For the engagement owner. A useful request explains why a record is needed, who owns it and what period it must cover.
Begin with the criterion
An evidence request should be traceable to an assessment objective. “Send all security documents” creates volume without explaining the conclusion the assessor needs to support. A better request names the control, the required record, the relevant population and the period. For an access-lifecycle review, ask for the approved disablement target, the leaver population and the relevant directory status history. These records answer a defined question. They also make it easier for an evidence owner to identify limitations before fieldwork begins.
Read diagram text
- Criterion
- Name the control expectation.
- Record
- Specify the source and period.
- Owner
- Assign one accountable respondent.
Separate populations from samples
Obtain the population before choosing records to inspect. A list hand-picked by the control owner may omit unusual cases and cannot automatically be treated as representative. Record how the population was produced, its date boundaries and any exclusions. Then document the sample selection rationale: criticality, system variation, time coverage or specific risk. A judgemental sample can be useful, but its limitations should be stated. Do not turn a percentage of sampled exceptions into an estate-wide estimate without an appropriate statistical design.

Make each request operational
Use a compact register with a request identifier, purpose, requested period, owner, due date and status. Add handling requirements where records contain personal information or sensitive configuration. Ask for stable pseudonymous identifiers when names are unnecessary. Keep the source and collection date with each export. Screenshots can explain a setting, but they often omit the surrounding scope, timestamps or query conditions. Where practical, pair them with structured exports and a short explanation of how the record was generated.
Read diagram text
- Population
- Complete records within the boundary.
- Selection
- Document the risk-based method.
- Exception
- Track condition and corroboration.
Handle missing evidence honestly
Missing evidence is a fact to assess, not an invitation to reconstruct history. A control owner may be able to provide a different corroborating source or explain a retention limit. Record that explanation and evaluate what it actually supports. A newly created procedure may show improved design today; it does not prove the process operated last quarter. Separate confirmed exceptions, evidence limitations and controls that were not assessed. This helps management choose between remediation, better record keeping and additional assessment.
Read diagram text
- Source
- Record system and collection date.
- Context
- Keep query, scope and limitations.
- Integrity
- Preserve approved evidence references.
Control the transfer and the follow-up
Agree the secure channel, authorised recipients, access expiry and retention before collecting detailed material. Do not put credentials, production secrets or unnecessary personal records into initial web forms. Track superseded evidence so reviewers can reproduce the conclusion. After factual review, preserve the approved evidence references and record subsequent changes separately. This avoids quietly replacing a record that supported the original finding. Related guidance from the same Atlant Security portfolio: verifying remediation evidence and measuring security service delivery. Use these when an audit recommendation needs a separately scoped technical test or a clearly owned operational improvement.
Prepare a useful first conversation
Use the audit scoping brief builder to record your objectives, control areas, platforms and evidence period. Review its draft before sending it to Atlant Security through the contact form. You can attach an NDA or RFP for human review. Begin with non-sensitive context and approximate counts; confidential control evidence belongs in an agreed secure channel. The brief does not authorise system access, accept an NDA or establish an assurance opinion.
Read diagram text
- Alternative
- Can another source corroborate it?
- Limitation
- What conclusion is no longer supported?
- Action
- Improve records or extend assessment.
Primary sources
- Atlant Security IT security audit
- NIST Cybersecurity Framework
- NIST SP 800-53A assessment methodology
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.
Published by Atlant Security. Sources, editorial policy and corrections.

