Evidence must be traceable to the source and support the stated control requirement.

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

Where did your evidence come from?

For example, as an auditor, you obtain evidence through inquiry, direct observation, screenshot, testing a system or obtaining a file sample such as a configuration file from the client during direct observation, the evidence contains details to include:

  • Date: What is the date of the sample?
    Use system date stamps, system date commands or even including the endpoints system date and time display in the screenshot.

  • Source: Where did the evidence come from?
    Use hostname displays, system commands for host, or other parameters to show the source of the sample.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.