Audit Management
Audit Management gives you a single place to prepare for security and compliance audits: gather the evidence that demonstrates a control is met, track the findings that come out of an assessment, and drive each finding through to closure. Evidence and findings are organized around the same framework controls you track elsewhere in Compliance, so the work you do day to day feeds directly into audit readiness.
Compliance — including Audit Management — is a Beta capability in Cert-IX and is still expanding. The evidence organization, finding lifecycle, and remediation workflow described below are the core of what ships today. Sections marked rolling out describe automation that is planned or being introduced; treat them as roadmap rather than guaranteed behavior.
How audit management fits together
An audit, at its simplest, is a check that your controls are in place and that you can prove it. Cert-IX supports that in three linked stages:
| Stage | What you do | What the platform tracks |
|---|---|---|
| Evidence | Collect and attach the artifacts that show each control is satisfied | Evidence items linked to the controls they support |
| Findings | Record gaps, observations, and non-conformities raised during (or before) an audit | Findings with severity, owner, and status |
| Remediation | Fix the underlying issue and prove the fix | Remediation progress until each finding is closed |
Because evidence and findings attach to controls from the frameworks you already track — NIST CSF, ISO 27001, SOC 2, CIS Controls, NIS2, and any custom frameworks you define — the same record can serve more than one audit when those frameworks share overlapping requirements.
Preparing for an audit
Preparation is mostly about closing the gap between the control status you claim and the evidence you can produce. A practical sequence:
- Confirm scope. Decide which framework(s) and which controls the audit will cover.
- Review control status. Identify controls that are marked satisfied but have thin or missing evidence.
- Collect evidence for those controls (see below).
- Self-assess and note gaps. Where a control is not yet met, record it as a finding so it is tracked rather than forgotten.
- Remediate the most significant gaps before the audit begins.
Treat gaps you find during self-assessment as first-class findings. Logging them up front means they move through the same remediation workflow as auditor-raised findings, with an owner and a clear status — instead of living in a spreadsheet.
Managing evidence
Evidence is any artifact that demonstrates a control is operating: a written policy, a configuration export, a screenshot of a setting, a ticket showing a process was followed, or output from a security scan. In Cert-IX, evidence items are attached to the controls they support, so an auditor (or a future you) can move from a control to the proof behind it directly.
Types of evidence
- Documents — policies, procedures, and standards you maintain in Policy Management.
- Configuration and screenshots — exported settings or captured screens that show a control is configured correctly.
- Scan output — findings and results produced by Cert-IX's own vulnerability scanning. Because the platform already runs dependency and vulnerability scans (see Vulnerability Management), scan results can serve as evidence that technical controls are being monitored.
- Records and tickets — artifacts that show a recurring process (access reviews, patching, incident handling) actually happened.
Each evidence item records who added it and when, so you retain a basic history of what was submitted for a given control.
Automated evidence collection — pulling evidence for certain technical controls directly from platform data on a schedule — is rolling out. Today, plan to attach most evidence manually or export it from the relevant Cert-IX surface.
Tracking findings
A finding is anything an audit surfaces that needs attention: a missing control, a partially met requirement, or an observation for improvement. Findings are the unit of work you manage after (and during) an assessment.