Compliance
Compliance: Assessments, Frameworks, Controls and Evidence, how you measure and prove posture against the standards enabled in Governance.
Compliance covers assessing your posture against enabled frameworks, mapping controls to the requirements they satisfy, and backing requirements with evidence.
Typical workflow
Run an assessment
Open Assessments, pick a standard enabled under Governance, and start or continue an assessment, marking each requirement as claimed as you go.
Easy to miss
Claimed and validated are counted separately. Claimed is self-attested; a control becomes validated only once it's corroborated by evidence, and promoting it is a deliberate step. A fully claimed assessment can still carry a real gap.
Map controls
Map Controls to the requirements they already satisfy before treating the rest as gaps to fix from scratch. A control attached to a requirement shared across frameworks lifts coverage on each of them.
Attach evidence
Attach Evidence to back a requirement.