Assessment methodology

A screenshot is not an assessment conclusion

Strong assessments separate three things that are often mixed together: the organization's claim, the evidence supporting that claim, and the reviewer's judgment. Keeping those layers distinct makes findings explainable and keeps the record useful when the environment changes.

Six dimensions of useful evidence

Provenance

Who or what produced the artifact? Prefer system-generated records or clearly attributable documents over unattributed screenshots.

Scope

Which system, process, location, business unit, population, or control claim does the artifact actually cover?

Freshness

Does the collection date and evidence period match the assessment period, or could the environment have materially changed?

Integrity

Can reviewers tell whether the artifact is complete, versioned, altered, superseded, or missing relevant context?

Design evidence

Does it demonstrate that a policy, configuration, or process is designed to achieve the claimed security outcome?

Operating evidence

Does it demonstrate the process or control actually operated during the period under review, rather than merely existing on paper?

The minimum evidence record

For every material artifact, preserve enough metadata that a reviewer can understand it later without asking the original uploader to reconstruct the story.

Artifact title and type
Source system or owner
Collection date and period covered
Systems/processes/population in scope
Assessment claim(s) supported
Reviewer and review date
Evidence status and limitations
Version, integrity, or supersession notes

Reviewer confidence should be explicit

A binary “evidence attached” field hides uncertainty. A reviewer should be able to state how much confidence the evidence provides and why.

High confidence

Independent or system-generated evidence is current, scoped correctly, internally consistent, and demonstrates both design and operation where relevant.

Moderate confidence

Evidence supports the claim but has a material limitation: narrow sample, aging artifact, incomplete operating history, or dependence on manual records.

Low confidence

Evidence is indirect, stale, contradictory, incomplete, self-attested without corroboration, or does not cover the claimed scope.

Unknown

No usable evidence has been reviewed yet, or the reviewer cannot determine whether the claim is supported.

Examples: weak artifact vs defensible record

ClaimWeak evidenceStronger evidence record
MFA is enforced for privileged usersOne screenshot from an admin portalCurrent configuration export + privileged-account population + exception list + recent sign-in evidence + reviewer note on coverage
Backups can be restoredScreenshot showing backup jobs are greenBackup configuration + retention + recent successful jobs + documented restore test + test result + corrective actions from failures
Access is reviewed periodicallyPolicy requiring quarterly reviewsPolicy + review population + completed review records + removals/changes + reviewer sample showing the process operated
Incidents are handled consistentlyIncident-response plan PDFApproved plan + recent incident/tables-top exercise records + timestamps + decisions + lessons learned + tracked remediation

Evidence reuse is good. Conclusion reuse is dangerous.

One artifact may support NIST, ISO readiness, and HIPAA assessment work. Keep a reusable evidence object, then map it to separate claims and reviewer decisions. That prevents three copies of the same screenshot while preserving framework-specific applicability and semantics.

How this fits Pulse, Compass, and Assurance

Pulse

Use evidence selectively to reduce uncertainty around the few capabilities that will materially change executive priorities.

Compass

Increase evidence depth, expose insufficiency, assign remediation, and prepare the organization for structured review.

Assurance

Require reviewer judgment, preserve evidence limitations, verify operating effectiveness where appropriate, and keep formal decisions auditable.