GRC Oversight
Glossary

Evidence

The artifact backing a test result, carrying a timestamp, source system, and content hash.

Evidence is the proof an auditor or reviewer actually looks at: a screenshot, a config export, a signed policy, an API response. Good evidence records when it was collected, where it came from, and (ideally) a hash so it can't be silently altered after the fact.

Looking for another term or the full list?