Evidence Collection
Evidence links your security posture to ISM controls. QuantAssure collects evidence automatically from pipeline runs and allows you to add manual evidence for controls that aren't covered by integrations.
Evidence Types
| Type | Source | Example |
|---|---|---|
| Finding | Pipeline scans | Dependabot alert mapped to ISM-1504 |
| Policy | Google Drive sync | Information Security Policy |
| Audit Log | System activity | Change to control status |
| Security Check | Integration scans | MFA enforcement check |
| Manual | User upload | Screenshot, config export, attestation |
| Assessor Review | SOA import | Assessor determination and notes |
Automated Evidence
How Findings Link to Controls
- Pipeline runs collect findings from your integrations
- AI enrichment maps findings to specific ISM controls
- Linked findings appear automatically on the control detail page
- Run scans regularly to keep evidence current
Policy Evidence
- Policies synced from Google Drive provide documentary evidence
- Link policies to your compliance framework
- Policies are referenced by AI during assessment
Tip: Run pipeline scans weekly to maintain fresh automated evidence.
Manual Evidence
When to Add Manual Evidence
- Physical security controls (building access, server room)
- Procedural controls (hiring processes, training records)
- Third-party attestations (vendor security certifications)
- Configuration screenshots not captured by integrations
Adding Evidence
- Navigate to the ISM control detail page
- Scroll to the Evidence section
- Enter a title (e.g., "MFA configuration screenshot")
- Add a description explaining what the evidence demonstrates
- Optionally add a URL linking to the source document
- Click Add Evidence
Evidence Freshness
| Status | Age | Meaning |
|---|---|---|
| Fresh | < 60 days | Current and audit-ready |
| Aging | 60–90 days | Consider refreshing before audit |
| Stale | > 90 days | Should be refreshed |
| Expired | Past expiry date | No longer valid |
Warning: Assessors expect recent evidence. Stale evidence may be questioned during audit.
System Boundaries
- Evidence is collected against registered systems and their assets
- If a system isn't registered, its findings won't appear
- If an asset isn't in scope, evidence won't link to controls
- Register all in-scope systems before running assessments