Collect evidence from the system or process that performs the control. For ISO/IEC 27017, that can include the signed service agreement, a service-specific responsibility matrix, provider assurance material, customer configuration exports, privileged-operation logs, monitoring tests, incident records, and termination tests.
Each record should identify the service, customer and provider entities, service model, regions, control boundary, period, owner, exceptions, and follow-up. A certificate or provider report supports only the entities, services, locations, controls, and period within its scope; it does not prove the customer's configuration. Where individual customer audits are impractical or could increase risk, the provider should offer sufficiently transparent independent evidence; if independent audit is impractical, the 2015 guidance calls for a disclosed self-assessment.