Docs
How it works

Compliance

Compliance: Assessments, Frameworks, Controls and Evidence, how you measure and prove posture against the standards enabled in Governance.

Compliance covers assessing your posture against enabled frameworks, mapping controls to the requirements they satisfy, and backing requirements with evidence.

Typical workflow

Run an assessment

Open Assessments, pick a standard enabled under Governance, and start or continue an assessment, marking each requirement as claimed as you go.

Easy to miss

Claimed and validated are counted separately. Claimed is self-attested; a control becomes validated only once it's corroborated by evidence, and promoting it is a deliberate step. A fully claimed assessment can still carry a real gap.

Map controls

Map Controls to the requirements they already satisfy before treating the rest as gaps to fix from scratch. A control attached to a requirement shared across frameworks lifts coverage on each of them.

Attach evidence

Attach Evidence to back a requirement.

On this page