Classify control evidence by whether it prevents, detects, corrects, or proves governance accountability.
Place each evidence item by the purpose it primarily serves. Preventive Detective Corrective Accountability MFA enforcement policy showing admins cannot log in without a second factor Weekly report listing privileged accounts with unusual login patterns Ticket showing stale vendor accounts were disabled after review Business owner sign-off accepting a 30-day exception for a legacy system Cloud policy preventing public object storage by default SIEM alert history showing failed privilege-escalation attempts were noticed Patch deployment record closing a critical vulnerability on the payment service Quarterly control review minutes with named unresolved risk owners
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in