Evidence Requests
System Evidence Checklist
Use this checklist to validate claims against systems of record. Evidence should support discovery findings, maturity scores, and recommendations.
Source control
Collect evidence for:
- Repository ownership.
- Branch protection or merge rules.
- Pull request review practices.
- Recent change volume.
- Dependency update activity.
CI/CD
Collect evidence for:
- Pipeline definitions.
- Required checks.
- Build and deployment history.
- Failed deployment patterns.
- Artifact publishing and promotion records.
- Secrets and permissions used by pipelines.
Cloud and infrastructure
Collect evidence for:
- Accounts, subscriptions, projects, and regions.
- Runtime platforms and resource ownership.
- IAM roles, groups, and privileged access.
- Infrastructure-as-code coverage.
- Drift or manually managed resources.
- Cost allocation and tagging coverage.
Observability and incidents
Collect evidence for:
- Dashboards for critical systems.
- Alert definitions and routing.
- Recent incident timelines.
- Runbooks linked from alerts.
- SLOs or customer-facing reliability targets.
Security and compliance
Collect evidence for:
- Vulnerability findings and remediation age.
- Secret scanning results.
- Access review exports.
- Audit logs and retention settings.
- Policy exceptions and expiry dates.
Watchouts
- Do not rely only on interviews for high-impact recommendations.
- Evidence access may require privacy or security approval.
- Record evidence gaps explicitly when access is unavailable.