Compliance Overview
Cert-IX Compliance gives you a single place to track the security frameworks that apply to your organization, map their controls to your environment, record supporting evidence, and see where gaps remain. Rather than living in a separate silo, it draws on data the platform already holds — your asset inventory, vulnerability findings, and agent-based hardening checks — so control status reflects your real security posture instead of a spreadsheet snapshot.
Compliance is a Beta feature and is still rolling out. The framework catalog, control mapping, and evidence tracking described below are the core of what ships today; automation such as scheduled reassessment and drift detection is on the roadmap and is not yet a guaranteed capability. Expect the workflow to be partly manual as the module matures.
How compliance works
Compliance in Cert-IX follows a straightforward model:
- Frameworks define a structured set of controls (for example, ISO 27001 Annex A controls or the NIST CSF functions).
- Controls are mapped to the systems, assets, and processes in your environment that satisfy them, and each control is given an owner.
- Status records how well each control is met — Compliant, Partially compliant, Non-compliant, or Not assessed.
- Evidence is attached to controls to substantiate their status, from documents you upload to signals the platform already collects.
- Gaps are the controls that are not yet met, which become the work list for improving your posture.
Because controls are tied back to real assets and findings, the same underlying data can support more than one framework at once — a hardening result or a resolved vulnerability can be evidence for an ISO 27001 control and a SOC 2 criterion simultaneously.
Supported frameworks
Cert-IX ships with a catalog of widely used security frameworks and lets you add your own. Use pre-loaded frameworks as a starting point, or define a custom framework to track internal standards or a regulatory obligation specific to your industry.
| Framework | What it covers |
|---|---|
| NIST CSF | The NIST Cybersecurity Framework's core functions for managing cyber risk. |
| ISO 27001 | The international standard for an information security management system (ISMS) and its Annex A controls. |
| SOC 2 | Trust Services Criteria used to demonstrate security and related controls to customers and auditors. |
| CIS Controls | The CIS prioritized safeguards for practical cyber defense. |
| NIS2 | The EU network and information security directive obligations. |
| Custom | Your own control set — an internal policy baseline or a framework Cert-IX does not pre-load. |
See Frameworks for the control detail of each framework and how mapping works.
Control mapping and status
The heart of the module is mapping controls to your environment and keeping their status current. Each control carries a status so you can see coverage at a glance:
- Compliant — the control is implemented and evidenced.
- Partially compliant — implemented in part, or evidenced for only some of your systems.
- Non-compliant — not currently met; this is a gap to remediate.
- Not assessed — no status has been recorded yet.
Where frameworks overlap, the same control work counts toward each of them. The Compliance Matrix shows this cross-framework view so you can see how a single set of controls maps across the frameworks you track.
Evidence
Evidence is what substantiates a control's status when you or an auditor need to verify it. You can attach evidence to controls in a few ways:
- Uploaded artifacts — policy documents, procedure records, configuration exports, and screenshots.
- Platform signals — data Cert-IX already produces, such as vulnerability findings and scanner-agent hardening results, linked to the controls they support.
Evidence handling is part of the Beta surface. Treat it as a way to organize and link supporting material to controls, not as a certified system of record. See Audit for how evidence supports audit preparation and finding tracking.
How compliance connects to the rest of the platform
Compliance is most useful when it reuses the security work you are already doing in Cert-IX:
- Vulnerability findings. Findings from the platform's scanning surfaces are ranked by severity with remediation guidance, and open findings on a system are direct evidence of gaps in the controls that system supports. See Vulnerability Management.
- Scanner-agent hardening. The Bitenforcer scanner agent checks internal systems against CIS, STIG, and PCI-DSS hardening baselines. Those results give you concrete, per-host evidence for the corresponding controls. See Scanner Agents.
- Security posture. Your overall Security Score reflects the state of your environment, so improving compliance coverage and closing findings shows up in your posture over time.
Policies
Alongside frameworks, you can document the internal security policies that back up your controls and reference them as evidence. Policy management is early and evolving; see Policies for what is available today.
Data handling and privacy
Cert-IX runs on EU-hosted infrastructure and is designed to be GDPR-aligned. Some sub-processors are located in the US and are covered by Standard Contractual Clauses; the details are set out in the privacy notice.
The frameworks above are the ones Cert-IX helps you track. Custom frameworks let you record your own regulatory obligations, but the platform does not ship dedicated, certified modules for every regulation — treat compliance tracking as a tool to organize your program, not as a compliance guarantee or a substitute for your own legal and audit review.
Getting started
You will work with Compliance from the dashboard at app.cert-ix.com. A typical path is:
- Choose the frameworks that apply to your organization, and add a custom framework if you track an internal or industry-specific standard.
- Map controls to your systems and assets, and assign an owner to each.
- Record status and evidence, linking existing platform signals — vulnerability findings and Bitenforcer hardening results — where they apply.
- Track and close gaps, prioritizing the non-compliant controls that carry the most risk.
Let evidence accumulate as you go. Because scanner-agent hardening and vulnerability findings can be linked to controls as you work, keeping them current means much of your evidence is ready before an assessment rather than gathered in a scramble beforehand.
Next steps
- Frameworks — the control detail behind each supported framework.
- Compliance Matrix — the cross-framework coverage view.
- Audit — evidence, findings, and audit preparation.
- Vulnerability Management — the findings that feed control status.
War diese Seite hilfreich?