Evidence library

Document what changed and what supports it.

Don't merely say the risk was addressed. Record what changed and what supports that conclusion.

Claim

A statement expected to be true, such as “extra sign-in protection is required for administrators.”

Finding

An observed or reported condition compared with the claim, including scope and uncertainty.

Action

The specific change chosen to address, transfer, avoid, accept, or monitor the risk.

Evidence

Information supporting what existed or changed. Its strength depends on relevance, source, date, completeness, and scope.

Reassessment

A new review of the relevant condition after action, kept separate from the fact that a task was completed.

Residual risk

The risk that remains after action, including limits, exceptions, dependencies, and the next review point.

Potentially useful evidence

Configuration recordsScreenshotsPoliciesLogsTicketsApproval recordsVendor documentationTraining recordsInventory records

A screenshot may support one narrow configuration claim but not prove an entire program is effective. Evidence quality and sufficiency depend on the claim, scope, source, timing, and review performed.