What Is The ERL?
The Evidence Request List (ERL) is the Secure Controls Framework (SCF) finite list of the supporting evidence an organization is expected to produce for each applicable SCF control. It is provided to the organization before an assessment starts.
The ERL standardizes evidence requests for SCF-based assessments. Because it is shared up front, the organization has time to gather its evidence. Its artifacts represent "what a reasonable organization should be able to produce as proof that controls are implemented correctly, operating as intended, and producing the desired outcome."
Included As A Tab In The SCF Download
The ERL is one of the tabs in the free SCF workbook, so no separate download is required. Each ERL item lists the SCF controls it supports, and the workbook's main tab lists the ERL items for each control.
Who Is The ERL For?
The ERL is written for both sides of an assessment, and it is not limited to SCF assessments.
CISOs & Security Teams
Security teams see which evidence artifacts will be expected and stage documentation, configurations and reports before the assessor arrives.
GRC Practitioners
Governance, Risk & Compliance (GRC) practitioners use the ERL as the reference for what "reasonable" evidence looks like for SCF controls. Collecting it between assessments makes evidence gathering a continuous practice rather than a last-minute scramble.
External Assessors & 3PAOs
Under the Cybersecurity & Data Protection Assessment Standards (CDPAS), the assessor must provide an ERL. The SCF provides one that assessors and Third-Party Assessment Organizations (3PAOs) can use, in place of a custom list for each engagement.
Internal Audit Teams
Internal audit teams use the ERL as a benchmark for reasonable evidence, including on audits that are not SCF-based.
Procurement & Vendor Risk Teams
Vendor risk teams use the ERL's standardized evidence list to evaluate third-party controls consistently, in place of ad-hoc vendor questionnaires.
Privacy Officers
The ERL's Privacy items, such as the Record of Processing Activities (RoPA) and Data Subject Consent Records, are the evidence for data privacy controls and work the same way as the cybersecurity items.
How Is The ERL Organized?
The ERL tab has one row per evidence item. Each row gives the item's ERL # (such as E-BCD-13, where BCD is the identifier of the Business Continuity & Disaster Recovery (BCD) domain), its Area of Focus, the artifact name, a description of what the evidence must show and the SCF controls it supports.
How Do Organizations Use The ERL?
Organizations use the ERL in five phases, in the order of an assessment.
Scope The Assessment
The organization defines the assessment boundary, with the methodology in the Unified Scoping Guide (USG), then confirms the SCF controls that apply inside it.
Pull The Evidence Items
The main tab's Evidence Request List (ERL) # column lists the items for each control, and the ERL tab's SCF Control Mappings column gives the same answer in reverse. Governance items for policies, standards and procedures are added on top.
Assign And Collect
Each item's description states what the evidence must show, and its Area of Focus helps route it to the team that owns it. For a CDPAS assessment, evidence must be no more than one year old.
Work Through The Assessment
The assessor reviews the submitted evidence against the ERL and documents any gaps or exceptions. The list is finite, but the assessor may still request additional evidence or clarification as necessary.
Close The Gaps
Evidence gaps become findings, and remediation plans close them. Collecting evidence between assessments makes evidence gathering a continuous practice rather than a last-minute scramble.
The full list of evidence items, with a description of each, is on the ERL tab of the SCF workbook.
Why Some Controls Have No ERL Item
Not every SCF control has an ERL item, by design. Every control is expected to have policies, standards, procedures and assigned roles and responsibilities, so the ERL lists those once and saves its other items for evidence unique to a control. A control with no ERL item still needs that documentation.
For example, the items for documented policies (E-GOV-01), standards (E-GOV-02) and procedures (E-GOV-04) are mapped to GOV-04, Publishing Security, Compliance & Resilience Documentation, rather than repeated on every control.
Why The ERL Matters
The ERL addresses two of the most common complaints in cybersecurity assessments: unpredictable evidence demands and assessors making up documentation requirements on the fly.
Levels The Playing Field: Evidence expectations are set before the assessment begins, so the organization and the assessor both know which artifacts are expected.
Prevents Ad-Hoc Requirements: A standardized, finite list keeps evidence requests consistent across assessors, organizations and assessment cycles.
Makes Assessments More Efficient: The organization can stage its evidence before assessor time begins. CDPAS Standard 4.4 exists to minimize scope creep, which can increase the duration, cost and personnel commitments of an assessment.
Mapped To SCF Controls: Every ERL item maps to at least one SCF control, so each piece of evidence ties to a specific control requirement.
Demonstrates Due Diligence: The ERL identifies "reasonable" artifacts that demonstrate evidence of due diligence and due care.
The ERL Works With Other SCF Content
The ERL works with other free SCF content for assessment standards, scoping and the controls themselves.
CDPAS Assessment Standards
CDPAS Standard 4.4, Defined Evidence Request List (ERL), requires the assessor to provide an ERL based on the defined controls, and the ERL is provided before the assessment starts. Its guidance points to the SCF's ERL as the minimum level of reasonable evidence requests.
Unified Scoping Guide (USG)
The USG provides a methodology for defining the assessment boundary. The ERL then covers the evidence for the applicable controls inside that boundary.
SCF Control Catalog
The ERL is a tab in the SCF workbook, alongside the 1,500+ controls it maps to. The main tab's Evidence Request List (ERL) # column links each control to its items.
.png)
%20(white).png)