A compliance calendar we work through for you.
It starts when
It starts on a schedule.
Most compliance work recurs. The calendar knows when each activity is due, and the work begins ahead of the date.
A quarterly review comes due
Microsoft 365, AWS, and endpoint configuration are reviewed every quarter.
The month closes
Audit logs are reviewed every month, and a named reviewer signs off.
Twice a year, the network rules
Firewall and security group rulesets are reviewed every six months.
A test report arrives
Penetration test and application scan findings go into your vulnerability register and are worked to their windows.
An auditor opens an examination
The observation window starts, and the calendar's records become the evidence the auditor reads.
An activity runs late
Anything past its date escalates on our side, so the calendar stays current.
What our specialists do
We run each activity to a signed record.
Every activity follows the same path, from the calendar to a frozen record your auditor can read.
Run the activity
A specialist works the activity from a written procedure, one of the 28 we keep for the basic compliance activities.
Assemble the evidence
The evidence for that activity is gathered into one packet and mapped to the controls it satisfies in your framework.
Our CISO reviews it
Our CISO reviews the packet before it reaches you.
Bring it to you for sign-off
You sign off in the Portal, and the record freezes with the evidence exactly as you approved it.
Each signed activity rolls up into a readiness view per framework, and our CISO reads it with you, so you and your auditor see the same picture of where the program stands.
What you see in the Portal
The year's compliance work, on one calendar.
Each activity shows its cadence, its due date, and where it stands, so the next sign-off waiting on you is easy to find.
- Signed off
Microsoft 365 configuration review
Quarterly
- Awaiting your sign-off
Audit log review
Monthly
- In CISO review
AWS configuration review
Quarterly
- Scheduled
Network rule review
Twice a year
Cadence and due date on every activity
Each recurring activity carries its rhythm, quarterly, monthly, or twice a year, and the date it is next due.
The sign-off that is yours
An activity waiting on you says so, and opens to the evidence packet you are approving.
Readiness per framework
Your controls catalog is mapped to each framework you hold, with a readiness roll-up across the signed activities.
What you sign
Your sign-off on each activity.
When an activity's evidence is assembled and reviewed, it comes to you. You read the packet and sign off in the Portal.
What you keep
A frozen record for every period.
Each signed activity becomes a frozen record mapped to your controls, and each control keeps its evidence history in one place. During an examination, the records cover the observation window period by period.
How an auditor reads itEasy is a calendar our specialists work through, with the evidence assembled each time an activity completes.
This is how we keep security and compliance easy.
Next: Evidence and auditsAn audit that reads a record already kept.
A calendar of recurring activities, run by our specialists, signed off by you, and frozen as evidence mapped to your controls. That is how we run compliance operations, on the platform that runs your cloud, IT, and security.
Compliance operations come with the Assurance Tier. See what each tier covers.
Walk through the calendar on a real portal with us, and see the sign-off from your side.