Evidence

Evidence

Where proof lives: the evidence vault for artifacts and policies for governing documents.

Evidence is what an auditor reads to believe a control operates. In Noru it comes in two shapes: artifacts in the evidence vault, uploaded by you or synced from data sources, and policies, the governing documents you write, version, and approve. Both link to controls, and both count toward coverage.

Two kinds of proof

A policy says what should happen; an evidence item shows that it did. A control that requires a policy is satisfied by an approved policy linked to it; a control that requires a configuration screenshot, a log export, or a synced setting is satisfied by a valid evidence item in the right slot.

Last updated on

On this page