Terminology Index

Glossary

1801 terms

Open concept maps

Showing 609-640 of 1801 terms

E
32

Evidence Practices

The end-to-end practices for handling compliance evidence in a security program, how it is collected, organized, validated, and presented, applied as part of building and running a coherent program in the capstone context.

In building a full security program, evidence practices tie together how the organization produces and manages proof that its controls work: defining what evidence each control needs, how it is collected and stored, who validates it, and how it is presented to auditors. As a capstone-level concern, it integrates evidence handling with control mapping, the evidence repository, and audit readiness into a working whole rather than an isolated task.

Introduced in: GRC Capstone: Building a Security Program

Examples

  • Defining what evidence each mapped control requires and how to collect it.
  • Establishing validation so evidence is accurate before an audit.
  • Integrating evidence handling into the overall security program.

No related terms linked yet.