Illustrative sample

Website Evidence Pack

A review-ready index for operational website records. Actual packs contain customer-specific evidence and clearly identify items that were not observed, tested, or applicable.

Illustrative sample: This page shows the structure of an Evidence Pack. It is not a customer record, audit report, certification, or evidence that any event, test, or control occurred.

1. Pack identity and scope

  • Customer and covered site(s)
  • Reporting period and pack version
  • Prepared by, prepared date, and scope exclusions
  • Related order confirmation and operating contacts

2. Controls summary

  • Control area and customer-specific description
  • Responsible party: State Street, customer, or third party
  • Evidence reference and review date
  • Status vocabulary defined for the pack
  • Exceptions, limitations, and follow-up owner

3. Vendor register

  • Provider, service supplied, and relationship owner
  • Data or access involved
  • Contract or terms reference and review date
  • Known dependency, transfer, and exit notes

4. Update and change log

  • Date, system or component, and change category
  • Requester, implementer, and approval reference where used
  • Validation performed and result
  • Rollback or follow-up reference where applicable

5. Backup and restore evidence

  • Customer-specific backup responsibility and configuration
  • Evidence source and observation date
  • Restore exercise date, scope, and result when one occurred
  • Exceptions and corrective action without invented RPO/RTO claims

6. Incident record

  • Incident identifier, reported time, and reporting source
  • Affected site or service and observed impact
  • Actions, communications, resolution, and follow-up
  • “No incidents recorded in this period” only when supported by the customer record

7. Quarterly posture summary

  • Period reviewed and evidence sources consulted
  • Material changes, open exceptions, and dependency changes
  • Upcoming actions with owner and target review date
  • Items requiring customer or CCO decision

8. Customer and CCO review

  • Customer reviewer / title / date
  • CCO or compliance reviewer / title / date, if applicable
  • Questions, requested corrections, and acceptance notes
  • Acknowledgment that review is not regulatory approval

Evidence handling rule

A field is marked not observed, not tested, not applicable, or pending when the underlying record is unavailable. Empty space is never converted into a passing claim.

See the Trust & Evidence Center for the compliance boundary, ownership, dependencies, and exit process.

← All resources