jump to content

Core Concepts

Understand how the platform data model connects frameworks, controls, measures, risks, evidence, audits, documents, and other basic records.

Show as Markdown

Understanding these relationships helps teams avoid duplication and keep traceability from a requirement to implementation and its evidence.

flowchart TB
  subgraph required [What is required]
    direction LR
    framework["Framework"] --> control["Control"]
    obligation["Obligation"] --> control
    control --> soa["Statement of<br/>Applicability"]
  end

  subgraph operated [What you operate]
    direction LR
    measure["Measure"] --> task["Task"]
    measure --> evidence["Evidence"]
    measure --> document["Document"]
  end

  subgraph assurance [Risk and assurance]
    direction LR
    asset["Asset"] --> risk["Risk"]
    audit["Audit"] --> finding["Finding"]
  end

  control <-->|many-to-many| measure
  measure -->|mitigates| risk
  evidence -->|supports| audit
How primary records are Each record belongs to a single organization.

The top-level entity on the platform. All compliance data – frameworks, controls, risks, third parties, evidence – belongs to an organization. Users are invited as members of an organization.

Compliance standards or custom programs are followed by your organization.Each framework contains controls that define the expected results.

Specific requirements in a framework. For example, “Access control must be implemented for all production systems” or “Data must be encrypted at rest”.

Actions and processes implemented by your organization to meet controls. One measure can meet multiple controls in different frameworks. For example, a “multi-factor authentication” measure could meet access control requirements in both SOC2 and ISO27001.

Risks may be related to measures, obligations, supplier assessments and structured risk assessment scenarios.

Structured analysis of fields, nodes, boundaries, processes, threats and scenarios.

Third-party management includes tracking contracts, performing risk assessments, verifying and monitoring compliance status.

The systems, applications, databases and infrastructure that your organization operates Assets are inventory and related to the controls and risks that apply to them.

Files and URLs that support the operation of a measure. Linking evidence to the implementation record keeps it reusable on each measurement-accepted control.

Activity-tracking tasks, such as implementing a control, reviewing a third party, completing an evaluation, or fixing a result.

Formal assessments of your compliance position. the platform helps you prepare evidence packages, organize documentation, and track audit findings and remedy.

Policies, procedures, reports and other controlled content. Documents support versions, approval quorums, electronic signatures, publication, archiving and PDF export.

Problems identified during an audit or other review. Identification types include major non-compliance, minor non-compliance, observation and exception.

Obligations are followed separately by framework controls to capture jurisdiction-specific requirements.

Data records describe the information processed by the organization, including business sensitivity and impact.

Records of data processing activities, as necessary for compliance with the GDPREach records which data is processed, the legal basis, retention periods and the data subjects involved.

Evaluations required for high-risk data processing activities under the GDPR. DPIA assesses the necessity and proportionality of the processing and identifies measures to mitigate the risks for data subjects.

TIAs (Transfer Impact Assessments)

TIAs (Transfer Impact Assessments)

The TIA assesses whether the destination country ensures adequate data protection and what additional measures are needed.

Statements of Applicability (SoA)

Statements of Applicability (SoA)

It is commonly used with ISO27001, but may represent applicability decisions for other control sets.

Campaigns that bring access entries from platform members, CSV data or connected providers in a single review. Campaign decisions, flags, sources and statistics remain associated with the campaign.

A public portal for certifications, commitments, references, files and selected links.

Devices and Agent Runs

“Devices and Agent Runs”

Device records represent the recorded endpoints and their posture.Agent tasks represent the agent's activity in the product on authorized GRC data; they differ from the device's ZebraByteDevice Agent record.

How Concepts Relate

Title: How Concepts Relate

The core workflow in the platform follows this chain:

  • Frameworks contain Controls It defines what needs to be done.
  • Measures Implementation of controls – one measure can meet multiple controls within the framework of the
  • Risks It is mitigated by measures.
  • Evidence supports Measures
  • Tasks Leads the daily work of implementing andining compliance
  • Audits Make sure everything works as expected.
  • Findings preserve the issues identified during review
  • Documents formalize approved policies, procedures, and reports

See Compliance program For how this chain is operated day by day.

Ultima actualizare: