Valeo · security governance / January 2026
Evidence expires too: treating freshness as part of the evidence model
A screenshot or export from last year can be factually correct and still fail to demonstrate current operation. Evidence existence and evidence freshness had to become separate states.
Situation
Several items carried the assumption that once evidence had been collected, the work was permanently complete. Dynamic systems do not work that way: permissions, patch levels, device inventories and configurations change. An old export often proves only that a process worked at one point in the past, not that it still works now.
Approach
I added evidence creation time and expected refresh cadence to the register. The interval was not identical for every evidence type: a policy changes at a different pace from a vulnerability report or access list. Where evidence generation could be automated, I preferred that path over manually created screenshots.
Outcome
Statuses became more expressive: missing evidence, present and current evidence, and present but stale evidence needing regeneration were no longer collapsed into the same state. That prevented a large set of supposedly green items from becoming a last-minute surprise just before the audit.