Strong assurance evidence has a known source and owner, clear scope and time period, preserved integrity or provenance, sufficient completeness for the decision, relevance to the control or risk claim, freshness appropriate to the subject, and a review trail that records limitations and contradictory evidence. Quantity of attachments is not evidence quality.
Evidence and decision record
Provenance
Record where the evidence came from, who generated or collected it and whether the source is authoritative for the claim.
Scope and period
State which systems, populations, services and time periods the evidence represents.
Integrity and preservation
Retain enough metadata, versioning, custody or source-system reference to support trust in the artefact.
Completeness and relevance
Assess whether the evidence supports the actual question rather than a nearby or narrower claim.
Freshness
Match review frequency to the rate at which the underlying control, asset, process or risk can change.
Review and contradiction
Record reviewer judgement, exceptions, contradictory observations and limitations instead of retaining only favourable evidence.
Operating sequence
Common failure modes
Where Cybatar fits
Claim boundary
Evidence quality is contextual. Cybatar can preserve provenance, review and relationships but cannot guarantee that evidence is complete, authentic, legally sufficient or adequate for a regulator, auditor or assurance provider.
Cybatar publishes cyber-risk and assurance guidance as a first-party operating model. It is not a legal opinion, audit opinion, certification, regulator determination, universal risk score, or proof that a specific control is effective.