Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CHECKLIST · ITv1.0 · REVIEWED 2026-07-28

IT Evidence Collection Checklist

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

The artifacts worth retaining for each IT practice, grouped by the four evidence categories the site uses throughout: governance, configuration, operations, and validation.

How to use it

Fill in where each artifact actually lives and who maintains it. An evidence list with no location column is an aspiration; one with locations is a programme. Retain what you would want to show a reviewer who asks how you know a control operates.

The four evidence categories

CategoryWhat it answers
GovernanceWho decided this, what did they decide, and who owns it now?
ConfigurationWhat is actually configured, and does it match the decision?
OperationsDoes it keep working during normal operations, and what happened when it did not?
ValidationHow do you know — what did you test, when, and what was the result?

IT evidence register

PracticeCategoryArtifactWhere yours lives / owner
IT-01GovernanceMFA policy with named owner and scope 
IT-01ConfigurationIdentity-policy export showing enforcement 
IT-01OperationsMonthly enrollment-coverage report 
IT-01ValidationQuarterly sign-in-log and recovery-path review 
IT-02GovernanceInventory policy naming the owner, sources, and cadence 
IT-02ConfigurationInventory export covering hardware, software, cloud apps, and identities 
IT-02OperationsMonthly reconciliation report with investigated discrepancies 
IT-02ValidationQuarterly review sign-off and joiner/leaver reconciliation 
IT-03GovernanceLifecycle/retirement policy and the funded roadmap 
IT-03ConfigurationEvidence legacy protocols are disabled and systems are isolated 
IT-03OperationsRoadmap progress report against retirement dates 
IT-03ValidationConfirmation scan showing no unsupported internet-facing systems 
IT-04GovernanceSecure-configuration standard and change checklist 
IT-04ConfigurationBaseline configuration documents for core systems 
IT-04OperationsRecords of changes tested against the baseline 
IT-04ValidationData-export test result and identity-integration review 
IT-05GovernanceNetwork segmentation design and zone policy 
IT-05ConfigurationFirewall/ACL rule exports enforcing inter-zone controls 
IT-05OperationsLogs of inter-zone traffic and investigated anomalies 
IT-05ValidationSegmentation test results showing blocked cross-zone access 
IT-06GovernanceVulnerability management policy with severity SLAs 
IT-06ConfigurationScanner coverage/configuration showing authenticated scans 
IT-06OperationsRemediation tracking report and exception register 
IT-06ValidationTrend of mean-time-to-remediate against SLA 
IT-07GovernanceSecure development standard and change-review policy 
IT-07ConfigurationPipeline configuration showing SAST/SCA/secret-scanning gates 
IT-07OperationsFindings backlog with owners and closure dates 
IT-07ValidationRecords of blocked builds and merge reviews 
IT-08GovernanceAI acceptable-use and data-classification policy 
IT-08ConfigurationApproved-tool list with data-protection terms; DLP rules for AI 
IT-08OperationsAI usage logs and review of unapproved-tool access 
IT-08ValidationDLP test result and periodic tool/terms review 
IT-09GovernanceBackup and DR policy with RTO/RPO targets 
IT-09ConfigurationBackup job configuration and immutability/offline settings 
IT-09OperationsTest-restore records with dates, durations, and outcomes 
IT-09ValidationScenario recovery-exercise report and gap remediation 
IT-10GovernanceRoles-to-skills plan and training policy 
IT-10ConfigurationTraining records mapped to technical roles 
IT-10OperationsExercise reports and cross-training coverage 
IT-10ValidationSkills/readiness tracker and post-exercise improvement log 

Limitations

IT Evidence Collection Checklist · version 1.0 · reviewed 2026-07-28 · file name batb-it-evidence-collection-checklist

Generated from IT Top 10 at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-it-evidence-collection-checklist to keep filenames consistent across your team.