Evidence Catalogue
Evidence types required to demonstrate control implementation and compliance.
Evidence-Based Compliance
ECGF controls require specific evidence types to demonstrate implementation. This catalogue shows the 288 evidence items mapped across all controls.
Evidence Categories
Procedures
113 itemsOperational procedures and work instructions
Policies
51 itemsSecurity policies, standards, and governance documents
Reports
28 itemsManagement reports, metrics, and KPIs
Configurations
26 itemsSystem and application configuration files
Logs
23 itemsSystem logs, access logs, and audit trails
Audits
16 itemsAudit reports and assessment findings
Registers
16 itemsAsset registers, risk registers, and inventories
Agreements
6 itemsContracts, SLAs, and third-party agreements
Training
5 itemsTraining records and awareness materials
Plans
4 itemsIncident response, business continuity, and project plans
About Evidence Types
Each ECGF control specifies the evidence types needed to demonstrate implementation. Evidence requirements vary by control complexity and risk level.
Organizations can provide alternative evidence types with proper justification, as long as they demonstrate effective control implementation.
View detailed evidence requirements for each control in the GitHub repository.