The Compliancy model
How Compliancy works
A compliance program is a set of objects and the relationships between them: requirements, controls, policies, evidence, risks and owners. Compliancy keeps those relationships intact so status can be reported at any time.
Define
Determine which frameworks apply, what is in scope and who is responsible.
Frameworks in scope
- SOC 2 (Security, Availability)Operating
- ISO 27001:2022Operating
- GDPROperating
Map
Connect framework requirements to the controls that address them, and see where nothing is mapped yet.
Manage
Connect controls with policies, risks, owners, evidence and vendors so the program has one structure.
Open risks
7
3 treated
Policies due review
2
- R-12 Excess privilege in production — owner Marcus T.
- R-19 Vendor without security review — owner Priya R.
Monitor
Understand readiness and outstanding actions continuously, rather than in the weeks before an audit.
Prove
Produce the control, policy and evidence information auditors, customers and stakeholders ask for.
Auditor request — CC6.1
- Q1 access review exportOperating
- Q2 access review exportOperating
- Access Management Policy v3Operating
How the objects connect
Requirements map to controls. Controls carry policies, evidence and risks. Compliance status is derived from what those objects actually show.
Every risk, with its score and treatment in one view.
Acknowledge POC Policy
Step: Perform Task
Workflow progress
Control procedure
Policy Acknowledgement
Go to the “Policies” tab. Review the policy and acknowledge that you have read it by certifying and submitting the task.
Resources
CCPA policy Rev 2.docx11/3/2022
Response
This looks very good! Go ahead.
Attachments
Upload