Exercises
Record penetration tests, disaster-recovery and continuity exercises, internal audits and scans, with their reports and what they found.
Some evidence cannot be collected from a system, because it is something people did: a penetration test, a disaster-recovery restore, a tabletop continuity exercise, an internal audit, a scan somebody ran by hand. Frameworks ask for these on a cadence, and the report usually ends up in a shared drive nobody opens again.
Exercises is where they live: what you ran, who ran it, when, the report itself, and what it found.
Record one
- Choose the type - penetration test, disaster recovery, business continuity, internal audit, security scan, or other.
- Give it a name, who performed it (a firm or an internal team), and the date.
- Attach the report, and record the findings.
Who performed it matters as much as the result: an auditor asking about a penetration test wants to know it was independent.
Upload the report, including zipped scan output
Attach the report as a file. If you upload an archive, Joopler unpacks it and stores every file inside it individually, each hashed on its own and labelled with the archive it came from.
That matters for tool output. A scanner that exports a zip of a hundred JSON and CSV files is not evidence anyone can check while it stays a single opaque blob - you cannot point an auditor at the one file that backs a particular finding. Unpacked, every file is addressable and verifiable in its own right.
You can attach more than once. A retest report is added alongside the original, never over it.
Record what it found
Findings go into your shared findings register - the same place your connected scanners report to, not a separate list. Enter them one per line, so a list from a report can be pasted straight in.
Each finding is then closed the same way any other is: remediated, accepted with a reason, or not applicable. A penetration test where two things were fixed and one was consciously accepted is a better answer than one where everything is marked closed.
An exercise that found nothing
Recording an exercise with no findings is a valid and useful outcome. Saying "we ran the DR test in June and it passed" is a different claim from never having run one, and only one of them is evidence.
What it proves
Exercises are the live evidence behind the controls that ask whether these things actually happen - penetration testing, disaster recovery and business continuity testing, internal audit, and scanning cadence. Instead of signing an attestation that says an exercise took place, the exercise itself is on the record, with its report and its findings, and the control is graded from that.
Findings and vulnerabilities
One register for everything your scanners, penetration tests, exercises and access reviews turn up, with severity rollup, auto-remediation, and a disposition other than "fixed".
Policies
Adopt, version, and get sign-off on your security policies, with acceptance tracked per person.