Compliance program
Learn how a platform compliance program connects frameworks, controls, measurements, tasks and evidence, plus how it records validity statements.
The organization of the platform is the limit for compliance records and members of a company. Inside it, a compliance program connects external requirements to the activity and evidence demonstrating how these requirements are met.
Core model
Section entitled “Core Model”- A framework grouping requirements from a standard or customized program.
- A control Describes a result that the organization expects to.
- A measure Describe what the organization actually works to meet one or more controls.
- A task assign a specific work, optional with a due date.
- Evidence is a file or URL supporting the operation of a measure.
flowchart TB framework["Framework"] --> control["Control"] control <-->|many-to-many| measure["Measure"] control --> soa["Statement of<br/>Applicability"] measure --> task["Task"] measure --> evidence["Evidence"]
A reusable measure, such as an access review, can support controls across multiple frameworks, which avoids duplication of the same implementation work.
Applicability
Section “Applicability”A validity statement records which controls apply to an organization and why.It is a separate version of the daily measurement activity so that teams can review and publish a deliberate scope.
Program records
Section entitled “Program records”Frameworks, controls, measures, tasks, evidence, risks, documents, audits and obligations can be linked rather than copied.These relationships provide traceability from a requirement to its implementation, supporting the material, risks and results of the audit.
Publishing a list or statement creates a stable representation for review. project records remain editable until the responsible team is ready to publish them.
Ownership and access
Section entitled “Ownership and access”The member of the organization determines access to the program. Assign the work to named and used users audit log to investigate important changes. See Roles and permissionsSSO and SCIM manage access to the platform itself; access reviews review the imported access from the platform and connected systems.
Automation
Section entitled “Automation”Frames, controls, measurements, tasks, evidence, and validity statements are available through the console and developer interfaces.