Definition
An evidence ladder is a governed sequence of evidence states, such as detected, observed, corroborated, validated, proven, disproven, or accepted. It prevents teams from treating a raw signal as proof before the signal has earned authority.
States cannot be skipped unless the source is explicitly trusted to support the target evidence level. Qualification strength is a function of source diversity, not signal count.
Why it matters
It prevents teams from treating a raw signal as proof before the signal has earned authority. Without a ladder, severity and confidence scores are mistaken for decision-grade evidence.
Example
A scanner detection of a SQL injection is at the "detected" state. Reachability analysis promoting it to "observed" and a retest promoting it to "validated" are separate, recordable steps.
Related terms
- Security verification body — An independent function that evaluates whether security evidence satisfies policy for a consequential decision.
- Suppression vs disproval — Suppression hides or accepts a finding for workflow purposes; disproval provides evidence that the finding is invalid in the evaluated context.
- Verified remediation — Confirmation, through qualified evidence, that a claimed fix removed or neutralized the specific risk being evaluated.