Skip to main content

Evidence Collection

Automated Evidence

EvidenceSourceFrequency
Security scansGitHub Actions logsPer commit
Access logsCloudWatch/CloudTrailContinuous
ConfigurationTerraform stateOn change

Manual Evidence

EvidenceOwnerFrequency
Access reviewsSecurityQuarterly
Policy reviewsSecurityAnnual
Penetration testExternalAnnual

Storage

Evidence stored in secure S3 bucket with versioning enabled.