Worked evidence row
Control EXAMPLE-02 says a webhook event is deduplicated before ledger posting. The owner is the platform team. A useful evidence set has the design rule, a replay test showing one ledger effect, and a dated sample from a running system with customer fields removed. The starter CSV leaves evidence_location blank on purpose. A team must replace that field with its own restricted link and set a review date. A written policy with no required test result must be marked missing.
Make the index useful at review time
The CSV starts with six example controls. Replace example entries with controls your organization actually runs. For each, link a design record, a test result, and a recent run record. Set an owner and review date.
Checks to run
- For each control, name the owner, source requirement, evidence type, review date, and retention location.
- Version the control statement and mark evidence as current, expired, or missing.
- Separate a design document from an execution log and a retest result.
Evidence freshness
Each index row needs a review date and status. A passing test from an old release may no longer reflect the live system. Ask the control owner to refresh evidence after a material code or policy change and keep the old version for traceability.
A control-to-evidence map helps a reviewer find records; it does not replace a security test. The starter CSV uses example entries that must be replaced with the organization’s own controls and records.
Trace a control to a record
For a payout approval control, store four links in one evidence row: the approved policy version, a test case that tries a one-person payout, the live approval log for a sampled payout, and the exception ticket if the check failed. Set an owner and review date. Mark “missing” when the record cannot be found; do not treat a policy file as proof that the server enforced the rule. The CSV is an index, not the evidence itself. Restrict the linked records because they can include customer or staff details. NIST separates control statements from audit records and assessments.
For evidence-index revision 1.1, check the linked field guide before replacing example_only rows; it defines validity dates, review triggers, and missing and failed evidence. field guide and calculation rules.
Use the index status rules consistently
Revision 1.1 uses example_only for the six starter rows. For a real control, use missing when required design, test, or run evidence is absent; failed when a recorded test fails; expired after valid_until or a review trigger; and current only after a reviewer checks all required records for the stated build and scope. A not-applicable decision needs a reason and a scoped control rule. Record review_date as the actual check date, not the file upload time. Trigger a new review after approval logic, provider integration, or account permission changes. Preserve previous versions so a current link cannot erase an earlier gap.
Primary sources
Download example evidence index.
Next step
Replace one example index row with a real control, owner, current test result, and review date. Read the related guide. For a review of your own system, request a security review.