How to setup Evidence for Compliance Framework Controls
Last updated: May 22, 2025
To complete compliance checks without integration, you must provide evidence for each of the following items:
Risk assessment: Review and approve the risk register at risk register.
Requesting and approving access: Provide a screenshot of your access request and approval process (e.g., Slack channel or ticketing system).
SSL/TLS: Perform a test on SSL Labs and upload the results.
Disaster recovery testing: Complete the provided simulation exercise (duration: 30-60 minutes).
Security event logging: Provide a screenshot of your security logging tool.
Source control: Provide a screenshot of your version control tool (e.g., GitHub).
Security event review: Provide a screenshot of your security event review system (e.g., post-mortem on Notion).
Cyber insurance: Provide proof of your cyber insurance or explain the reason for not having it.
Incident tracking: Provide a screenshot of your incident tracking tool.
Separation of environments: Provide evidence of separation between development and production environments.
Agile process: Provide evidence of recurring meetings (e.g., calendar invites).
Role-based access control (RBAC): Provide documentation showcasing RBAC setup.
Restricted production access: Provide screenshots showing the process for requesting production access.
Penetration testing: Provide penetration test results.
Employee performance reviews: Provide an anonymized template or example.
Change Management Approvals : Screenshot of your code versioning tool.
Architecture diagram: Provide a screenshot of your architecture diagram.
Board oversight: Provide meeting records of board meetings or meetings with founders.
Published job descriptions: Provide a screenshot or URL of your job postings.
Infrastructure as code: Provide an example of Terraform configurations or CI setup.
Least-privilege access : Provide documentation showcasing RBAC setup.
Master Services Agreement: Include the relevant section of a client contract.
Change Management Tooling : Screenshot of your code versioning tool.
System description: Use the template provided by Bastion to describe your system.
Password management tool: Provide proof of using a password management tool.
Public privacy policy : URL of your public privacy policy.
Terms of Use : URL of your Terms of Use or Terms & Conditions.