What to Provide
Evidence of response to any security incidents that have taken place for the in-scope during the review period.
This evidence should include any:
Formal documentation
Tickets
Postmortem documents
Communications made related to the security incident
If no security incidents have taken place during the review period then provide system-generated evidence demonstrating that no security incidents have taken place.
System screenshots, or the system query, or the source documentation, that demonstrates that the list of security incidents (or lack thereof) you've provided is complete and accurate
Evidence Format
Exported document in a common file type such as .docx, .csv, or .pdf or screenshots or exported images in a common image file type such as .jpg, .png, or .pdf.