Evidence record: [control ID]¶
| Field | Value |
|---|---|
| Control ID and text | |
| Status | Pass / Fail / Blocked / Not Applicable |
| Accountable owner | |
| Implementer | |
| Independent reviewer | |
| Release identifier | |
| Source commit/tag | |
| Artifact digest | |
| Configuration and flags | |
| Environment | |
| Evidence collected at | |
| Evidence expires at |
Applicability¶
Explain why this control applies. For Not Applicable, identify the absent trigger and how that was verified.
Evidence¶
Link the test report, command output, screenshot, query, configuration export, code review, architecture decision, contract, drill report, or monitoring view. Do not paste secrets or unnecessary personal data.
Why the evidence is sufficient¶
Explain how the evidence demonstrates the complete control for this release and environment, including important limitations.
Reproduction or verification¶
[safe command, test procedure, or review steps]
Result and follow-up¶
- Result:
- Residual risk:
- Related defects or exceptions:
- Conditions that invalidate this evidence:
- Next review date: