Add evidence to a requirement
How to upload a supporting file directly to a requirement in the ISMS cockpit and give it a designation and a validity date. This documents the implementation of the requirement in an audit-proof way for ISO 27001 or BSI IT baseline protection.
In the detail view of a requirement, the “Evidence” section is where you store the supporting file that proves the requirement has been implemented — for example a policy, a log or a screenshot of a configuration. The evidence stays attached to the requirement permanently and is therefore available for every internal review or certification audit under ISO 27001 or BSI IT baseline protection.
Prerequisites
- At least one list of requirements has been loaded.
- You have permission to edit requirements.
- The supporting file is available to you locally. If it is not, request it from the responsible person instead (see below).
Open the detail view of the requirement
- Open the “ISMS cockpit” or the detail view of the list of requirements.
- Click the requirement you want to add the evidence to. The detail view opens with the tabs “Contents”, “Activities”, “Files”, “Tasks” and “Comments”.
- In the “Contents” tab, scroll to the “Evidence” section.
Add evidence
- Click “New” in the “Evidence” section.
- Enter a “Designation”. Choose a meaningful one such as
Password policy v2.1so the file can be identified later without opening it. - Under “Evidence”, upload the supporting file.
- Optionally set a “Valid until” date until which the evidence is valid.
- Click “Save”.
The evidence then appears in the list in the “Evidence” section. The process is logged in the activity history of the requirement and can be traced in the “Activities” tab.
How this differs from requesting evidence
Use “New” to upload a file you already have. If the proof is held by someone else — in IT or at a service provider, for example — use the “Request” button in the same section instead. The requested person then receives a link that allows them to upload the evidence without their own user account.
Practical tips
- Maintain “Valid until” wherever the proof has an expiry date — certificates, penetration test reports or annual training records, for instance. That way the cockpit shows you early which evidence has to be renewed before the next audit.
- Evidence documents the supporting files themselves. For documents already maintained in preeco — sets of rules, measures or systems — use the “Links” section instead, so the proof does not have to be maintained twice.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.