jump to content

Compliance program

Learn how a the platform compliance program connects frameworks, controls, measures, tasks, and evidence, plus how Statements of Applicability record scope.

View as Markdown

A the platform organization is the boundary for a company’s compliance records and memberships. Inside it, a compliance program connects external requirements to the work and proof that demonstrate how those requirements are met.

  1. A framework groups requirements from a standard or a custom program.
  2. A control describes an outcome the organization is expected to achieve.
  3. A measure describes what the organization actually operates to satisfy one or more controls.
  4. A task assigns a concrete piece of work, optionally with a due date.
  5. Evidence is a file or URL supporting the operation of a measure.
flowchart TB
  framework["Framework"] --> control["Control"]
  control <-->|many-to-many| measure["Measure"]
  control --> soa["Statement of<br/>Applicability"]
  measure --> task["Task"]
  measure --> evidence["Evidence"]
From a requirement to the work and proof that satisfy it.

Controls and measures are many-to-many. A reusable measure such as an access review can support controls in several frameworks, which avoids duplicating the same implementation work.

A Statement of Applicability records which controls apply to an organization and why. It is versioned separately from day-to-day measure work so teams can review and publish a deliberate scope.

Frameworks, controls, measures, tasks, evidence, risks, documents, audits, and obligations can be linked rather than copied. These relationships provide traceability from a requirement to its implementation, supporting material, risks, and audit results.

Publishing a list or statement creates a stable representation for review. Draft records remain editable until the responsible team is ready to publish them.

Organization membership determines access to the program. Assign work to named users and use the audit log to investigate important changes. See Roles and permissions. SSO and SCIM manage access to the platform itself; access reviews review access imported from the platform and connected systems.

Frameworks, controls, measures, tasks, evidence, and statements of applicability are available through the console and developer interfaces.

Ultima actualizare: