Documents & Evidence
Collect once. Cite it from every record that needs it.
A document is a typed, versioned, classified record linked to controls, assessments, questionnaires, findings, policies and vendors. There is no second copy to reconcile, and removal is governed by retention policy and legal hold.
- Document types, versions and a classification scheme you can replace
- Checksum-verified storage; every citation is a link, not a copy
- Retention policies by object type; legal holds block removal
- Evidence packages bundle everything in scope into one download
In the application · Govern
- Documents
- Document types
- Retention policies
- Legal holds
- Evidence packages
PAM-quarterly-access-review.pdf
Cited by
- Control A.9.2.3 · Privileged accessEvidence
- ISO/IEC 27001 assessment · Q3Response attachment
- Vendor questionnaire · Calder TelecomSupporting document
- Finding F-0142 · PAM coverageRemediation proof
Collected once. Legal holds block removal; an evidence package bundles everything in scope.
Reuse
One file, many citations
Attach evidence once and cite it from every control, assessment and questionnaire that needs it. A link records its role — evidence, response attachment, supporting document — so a reviewer sees why the file is there.
- Links carry a role and a review state
- Public, internal, confidential and restricted classification by default; your own scheme if you prefer
- Versioned: the assessment that cited v2 still shows v2
- Full-text search across documents and their metadata
PAM-quarterly-access-review.pdf
Cited by
- Control A.9.2.3 · Privileged accessEvidence
- ISO/IEC 27001 assessment · Q3Response attachment
- Vendor questionnaire · Calder TelecomSupporting document
- Finding F-0142 · PAM coverageRemediation proof
Collected once. Legal holds block removal; an evidence package bundles everything in scope.
Integrity and retention
Kept as long as the policy says, and no longer
Retention policies decide when a document class is removed; legal holds override them. Erasure requests under data-protection law are handled on the record with the same audit trail as any other change.
- Retention policy per object type with a recorded action
- Legal holds with reason, owner and release
- Checksums verified on storage and on download
- Generated reports stored with the evidence they cite
Treatment decision
- 1Treatment planActions with owners, priority, and due dates
- 2Action trackingStatus per action, SLA where defined
- 3ReassessmentResidual score recalculated after closure
Framework alignment
Works with your control frameworks
This module shares the platform control library. International standards, sector regulations and your own internal standard are loaded the same way and mapped to one another, wherever you operate.
See documents and evidence in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.