Monitor

Getting started

Using Monitor

Network and troubleshooting

Your account

Project

Build an evidence pack

An evidence pack is the record, for one client over a period you choose, of what each of their machines reported and when. It is built from readings the collector stored as they arrived, timed by the collector's own clock rather than the machine's, and none of them can be changed afterwards.

Build one

The Evidence pack page with the client Quillmoor Dental and the dates chosen
Choosing the client and the dates.
  1. Open Evidence.
  2. Choose the client and the dates.
  3. Choose Build. Print it, or save it as a PDF from your browser.

Anyone on your account can build one.

What is in it

The top of an evidence pack for Quillmoor Dental: the period and provider, what the pack is and is not, and its three machines
The start of a pack.

What it is, and is not

What each machine reports is an attestation, not proof. The machine belongs to your client, and someone with administrator rights on it could make it report something untrue. The pack is a continuous, timestamped record of what the machines said, which is useful evidence for an assessment and for the year between assessments; it cannot verify that a machine was set up as it said.

For disk encryption, the pack records whether the machine reports a recovery key protector. It cannot confirm that a key held elsewhere can actually be retrieved.

Next: Read the audit log