Assessment methodology
A screenshot is not an assessment conclusion
Strong assessments separate three things that are often mixed together: the organization's claim, the evidence supporting that claim, and the reviewer's judgment. Keeping those layers distinct makes findings explainable and keeps the record useful when the environment changes.
Six dimensions of useful evidence
Provenance
Who or what produced the artifact? Prefer system-generated records or clearly attributable documents over unattributed screenshots.
Scope
Which system, process, location, business unit, population, or control claim does the artifact actually cover?
Freshness
Does the collection date and evidence period match the assessment period, or could the environment have materially changed?
Integrity
Can reviewers tell whether the artifact is complete, versioned, altered, superseded, or missing relevant context?
Design evidence
Does it demonstrate that a policy, configuration, or process is designed to achieve the claimed security outcome?
Operating evidence
Does it demonstrate the process or control actually operated during the period under review, rather than merely existing on paper?
The minimum evidence record
For every material artifact, preserve enough metadata that a reviewer can understand it later without asking the original uploader to reconstruct the story.
Reviewer confidence should be explicit
A binary “evidence attached” field hides uncertainty. A reviewer should be able to state how much confidence the evidence provides and why.
High confidence
Independent or system-generated evidence is current, scoped correctly, internally consistent, and demonstrates both design and operation where relevant.
Moderate confidence
Evidence supports the claim but has a material limitation: narrow sample, aging artifact, incomplete operating history, or dependence on manual records.
Low confidence
Evidence is indirect, stale, contradictory, incomplete, self-attested without corroboration, or does not cover the claimed scope.
Unknown
No usable evidence has been reviewed yet, or the reviewer cannot determine whether the claim is supported.
Examples: weak artifact vs defensible record
| Claim | Weak evidence | Stronger evidence record |
|---|---|---|
| MFA is enforced for privileged users | One screenshot from an admin portal | Current configuration export + privileged-account population + exception list + recent sign-in evidence + reviewer note on coverage |
| Backups can be restored | Screenshot showing backup jobs are green | Backup configuration + retention + recent successful jobs + documented restore test + test result + corrective actions from failures |
| Access is reviewed periodically | Policy requiring quarterly reviews | Policy + review population + completed review records + removals/changes + reviewer sample showing the process operated |
| Incidents are handled consistently | Incident-response plan PDF | Approved plan + recent incident/tables-top exercise records + timestamps + decisions + lessons learned + tracked remediation |
Evidence reuse is good. Conclusion reuse is dangerous.
One artifact may support NIST, ISO readiness, and HIPAA assessment work. Keep a reusable evidence object, then map it to separate claims and reviewer decisions. That prevents three copies of the same screenshot while preserving framework-specific applicability and semantics.
How this fits Pulse, Compass, and Assurance
Pulse
Use evidence selectively to reduce uncertainty around the few capabilities that will materially change executive priorities.
Compass
Increase evidence depth, expose insufficiency, assign remediation, and prepare the organization for structured review.
Assurance
Require reviewer judgment, preserve evidence limitations, verify operating effectiveness where appropriate, and keep formal decisions auditable.