Compliance & operations

Review compliance coverage and trends

Generate a Secorvia compliance snapshot, review framework coverage, and investigate controls through their supporting findings.

Reviewed

Before you start

Your organization needs scan results and access to Compliance. A trend needs more than one historical snapshot.

Open Compliance and generate a snapshot

Open Compliance under Overview and use the snapshot-generation action. A snapshot evaluates the available findings and mappings; it is not a certification or a replacement for an audit.

Secorvia compliance framework cards showing CIS, NIST CSF, ISO 27001, and SOC 2 coverage.
Screenshot walkthrough
  1. Generate Snapshot

    Evaluate the available findings and mappings. A snapshot is an assessment record, not a certification.

Product recording: coverage is shown separately for each framework.

Read each framework separately

Review passing and failing controls for the displayed framework cards. The recorded product includes CIS AWS, Azure and GCP Foundations, NIST CSF, ISO 27001, and SOC 2. Read the actual framework set in your deployment and inspect the controls behind a percentage.

Secorvia compliance framework cards showing CIS, NIST CSF, ISO 27001, and SOC 2 coverage.
Screenshot walkthrough
  1. CIS AWS Foundations

    Read both the percentage and controls passing. Here 7 of 17 controls pass; open findings appear against individual controls.

  2. Azure and GCP frameworks

    Each cloud has its own evaluated controls. A displayed 100% applies to that framework and the assessed scope.

  3. NIST CSF

    Compare coverage within this framework rather than treating different control totals as equivalent.

  4. ISO 27001 and SOC 2

    Read their coverage and control references separately. One underlying finding may affect several frameworks.

Product recording: coverage is shown separately for each framework.

Investigate the findings behind a control

Use the control/finding detail available in the framework view and review Compliance impact on an individual finding. A single security condition can map to several frameworks. Remediate the underlying condition and verify it with a scan.

Secorvia compliance framework cards showing CIS, NIST CSF, ISO 27001, and SOC 2 coverage.
Screenshot walkthrough
  1. Control references and open findings

    Start with the affected control and its open-finding count, then inspect the supporting findings in the app.

  2. The same workflow in another framework

    SOC 2 also lists control references with open findings. Check the underlying condition before counting it as a separate issue.

The cards show control references and counts. Control detail and an individual finding’s Compliance impact are not pictured.

Product recording: coverage is shown separately for each framework.

Use the coverage trend

Select a framework, interval, and date range under Coverage Trend. If there is not enough history, collect additional snapshots before making a trend claim. Keep the same framework and interval when comparing periods.

Compliance Coverage Trend with framework, time interval, and date-range selectors.
Screenshot walkthrough
  1. Framework

    Choose the framework to compare over time. Keep it consistent when comparing periods.

  2. Interval

    Select the interval, such as Daily, for the coverage history.

  3. Date range

    Choose a period with enough snapshots to support the comparison.

  4. Not enough history

    This message means a trend cannot yet be drawn. Collect more snapshots; a latest reading alone is not a trend.

Product recording: the trend is empty when there is not enough snapshot history.

Prepare evidence for review

Generate the appropriate report from Reports and include the assessment scope and period. Review failed controls and missing evidence with the responsible team rather than treating a headline percentage as complete assurance.

Where you are now

You can connect a framework percentage to evaluated controls, findings, and a dated snapshot.

WHEN SOMETHING LOOKS OFF

A few things to check

No coverage data yet

Generate a snapshot after scans have produced results.

Not enough history to chart

More snapshots are required; a single snapshot cannot show a reliable time trend.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia