Add custom manual evidence records to list
We'd like to manually add evidence records to prove that we're actually generating "records of access request issues tracked". Since Secfix doesn't provide Clickup integration yet and we can't turn some ticketing-system-related tasks green, we would then add proof for that on the manual evidence list.
I'm referring to the automated tasks called "Records of access requests issues tracked" and "Records of security issues being tracked" in my example.
Log in to comment and vote
Comments8
Johannes Renk
Aug 27
It would be extremely helpful to have a feature that allows us to create completely new evidence items, give them a custom name, and assign them to a specific control or other relevant category.
This would allow us to map recurring tasks in SecFix that belong to the same ISO 27001 control but are assigned to different employees. For example, multiple employees could be responsible for similar recurring tasks, with each task having its own evidence item while still being linked to the same control.
In addition: This would be very helpful for custom policies. Currently, it is not possible to attach evidence to them.
Jan 12
Jakub Wanat
Aug 22, 2025
Marc Morone reported having some extra manual evidence in SharePoint (e.g., floor plan, process landscape, Ubuntu encryption exceptions) that can’t be added directly in Secfix.
It would be good to add custom manual evidence (similar to policies).
Nov 12, 2024
Grigory Emelianov
Oct 2, 2024
Hi Michael Niemand thank you for your feedback. I'd love to review this for you. Can you please provide 2-3 specific examples of links or files that you wanted to add to the security report under A8 (Tech Controls)? Thank you
Michael Niemand
Oct 2, 2024
Grigory Emelianov absolutely!
Here goes:
8.1 - Screenshot of password complexity rules in MDM
8.4 - Screenshot that shows git users are specific to a project
8.23 - Screenshot of router blacklist, VPN blacklist
8.24 - Screenshot of ssl checker like ssllabs.com
8.25 - Screenshot showing there is an approval process in Git
This is what I can remember; Now that we had our first audit it is evident that the auditor can have different views on what needs more detailed evidence, so the ability to add and update arbitrary evidence on a per control basis (on top of the templates in manual evidence) would be beneficial.
Grigory Emelianov
Oct 2, 2024
Michael Niemand: Thank you, now it's loud and clear. I completely understand. You’re right—every auditor has their own approach, and it’s challenging to predict what additional evidence they might request.
Based on your feedback, I have a suggestion: Would it help if we allowed you to add custom evidence, be it a link or a document, in the Manual Evidence page and map it to the relevant framework controls? This way, you could centralize all additional evidence, and it would automatically appear in each security report, even across multiple standards.
Michael Niemand
Oct 2, 2024
Grigory Emelianov that would be perfect - as long as I can look for a certain control by its number and then add evidence to that. Right now, the control number can only be seen when hovering over the standard "pill" which makes it kinda hard to find the right section in manual evidence. scrolling down, hovering over each pill to find 8.24 is pretty cumbersome. That's how the auditor works though, he goes through all the controls by their number. So being able to find an evidence by its control number is crucial