IT Evidence Collection Checklist
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
The artifacts worth retaining for each IT practice, grouped by the four evidence categories the site uses throughout: governance, configuration, operations, and validation.
How to use it
Fill in where each artifact actually lives and who maintains it. An evidence list with no location column is an aspiration; one with locations is a programme. Retain what you would want to show a reviewer who asks how you know a control operates.
The four evidence categories
| Category | What it answers |
|---|---|
| Governance | Who decided this, what did they decide, and who owns it now? |
| Configuration | What is actually configured, and does it match the decision? |
| Operations | Does it keep working during normal operations, and what happened when it did not? |
| Validation | How do you know — what did you test, when, and what was the result? |
IT evidence register
| Practice | Category | Artifact | Where yours lives / owner |
|---|---|---|---|
| IT-01 | Governance | MFA policy with named owner and scope | |
| IT-01 | Configuration | Identity-policy export showing enforcement | |
| IT-01 | Operations | Monthly enrollment-coverage report | |
| IT-01 | Validation | Quarterly sign-in-log and recovery-path review | |
| IT-02 | Governance | Inventory policy naming the owner, sources, and cadence | |
| IT-02 | Configuration | Inventory export covering hardware, software, cloud apps, and identities | |
| IT-02 | Operations | Monthly reconciliation report with investigated discrepancies | |
| IT-02 | Validation | Quarterly review sign-off and joiner/leaver reconciliation | |
| IT-03 | Governance | Lifecycle/retirement policy and the funded roadmap | |
| IT-03 | Configuration | Evidence legacy protocols are disabled and systems are isolated | |
| IT-03 | Operations | Roadmap progress report against retirement dates | |
| IT-03 | Validation | Confirmation scan showing no unsupported internet-facing systems | |
| IT-04 | Governance | Secure-configuration standard and change checklist | |
| IT-04 | Configuration | Baseline configuration documents for core systems | |
| IT-04 | Operations | Records of changes tested against the baseline | |
| IT-04 | Validation | Data-export test result and identity-integration review | |
| IT-05 | Governance | Network segmentation design and zone policy | |
| IT-05 | Configuration | Firewall/ACL rule exports enforcing inter-zone controls | |
| IT-05 | Operations | Logs of inter-zone traffic and investigated anomalies | |
| IT-05 | Validation | Segmentation test results showing blocked cross-zone access | |
| IT-06 | Governance | Vulnerability management policy with severity SLAs | |
| IT-06 | Configuration | Scanner coverage/configuration showing authenticated scans | |
| IT-06 | Operations | Remediation tracking report and exception register | |
| IT-06 | Validation | Trend of mean-time-to-remediate against SLA | |
| IT-07 | Governance | Secure development standard and change-review policy | |
| IT-07 | Configuration | Pipeline configuration showing SAST/SCA/secret-scanning gates | |
| IT-07 | Operations | Findings backlog with owners and closure dates | |
| IT-07 | Validation | Records of blocked builds and merge reviews | |
| IT-08 | Governance | AI acceptable-use and data-classification policy | |
| IT-08 | Configuration | Approved-tool list with data-protection terms; DLP rules for AI | |
| IT-08 | Operations | AI usage logs and review of unapproved-tool access | |
| IT-08 | Validation | DLP test result and periodic tool/terms review | |
| IT-09 | Governance | Backup and DR policy with RTO/RPO targets | |
| IT-09 | Configuration | Backup job configuration and immutability/offline settings | |
| IT-09 | Operations | Test-restore records with dates, durations, and outcomes | |
| IT-09 | Validation | Scenario recovery-exercise report and gap remediation | |
| IT-10 | Governance | Roles-to-skills plan and training policy | |
| IT-10 | Configuration | Training records mapped to technical roles | |
| IT-10 | Operations | Exercise reports and cross-training coverage | |
| IT-10 | Validation | Skills/readiness tracker and post-exercise improvement log |
Limitations
Retaining these artifacts supports your own assurance and gives an assessor something concrete to review. It does not constitute an assessment, satisfy a contractual requirement, or establish a System Security Plan. What evidence is sufficient is a decision for your assessor and your contract, not for this checklist.
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-it-evidence-collection-checklist to keep filenames consistent across your team.