Compliance - Owned work
Turning a gap list into owned work: Lex proposes a task for each priority gap, you approve it, and reassign the owner on a live worklist once it's tracked.
A gap with no name against it never closes. Once gaps are identified, the next step is turning them into work someone is actually responsible for.
Your job here is judgement, not typing
Lex, the compliance sidekick, drafts a task for each priority gap. Approve it and it lands as a tracked item on your Actions worklist — that's where you reassign it to whoever's actually right for the job, not before.
Typical workflow
Set up a shared space for evidence
CISO360AI can gather evidence on many topics on its own. For the artefacts that still have to be collected by hand, set up a shared folder outside the platform so the evidence backing each gap has one home, rather than sitting wherever whoever last touched it left it.
Where evidence comes from
- inferred by the platform from a connected source
- proposed for linking by a sidekick, pending your approval
- entered during an assessment, under
Compliance → Assessments - linked by hand in the evidence library, under
Compliance → Evidence
Lex proposes a task for each priority gap
Lex drafts a task for each priority gap, rather than leaving you to turn a flat gap list into work by hand.
Approve, then track it live
Once approved, a proposal becomes tracked work with a status and a completion date, on a live worklist — this is also where you set or change who owns it.
Compliance - Your frameworks
Choosing a framework: why enabling it is deliberately yours alone, and what Lex does with it once it's on.
Compliance - Gather evidence
Getting evidence attached to requirements: what counts as done, what's already covered without you chasing it, and what still needs a person to produce and approve it.