Compliance

Evidence as a byproduct of the work

Findings carry their control context, so the inventory and remediation history you maintain day to day is the same artifact an assessor asks for. Mapping is a starting point for your assessor's scope, not a certification claim.

ISO 27001 logoAICPA SOC for Service Organizations logoNIST SP 800-53 badgeFedRAMP logoHIPAA compliance logo
FrameworkRelevant controlsEvidence produced
ISO 27001A.5.16, A.5.18, A.8.2, A.8.9Identity inventory with owners, privilege review records, credential lifecycle log
SOC 2CC6.1, CC6.2, CC6.3, CC7.2Continuous monitoring of logical access for nonhuman identities and remediation history
NIST 800-53AC-2, AC-6, IA-5, CA-7Account management, least privilege, authenticator management, continuous assessment
FedRAMPAC-2, IA-5, CA-7Inventory and monitoring artifacts for service and workload identities
HIPAA Security Rule§164.308(a)(4), §164.312(a)(1), §164.312(d)Access authorization, unique identification, and authentication management for system accounts

Bring machine identities into your control narrative

Walk through how findings map to the frameworks in your current scope.