Skip to main content

Evidence Collection

Collect, organize, and manage compliance evidence for audits

evidencecomplianceauditartifacts

Evidence Collection

Securtea automatically collects compliance evidence during assessments. Organize, supplement, and package evidence for auditors and compliance reviews.

What is Evidence?

Evidence demonstrates that your organization meets compliance requirements:

  • Technical evidence - Configuration screenshots, API responses, system logs
  • Policy evidence - Written policies, procedures, documentation
  • Attestations - Signed acknowledgments, training records
  • Artifacts - Any supporting documentation

Evidence Sources

Automatic Collection

Securtea automatically collects evidence during:

ActivityEvidence Type
Compliance assessmentsConfiguration data, control results
Drift detectionConfiguration snapshots
Report generationPoint-in-time data captures

Manual Uploads

Supplement automatic evidence with:

  • Policy documents
  • Training records
  • Meeting minutes
  • External audit reports
  • Screenshots
  • Signed attestations

Evidence Organization

By Control

Evidence is organized by compliance control:

Framework: CIS Microsoft 365
├── Theme: Identity & Access
│   ├── Control: Enable MFA for admins
│   │   ├── Conditional Access Policy screenshot
│   │   ├── MFA registration report
│   │   └── Policy acknowledgment
│   └── Control: Block legacy auth
│       └── Authentication policy configuration

By Framework

View all evidence for a framework:

  1. Go to Evidence > By Framework
  2. Select framework
  3. See all controls with evidence status

Evidence Status

StatusMeaning
CompleteSufficient evidence collected
PartialSome evidence, needs more
MissingNo evidence available
Manual RequiredNeeds manual upload

Getting Started

View Collected Evidence

  1. Navigate to Evidence in the sidebar
  2. Browse by framework or control
  3. Click any control to see evidence

Upload Evidence

  1. Find the control needing evidence
  2. Click Upload Evidence
  3. Select file(s)
  4. Add description/context
  5. Click Upload

Review Evidence Gaps

  1. Go to Evidence > Gaps
  2. See controls with missing evidence
  3. Prioritize by severity
  4. Upload or generate evidence

What's Next?

Global Search

Search for pages, settings, and documentation