Many companies work hard on security and still struggle in an audit or assessment. The reason is rarely that they did nothing. It is that they cannot prove what they did. Whether the review involves CMMC, a utility's obligations under NERC CIP, pipeline security requirements, or a customer's questionnaire, the reviewer's job is to verify claims with evidence.
Understanding what counts as evidence, and collecting it as you go, saves enormous effort later.
Three kinds of evidence
Assessors generally rely on three methods, and it helps to prepare for each.
- Examine. They look at documents, configurations, records, and logs.
- Interview. They ask people how things are done.
- Test. They observe a control in action or try it.
Your evidence should line up across all three. If a policy says one thing, a configuration shows another, and staff describe a third, the result is a finding.
Documents that matter
Keep current, approved versions of these.
- Policies that state what the organization requires
- Procedures that show how tasks are performed
- System descriptions and network diagrams showing boundaries and data flows
- Asset inventories of hardware, software, and where sensitive data lives
- Risk assessments and records of decisions made about them
- Incident response plans and records of tests
- Training records showing who was trained, when, and on what
Policies without procedures are weak. Procedures nobody follows are worse. Write what you actually do, then do what you wrote.
Records that prove the control operates
Beyond documents, assessors want records created by the control itself.
- Access review records, showing who reviewed accounts and what was removed
- Screenshots or exports of configuration settings, with dates
- Patch and vulnerability scan reports
- Backup logs and restore test results
- Logs showing authentication events and administrative actions
- Change records with approvals
- Visitor and badge logs for physical protections
- Vendor and third-party access records
Dated, repeatable records are the strongest. A single screenshot from last week is weaker than a series showing the control working for months.
Build an evidence library
Do not wait until an assessment is announced.
Organize by control or requirement
Create a structure that maps each requirement to its evidence. A simple folder tree or a spreadsheet listing the requirement, the evidence, the location, the owner, and the last updated date is enough.
Assign owners
Each piece of evidence should have a person responsible for keeping it current. Owners should know how often it needs refreshing.
Schedule collection
Set a recurring calendar for quarterly or monthly evidence capture. For example, a first-of-the-month task to export the user list, a quarterly access review, and an annual incident response exercise.
Protect the library
Evidence can contain sensitive configuration details. Limit access, keep backups, and avoid scattering copies in email.
Prepare your people
Interviews can be nerve-racking. Prepare staff by:
- Explaining the purpose of the review and what to expect
- Asking them to answer honestly and specifically, based on what they do
- Telling them it is fine to say they do not know and will find out
- Making sure the person described in a procedure actually performs it
Be honest about gaps
Assessors generally respond better to a company that knows its weaknesses than to one that hides them. A documented gap with an owner and a schedule for fixing it shows maturity. Where a program allows a formal plan of action for limited gaps, use it correctly and do not overstate completion.
A hypothetical example
Consider a hypothetical regional pipeline services firm preparing for a customer security review. It could assemble a one-page index listing each requirement area, the policy that covers it, the system that enforces it, and the most recent evidence with a date. When the reviewer asks about access removal for departed employees, the firm can produce the policy, the offboarding checklist, and the last three quarterly access reviews in minutes.
Common mistakes
- Creating documents the week before the audit
- Using templates without tailoring them
- Relying on one person's memory
- Leaving evidence undated
- Ignoring third parties who hold your data
Where Ironfield Cyber helps
Ironfield Cyber helps contractors and energy companies build compliance programs that produce evidence as a normal byproduct of good operations. If you are preparing for a customer review or assessment, we can help you organize what you have and identify what to collect.