Skip to main content

Compliance Officer Journey

You own frameworks, assessments, evidence, and audit readiness. This path assumes the security team has already connected accounts and run scans (Days 1–2 of the First 7 Days) — compliance scores are computed from that scan data, so coverage comes first.

Typical role: Compliance Officer, with Auditor accounts for external reviewers (see Roles, Teams & API Keys).

Stage 1 — Choose your frameworks

  1. Supported Frameworks — the full catalog (ISO 27001:2022, SOC 2, PCI DSS 4.0.1, NIST CSF 2.0, GDPR, DPDP Act, SEBI CSCRF, and more), all mapped through the SCF common-control library.
  2. Compliance & GRC overview — how one control maps to many frameworks, and how statuses become scores.
  3. Activate the one or two frameworks you actually answer to. Every additional framework is mostly free later — the common-control model means evidence and control status carry across.

You can now: explain to an auditor which framework versions you track and where the control library comes from.

Stage 2 — Read your posture

  1. Compliance Posture Dashboard — scores, gap analysis, and drift detection.
  2. Autonomous Compliance — how control statuses are derived automatically from scan findings, what the score weightings are, and when manual overrides are appropriate.

You can now: name your top gaps per framework and distinguish "failing" from "not assessed."

Stage 3 — Assess what scans can't see

  1. Interactive Assessments — questionnaire-based assessments (ISO 27001, SOC 2 Type II, NIST CSF, OWASP ASVS/SAMM, and more) with Yes/Partially/No scoring and PDF export.
  2. Use auto-fill to draft answers from platform data, then review each one — auto-filled answers carry confidence levels and are yours to confirm or correct.

You can now: produce a scored self-assessment for your primary framework.

Stage 4 — Build the evidence trail

  1. Evidence Hub — auto-collected evidence with quality scores and validity windows (cloud and scan evidence stays valid 90 days; assessment answers and policy documents, 365), plus manual upload for policies and screenshots.
  2. Run Collect All, then work the review queue: approve what's right, reject what isn't, replace what's expired.
  3. Turn material gaps into governed risks in the Risk Register so they get owners, treatment plans, and SLAs instead of living in a spreadsheet.

You can now: show, for any control, why it has its status — with dated evidence behind it.

Stage 5 — India-specific obligations

Skip this stage if you have no Indian regulatory exposure.

  1. DPDP Act (India) Privacy — readiness assessment, DPIA lifecycle, vendor due diligence, and the breach workflow with dual DPB and CERT-In reporting tracks and deadline watchdog. (Consent management and data-principal request handling are on the roadmap, not in the module today.)
  2. India Regulatory Readiness — how RBI expectations, SEBI CSCRF, and CERT-In directions map to platform capabilities, and the recommended deployment shape for regulated entities. Note: CSCRF audits and VAPT remain with CERT-In-empanelled firms — the platform maintains your evidence and posture between audits; it doesn't replace the auditor.

You can now: run a DPDP readiness check and show CSCRF-relevant evidence continuity between audit cycles.

Stage 6 — Face the audit

  1. Export the audit package for your framework from the Evidence Hub — up to four layers of proof per control: policy, procedure, technical proof, attestation.
  2. Generate executive and audit reports in PDF/HTML — Reports & AI Assistance.
  3. Give your external auditor an Auditor account: read-only access to evidence and reports, with export rights — Roles, Teams & API Keys.

You can now: hand an auditor a package and an account instead of a shared drive of screenshots.

Ongoing rhythm

  • Weekly: check the Compliance Dashboard for drift and newly failing controls.
  • Monthly: review the Evidence Hub for expiring evidence (technical evidence ages out on its validity window by design — fresh scans refresh it automatically).
  • Quarterly: re-run interactive assessments and update the Risk Register treatment plans.
  • Continuously: let scheduled scans keep the technical evidence current — that's what makes this posture continuous rather than an annual scramble.