Night Mode LabsBlue Book
Evidence Requests

System Evidence Checklist

Use this checklist to validate claims against systems of record. Evidence should support discovery findings, maturity scores, and recommendations.

Source control

Collect evidence for:

  • Repository ownership.
  • Branch protection or merge rules.
  • Pull request review practices.
  • Recent change volume.
  • Dependency update activity.

CI/CD

Collect evidence for:

  • Pipeline definitions.
  • Required checks.
  • Build and deployment history.
  • Failed deployment patterns.
  • Artifact publishing and promotion records.
  • Secrets and permissions used by pipelines.

Cloud and infrastructure

Collect evidence for:

  • Accounts, subscriptions, projects, and regions.
  • Runtime platforms and resource ownership.
  • IAM roles, groups, and privileged access.
  • Infrastructure-as-code coverage.
  • Drift or manually managed resources.
  • Cost allocation and tagging coverage.

Observability and incidents

Collect evidence for:

  • Dashboards for critical systems.
  • Alert definitions and routing.
  • Recent incident timelines.
  • Runbooks linked from alerts.
  • SLOs or customer-facing reliability targets.

Security and compliance

Collect evidence for:

  • Vulnerability findings and remediation age.
  • Secret scanning results.
  • Access review exports.
  • Audit logs and retention settings.
  • Policy exceptions and expiry dates.

Watchouts

  • Do not rely only on interviews for high-impact recommendations.
  • Evidence access may require privacy or security approval.
  • Record evidence gaps explicitly when access is unavailable.

On this page