Evidence Collection
Collect, organize, and manage compliance evidence for audits
evidencecomplianceauditartifacts
Evidence Collection
Securtea automatically collects compliance evidence during assessments. Organize, supplement, and package evidence for auditors and compliance reviews.
What is Evidence?
Evidence demonstrates that your organization meets compliance requirements:
- Technical evidence - Configuration screenshots, API responses, system logs
- Policy evidence - Written policies, procedures, documentation
- Attestations - Signed acknowledgments, training records
- Artifacts - Any supporting documentation
Evidence Sources
Automatic Collection
Securtea automatically collects evidence during:
| Activity | Evidence Type |
|---|---|
| Compliance assessments | Configuration data, control results |
| Drift detection | Configuration snapshots |
| Report generation | Point-in-time data captures |
Manual Uploads
Supplement automatic evidence with:
- Policy documents
- Training records
- Meeting minutes
- External audit reports
- Screenshots
- Signed attestations
Evidence Organization
By Control
Evidence is organized by compliance control:
Framework: CIS Microsoft 365
├── Theme: Identity & Access
│ ├── Control: Enable MFA for admins
│ │ ├── Conditional Access Policy screenshot
│ │ ├── MFA registration report
│ │ └── Policy acknowledgment
│ └── Control: Block legacy auth
│ └── Authentication policy configuration
By Framework
View all evidence for a framework:
- Go to Evidence > By Framework
- Select framework
- See all controls with evidence status
Evidence Status
| Status | Meaning |
|---|---|
| Complete | Sufficient evidence collected |
| Partial | Some evidence, needs more |
| Missing | No evidence available |
| Manual Required | Needs manual upload |
Getting Started
View Collected Evidence
- Navigate to Evidence in the sidebar
- Browse by framework or control
- Click any control to see evidence
Upload Evidence
- Find the control needing evidence
- Click Upload Evidence
- Select file(s)
- Add description/context
- Click Upload
Review Evidence Gaps
- Go to Evidence > Gaps
- See controls with missing evidence
- Prioritize by severity
- Upload or generate evidence
What's Next?
- Evidence Artifacts - View and manage evidence files
- Evidence Gaps - Identify and resolve missing evidence
- Attestations - Manage signed attestations
- Evidence Bundles - Package evidence for audits