Evidence Storage
Compliance evidence often needs to be stored in specific repositories with defined retention policies (for example, for audits or customer assurances).
Evidence Types
From Compliance Engine you can generate and store:
- Reports and dashboards exported as files.
- CSV extracts of findings for specific controls or time ranges.
- Screenshots or documents that show configuration, approvals, or exceptions.
These artifacts can be stored in:
- Designated evidence repositories (for example, SharePoint, Confluence, dedicated file stores).
- Object storage buckets with strict access controls and retention policies.
Considerations
When designing evidence storage:
- Ensure access controls match your regulatory requirements.
- Define retention and disposal policies for evidence, aligned with your broader records management.
- Maintain traceability between evidence artifacts and the underlying findings in Cloudaware.
Compliance Engine’s structured findings and timestamps make it easier to generate evidence on demand and to reconstruct the context around each artifact.