Core Concepts
Understand how the platform data model connects frameworks, controls, measures, risks, evidence, audits, documents, and other basic records.
Understanding these relationships helps teams avoid duplication and keep traceability from a requirement to implementation and its evidence.
flowchart TB
subgraph required [What is required]
direction LR
framework["Framework"] --> control["Control"]
obligation["Obligation"] --> control
control --> soa["Statement of<br/>Applicability"]
end
subgraph operated [What you operate]
direction LR
measure["Measure"] --> task["Task"]
measure --> evidence["Evidence"]
measure --> document["Document"]
end
subgraph assurance [Risk and assurance]
direction LR
asset["Asset"] --> risk["Risk"]
audit["Audit"] --> finding["Finding"]
end
control <-->|many-to-many| measure
measure -->|mitigates| risk
evidence -->|supports| audit
Organizations
Section entitled “Organizations”The top-level entity on the platform. All compliance data – frameworks, controls, risks, third parties, evidence – belongs to an organization. Users are invited as members of an organization.
Frameworks
Section entitled ‘Frameworks’Compliance standards or custom programs are followed by your organization.Each framework contains controls that define the expected results.
Controls
Section titled “Controls”Specific requirements in a framework. For example, “Access control must be implemented for all production systems” or “Data must be encrypted at rest”.
Measures
Section entitled ‘Measures’Actions and processes implemented by your organization to meet controls. One measure can meet multiple controls in different frameworks. For example, a “multi-factor authentication” measure could meet access control requirements in both SOC2 and ISO27001.
Risks may be related to measures, obligations, supplier assessments and structured risk assessment scenarios.
Risk Assessments
Section entitled “Risk Assessments”Structured analysis of fields, nodes, boundaries, processes, threats and scenarios.
Third Parties
Section titled “Third Parties”Third-party management includes tracking contracts, performing risk assessments, verifying and monitoring compliance status.
The systems, applications, databases and infrastructure that your organization operates Assets are inventory and related to the controls and risks that apply to them.
Evidence
Section entitled “Evidence”Files and URLs that support the operation of a measure. Linking evidence to the implementation record keeps it reusable on each measurement-accepted control.
Activity-tracking tasks, such as implementing a control, reviewing a third party, completing an evaluation, or fixing a result.
Formal assessments of your compliance position. the platform helps you prepare evidence packages, organize documentation, and track audit findings and remedy.
Documents
Section entitled ‘Documents’Policies, procedures, reports and other controlled content. Documents support versions, approval quorums, electronic signatures, publication, archiving and PDF export.
Findings
Section entitled “Findings”Problems identified during an audit or other review. Identification types include major non-compliance, minor non-compliance, observation and exception.
Obligations
Section entitled ‘Obligations’Obligations are followed separately by framework controls to capture jurisdiction-specific requirements.
Data Classification
Section entitled ‘Data Classification’Data records describe the information processed by the organization, including business sensitivity and impact.
Processing Activities
Section “Processing Activities”Records of data processing activities, as necessary for compliance with the GDPREach records which data is processed, the legal basis, retention periods and the data subjects involved.
DPIAs (Data Protection Impact Assessments)
Section entitled “DPIAs (Data Protection Impact Assessments)”Evaluations required for high-risk data processing activities under the GDPR. DPIA assesses the necessity and proportionality of the processing and identifies measures to mitigate the risks for data subjects.
TIAs (Transfer Impact Assessments)
TIAs (Transfer Impact Assessments)The TIA assesses whether the destination country ensures adequate data protection and what additional measures are needed.
Statements of Applicability (SoA)
Statements of Applicability (SoA)It is commonly used with ISO27001, but may represent applicability decisions for other control sets.
Access Reviews
Posts Tagged ‘Access Reviews’Campaigns that bring access entries from platform members, CSV data or connected providers in a single review. Campaign decisions, flags, sources and statistics remain associated with the campaign.
Compliance Portal
The “Compliance Portal” sectionA public portal for certifications, commitments, references, files and selected links.
Devices and Agent Runs
“Devices and Agent Runs”Device records represent the recorded endpoints and their posture.Agent tasks represent the agent's activity in the product on authorized GRC data; they differ from the device's ZebraByteDevice Agent record.
How Concepts Relate
Title: How Concepts RelateThe core workflow in the platform follows this chain:
- Frameworks contain Controls It defines what needs to be done.
- Measures Implementation of controls – one measure can meet multiple controls within the framework of the
- Risks It is mitigated by measures.
- Evidence supports Measures
- Tasks Leads the daily work of implementing andining compliance
- Audits Make sure everything works as expected.
- Findings preserve the issues identified during review
- Documents formalize approved policies, procedures, and reports
See Compliance program For how this chain is operated day by day.