Machine-Readable Evidence

Machine-Readable Evidence A data-flow diagram generated by Archify. 01 / Sources 02 / OSCAL (Layer 05) 03 / Validator 04 / Consumers Control catalogue · controls · 01 / Sources Control catalogue controls Assessment results · eval runs · 01 / Sources Assessment results eval runs Evidence records · verdicts · 01 / Sources Evidence records verdicts OSCAL documents · component / assessment · 02 / OSCAL (Layer 05) · Layer 05 OSCAL documents component / assessment Layer 05 Validator · schema-checked · 03 / Validator Validator schema-checked Auditor · reads directly · 04 / Consumers Auditor reads directly Compliance tooling · continuous · 04 / Consumers Compliance tooling continuous Regulator · submission · 04 / Consumers Regulator submission map map map check read read submit Legend primary data data store data flow

Evidence as data, not screenshots

  • • Control catalogue, assessment results and evidence records become OSCAL
  • • Component-definition and assessment-results carry the traceability to controls
  • • Emitted from the same data you already hold, so nothing is re-typed

Validated, then read

  • • A validator checks the documents against the schema at one gate
  • • Auditor, compliance tooling and regulator read the same documents
  • • The audit becomes a query and evidence composes across tools

First step

  • • Choose the format your assessor can ingest
  • • Generate it from the data you already hold