Security Operations
Help Centre
❓
How compliance monitoring works
1
Control catalog
Frameworks are modelled as control catalogs (ISO 27001, NIST CSF, CIS Controls, Essential Eight…).
2
Geo-sensing
Only the frameworks that apply to your country, industry and attributes are evaluated. NZ clients see NZISM/PSR; US federal sees FedRAMP; EU sees GDPR/NIS2 - frameworks that don't apply are hidden.
3
Automatic evidence
Each control maps to real platform evidence - audit logs, automation runs, approvals, RBAC, secure score, integration health. Status is recomputed on demand from live data.
4
Continuous re-check
Sensors monitor evidence sources continuously, so posture stays current without manual collection.
The platform reports which controls are demonstrably satisfied - it never claims certification or attestation.
Supported frameworks
ISO 27001 ISO 27002 ISO 27701 GDPR NZ Privacy Act NIST CSF CIS Controls SOC 2 PCI DSS Essential Eight NZISM PSR IRAP FedRAMP FISMA NIS2 DORA COBIT
Compliance changes

The Compliance Watch page tracks changes to standards and regulations - ISO 27001 updates, NIS2 implementation, NZISM revisions, GDPR guidance and more - so your team knows when a framework you rely on changes.

Compliance Watch β†’
Compliance reports

Generate compliance reports from the Reports page - posture, framework status, control evidence - exportable as branded PDF. Reports include a clear disclaimer that they are guidance, not certification.

Reports β†’
Troubleshooting: "Compliance temporarily unavailable"
If the compliance engine can't compute posture, the page tells you the failure class:
  • Internal error - a platform bug; check System Health and contact support.
  • External source unavailable - an upstream source timed out; use Retry or view source status.
  • Permission failure - the configured credentials lack permission; fix in the Configuration Centre.
  • Configuration problem - credentials missing or invalid; configure and test.
The page always shows the last successful update where available, with Retry and source-status options - never a bare server error.