Security in depth · Unit 30 · Lesson 5 of 11
Evidence needs enough context to review
Turn an isolated screenshot into a record another reviewer can interpret.
Helpful before thisReporting: turn evidence into useful improvements
After this lesson you can
- Identify the minimum contextual fields needed to assess a supplied permission decision.
More evidence is not always more explanatory evidence.
Preserve the conditions that matter
Evidence context records the conditions and provenance needed to understand an observation. A reviewer needs to distinguish the expected behavior from the result, and know which release, environment, identity role, and time the observation concerns. An image alone often omits those facts.
Assume a fictional archive is reviewing whether a Viewer can change catalog descriptions. The task is to assess supplied records, not perform an access attempt. A report copy should minimize unrelated personal information while preserving a controlled reference to the original evidence.
Supplied evidence packet
- E1: A screenshot says “change saved,” but includes no visible environment or role. It also contains unrelated member names.
- E2: The assessor’s accompanying record identifies staging release 4.2, Viewer role, and observation time 14:05 UTC on the recorded exercise date.
- E3: The approved policy permits Viewer reading only. A protected before-and-after record confirms the changed description persisted under E2’s conditions and identifies the evidence custodian.
Build an interpretable card
Combine E1 with E2 and E3: expected read-only behavior, observed saved change, and the stated conditions. A redacted report copy can replace unrelated names with stable labels and point to the protected original. Keep the original separately governed; do not claim that an edited screenshot is unchanged evidence.
The card supports review of this observation, not all roles or releases. It also does not independently establish the technical cause of the policy mismatch. If the record is inconsistent, preserve the conflict and request clarification instead of filling gaps from memory.
Model card: Staging 4.2; Viewer; read-only policy; saved change observed; dated source reference; other environments and cause unverified.
Terms you met
Check yourself
No timer. No penalties. Read the explanation and try again whenever you like.
This lesson’s questions have changed. Your reading progress is saved; review the updated questions.
-
Which revision makes the evidence most useful?
Show the answer
Correct answer: Add the release, staging environment, role, expected policy, timestamp, and protected source reference. These fields make the observation interpretable and traceable while supporting a limited report copy that excludes unnecessary personal data.
Try it
- WriteDraft a compact evidence card from E1-E3 with release, environment, role, expected policy, observation, time, and limitation. Replace personal names with stable fictional labels, retaining the separate protected original reference.