Evidence, with its limits visible

What a record proves—and what it does not.

A policy, an implementation record and evidence that a control operated are not interchangeable. These entries help you describe the artifact you actually have.

information security

Audit-log export

A scoped, time-bounded export of system events with provenance sufficient to connect actions, actors and affected objects.

Likely owner: security lead

business continuity and backups

Backup restoration test record

A dated record showing that selected backup data was restored, checked against defined criteria and followed by recorded actions.

Likely owner: infrastructure lead

identity and access

Completed access-review record

A preserved record of the population reviewed, accountable reviewers, decisions, exceptions and completed follow-up actions.

Likely owner: system owner

employee lifecycle

Employee offboarding record

A dated record connecting a worker’s departure or role change to approved tasks, responsible owners, completion and exceptions.

Likely owner: people lead

identity and access

Identity-provider user and access export

A scoped export of identities, account status, groups or assigned applications from a central identity provider at a recorded time.

Likely owner: IT administrator

incident response

Incident-response exercise record

A dated record of an incident scenario, participants, decisions, observations, actions and follow-up from a tabletop or operational exercise.

Likely owner: security lead

secure software development

Penetration-test executive summary

A controlled summary of an authorized security test, including scope, dates, method, high-level findings and remediation status.

Likely owner: security lead

policies and training

Security-policy acknowledgement record

A record that a defined person or population received and acknowledged a particular version of a security policy.

Likely owner: people lead

policies and training

Security-training completion report

A dated system report showing the assigned population, training module, completion status and relevant exceptions.

Likely owner: people lead

privacy and data processing

Subprocessor register

A maintained list of third parties that process relevant personal data, with service, location, purpose and change information.

Likely owner: privacy lead