← WRITING  ·  GRC NOTE

Evidence is not theatre.

A screenshot can show that someone opened a dashboard. It cannot prove the population, time window, result, or remediation. Evidence is a chain another person can follow.

By Zion Boggan ·

The evidence question is simple: what was checked, against what, by whom, when, and what happened next?

Build a small packet, not a screenshot wall

Evidence packet made from scope, source, result, receipt, and reviewSCOPEwhat was checkedSOURCEauthoritative inputRESULTpass or failRECEIPTwhat changedREVIEWwhat remains
A packet preserves the path from a control run to an independent review.
Vertical evidence packet chainSCOPEwhat was checkedSOURCEauthoritative inputRESULTpass or failRECEIPTwhat changedREVIEWwhat remains
One packet preserves scope, source, result, receipt, and review.

A useful packet can be a folder with five files: period and scope metadata, the source export, the query or procedure output, remediation receipts, and an exception record. Include a short reviewer note that says what was checked and what was not checked.

What common evidence proves, and what it does not

policy

Review date

Proves the document was reviewed. It does not prove the behavior happened.

ticket

Closed status

Proves a workflow field changed. It does not prove the affected system changed without a receipt.

dashboard

Green number

Proves a report rendered. It does not prove that the population or source ledger was correct.

scan

Clean result

Proves what the scanner could see. It does not prove that every required asset was in scope.

Anti-theatre rule: if the artifact cannot identify its scope, time, source, operator, and result, call it an illustration until those fields are added.

Sample the population before sampling the records

Define the population first. Keep the rule or seed used to select the sample. Include a recent item, a high-impact item, an exception, and at least one item selected without operator choice when the population allows it.

A perfect sample chosen by the control owner is a demonstration. An independent sample tests whether the control works beyond the examples someone prepared for review.

Score evidence honestly

0 · absent

No record

There is no evidence, or there is only a policy statement.

1 · weak

Record without context

A file exists, but scope, time, or result cannot be established.

2 · repeatable

Traceable run

Source, scope, operator, time, result, and remediation can be followed.

3 · durable

Independent proof

The packet is retained, access-controlled, integrity-protected, and reviewable.

Do not increase the score because the control is important. Score the evidence that exists. The gap itself belongs in the risk register.

A final reviewer test

Give the packet to someone who did not run the control. Ask them to identify the population, repeat the test, find the failures, and locate each remediation receipt. If they need the operator to translate the evidence, the next improvement is obvious.

Framework context: NIST CSF 2.0 and NIST SP 800-53 Rev. 5.