Screenshots are snapshots, not assurance systems

A screenshot can be perfectly valid evidence when it clearly demonstrates a configuration or event. The problem appears when the whole assurance model depends on somebody manually navigating through systems, taking the same screenshots every quarter and uploading them into folders. The process is labour-intensive and the resulting artefacts become stale immediately after capture.

Screenshots can also omit important context such as the source system, timestamp, population, filter criteria or reviewer decision. Without that context, later readers may struggle to understand what the image actually proves.

Use screenshots where they add value

The aim is not to eliminate screenshots. It is to stop using a manual screenshot as the default answer when a more reliable and repeatable evidence source exists.

Use the strongest practical source

Where a system can produce a report, export, log or API response, that may provide more complete evidence than a manually captured image. Some controls still benefit from screenshots, especially visual settings that are difficult to export, but the evidence method should be chosen deliberately.

Automated or semi-automated collection can reduce repetitive work, provided the organisation still reviews exceptions and retains human ownership of security decisions. Automation should improve freshness and consistency rather than create blind trust in a feed.

Design evidence around review and exceptions

Evidence becomes more useful when it is tied to a review activity. A list of user accounts is raw data; a completed access review that records identified issues and remediation decisions is stronger assurance. Similarly, a backup success report is valuable, but the management action taken when failures occur demonstrates governance.

By linking evidence, review outcomes and exceptions to the relevant controls, the organisation creates a more sustainable assurance process and reduces the scramble before audit.

Make this easier to manage in OrcaComply

OrcaComply keeps the decisions, owners, documents, controls and evidence behind your ISMS connected so the work is easier to manage and easier to explain.

Build a stronger evidence workflow →