Resources / 07

A framework for assembling architecture, implementation, runtime, control, incident, and governance material without creating an unstructured document dump.

Independent software assuranceSM / 07.47

SecondMark position

Evidence should be requested in relation to claims and boundaries. Relevance, provenance, reproducibility, and contradiction matter more than volume.

The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.

01

Core questions

What the examination needs to establish.

  1. 01

    Which claim does each item support?

  2. 02

    Who or what produced the evidence?

  3. 03

    Can it be reproduced for the scoped system?

  4. 04

    What material evidence is unavailable?

02

Evidence model

Evidence is assembled around the claim—not the folder structure.

01

System and ownership records

Collected, attributed, challenged, and connected to the exact system boundary under examination.

02

Architecture, control, and runtime material

Collected, attributed, challenged, and connected to the exact system boundary under examination.

03

Known incidents and limitations

Collected, attributed, challenged, and connected to the exact system boundary under examination.

04

Decision context and required claims

Collected, attributed, challenged, and connected to the exact system boundary under examination.

Intended outcome

A more efficient evidence room organized around assurance reasoning rather than file categories alone.

Clearer engagement preparationReduced evidence ambiguityFaster scope formation
03

Professional boundary

What an opinion does—and does not—mean.

It provides

A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.

It does not provide

A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.