Evidence Capture Log¶
Purpose. The running chain of custody for every artefact filed in the evidence store: what it proves, who captured it, when, how, and its SHA-256 so integrity can be re-verified at any time. Written automatically by
tools/evidence.py— do not edit rows by hand; the hash is the point.Artefacts live in
s3://soon-isms-evidence(account 404379474355, Object Lock 3 years). This log is the index. Together with CloudTrail data events they answer "who did what, when" without any database — see Evidence Collection & Management §4.7.
| Captured (UTC) | Control | SOC 2 | Description | Method | Captured by | SHA-256 | S3 key |
|---|---|---|---|---|---|---|---|