagement, attestation letters, findings, remediation, retest. Not legal advice.
What security training evidence should you keep?
What security awareness training evidence to keep — completion records, curriculum, phishing simulations, role-based training, policy acknowledgements. Not legal advice.
Which change management artifacts evidence controlled change?
Which change management artifacts evidence controlled change — peer review, testing, deployment authorisation, emergency change, segregation of duties. Not legal advice.
Which incident-management artifacts should you preserve?
Which incident-management artifacts to preserve — detection records, timelines, severity decisions, comms, post-incident review — and the reporting clocks. Not legal advice.
Which AI governance artifacts should you keep?
Which AI governance artifacts to keep — system inventory, risk classification, model and dataset documentation, human-oversight and monitoring records. Not legal advice.
How long should security logs be retained?
Defensible log retention by log type, with the citation behind each period — PCI DSS twelve months, audit-period coverage — and the GDPR tension. Not legal advice.
How do you build an audit evidence repository?
A reference structure for an audit evidence repository — taxonomy, naming, versioning, access control, freshness, and a control-to-evidence index. Not legal advice.
What is continuous evidence collection?
Continuous evidence collection compared with point-in-time capture — what it changes, why it is best practice rather than a legal mandate, and what automation cannot evidence.
How do you prove a security control actually works?
Design effectiveness compared with operating effectiveness — populations, sampling, timeframes, and the evidence that shows a control operated consistently. Not legal advice.