Compliance proof

One status per requirement, read from what your documents are set up to check and what their sessions found. Nothing is attached or typed by hand.

Compliance proof

The compliance proof page answers one question per requirement: is it proven, and by what? It does no checking of its own. It reads two things from each of your documents:

  • Its steps — what the document is set up to check. A document's process step that checks a requirement puts the document on this page. Nothing is attached by hand.
  • Its sessions — what the document's agent found each time it ran, what it read (for example a user list from a connected system), and which version of the document it followed.

Requirements are grouped by topic (access management, asset management, backup and so on), one topic for each area your standards cover.

The five states

StateWhat it means
GapA session found a problem, or the document's steps cannot prove the whole requirement.
Needs youNo document checks it yet, its document is switched off, a session is waiting on a person, or a session ran and could not confirm it.
Set up, not yet runA document checks it, and its agent has not had a session yet.
ProvenEvery document that checks it can prove all of it, and their latest findings say it is met.
Not applicableYou recorded that it does not apply to you.

When several documents check the same requirement, every finding is shown and the worst one decides. A policy that requires two-step sign-in and a procedure whose session found three accounts without it make a gap, with both findings on the row.

A design gap is a requirement a document's steps can only partly prove. If a procedure checks that every admin role has an owner but no step checks that admin rights are reviewed, its sessions can never prove the whole requirement, and the row says which part is missing. The fix is a step in the document, not a setting on this page.

One proof, several standards

The page opens on one line per standard: how many of its requirements are proven and how many are missing. Below it is one line per topic with the same two numbers. Topics with something missing come first, and opening a topic lists its requirements, worst first.

A finding is recorded once, against the requirement its document checks. Each standard shows the same findings grouped by that standard's numbering, with the worst deciding, under the same topics.

Opening a requirement shows one line per document that checks it: what its latest session found, when that was, when it checks next, and a link to the session.

Looking back

Pick a date under Showing to see the page as it stood at the end of that day, rebuilt from the sessions and decisions recorded by then. A document's steps are read as they are today, because a document keeps one current set of steps.

Changing what is checked

Nothing is set on this page. How often a document runs, what it checks and whether it is switched on are all written in the document, so every action here opens the document or the session. Ask Alchex reads the same statuses, so "why is this a gap?" gets the answer this page shows.