Evidence for the examiner who asks “show me” rather than “tell me.”
Control documentation describes the program you designed. An examiner increasingly wants the program you run. CINQUE produces observed behavior per persona, with the source of every assertion attached.
The gap between the control narrative and the environment.
Most evidence packages are assembled from exports, screenshots, and attestations gathered the month before the examination. They describe a point in time that was prepared for. What they cannot show is whether the control behaved that way for the other eleven months.
Attestation is not observation
A signed access review proves that somebody signed. It does not prove the access was appropriate.
Evidence is assembled, not produced
If the package takes six weeks of manual collection, it is a project, not a control.
Scope is asserted
Defining which systems are in scope from an asset inventory rather than from observed access is a guess with a signature on it.
Findings without provenance
An examiner's first question about any number is where it came from. A finding that cannot answer that is a finding you will defend twice.
What CINQUE produces for the file.
Framework mapping, by industry.
Framework mappings are carried in full in the industry datasheets, each of which maps CINQUE outputs to the specific control families that framework examines.
What CINQUE does not do.
Stated plainly, so nobody is surprised in month two.
- CINQUE is not a GRC platform. It does not manage policies, track remediation tasks, or produce a certification.
- CINQUE does not assert compliance with any framework. It produces observed evidence; your auditors and your second line draw the conclusions.
Same platform, different question.
All use cases · What is Unified Security Posture Observability?