Mapped from the rules
that actually fired.
Compliance mappings are carried on the detection rules themselves. A control is covered because a rule mapped to it produced evidence in your estate, not because a vendor asserted coverage on a datasheet.
PCI DSS coverage computed from the rules that fired in your estate.
One mapping block, six frameworks.
A rule carries its control identifiers for every framework at once. Import the ruleset and thousands of mappings arrive with it. Write your own rule and you add the controls it evidences in the same file, in four lines.
- ▸PCI DSS, NIST 800-53, HIPAA, GDPR, TSC and GPG13 each with their own view, catalogue and report.
- ▸Mappings arrive with the ruleset and are editable, because your interpretation of a control may differ.
- ▸One block feeds everything. The page, the framework report and the case timeline all read the same mapping.
- ▸Names in full. Controls are shown with their titles wherever the catalogue provides one, never as a bare code.
The same engine, a different framework. Each view is real per framework data.
Every control opens onto the findings behind it.
An auditor asks how you know. A control here is not a green tick: it resolves to the detections mapped to it, each with a timestamp, a host, the rule that fired and the original log line that caused it.
- ▸Control to findings. Open a requirement and see the detections that evidence it, with counts over the period.
- ▸Findings to raw. Each detection keeps the identifier of the exact line on the wire that produced it.
- ▸Configuration checks count too. CIS assessment results carry their own control mappings into the same views.
- ▸File integrity counts too. Change events carry the framework codes from the rule that caught them.
NIST 800-53 by control family, resolving to the findings behind each one.
Coverage per control, and per host.
An organisation level percentage hides the one server that is failing everything. Each framework view breaks coverage down by host as well as by control, so you can see whether a gap is systemic or a single machine nobody has patched.
- ▸Per control coverage across the estate, with the trend over your chosen window.
- ▸Per host posture so a single unmanaged machine cannot hide behind a good average.
- ▸Honest gaps. A control with no mapped rule that fired shows as no evidence, not as passing.
- ▸Your time window. Coverage is computed over the period you select, not a fixed reporting month.
A document you can actually hand over.
Each framework has its own designed report, built from the same live queries that draw the page. Cover, executive summary, control analysis, per host coverage and notable findings, as A4 PDF for reading and Excel for the underlying data.
- ▸Per framework, not generic. Each report returns that framework own controls and its own coverage.
- ▸Same queries as the page so the document and the screen cannot disagree about a number.
- ▸Scheduled delivery. Cron in your timezone, delivered to a channel with the PDF attached.
- ▸Branded to you. Logo, organisation name and accent colour are settings, not a support request.
A report per framework, generated from the same live queries as the views.
Bring the control you always
have to explain.
Name the requirement your auditor keeps asking about. We will show you which rules evidence it and what the report looks like.
Powered by Codesecure Solutions. Self hosted, cloud or fully managed.
