Evidence guide

Questions that reveal more than a posture score

This checklist is a conversation aid, not an assessment, penetration test, risk rating, or compliance determination. Good answers point to current evidence, named owners, and tested procedures.

Ownership01

Who owns each critical system, dataset, security control, and escalation decision?

Identity02

Can we show that privileged access is limited, reviewed, and protected with strong authentication?

Assets03

Do we maintain a current inventory with business criticality, owner, exposure, and lifecycle state?

Detection04

Which events are logged, who reviews them, and what evidence proves that the review occurs?

Response05

Are containment actions rehearsed, human-approved, reversible, and protected by explicit stop conditions?

Recovery06

When were backups last restored in a test, and what did that test actually demonstrate?

Suppliers07

Which third parties receive data or access, and how are those dependencies reviewed?

Learning08

Which incidents, exercises, and control failures have produced a documented change?