Control Map Flashcards
What is ControlMap?
An automated control centre to run end-to-end cyber security compliance & vCSO operations.
Compliance
Compliance refers to the act of adhering to a set of rules, standards, or laws.
It involves ensuring that all actions and operations within an organization are in line with the established guidelines, whether they are internal policies or external regulations.
This could include following environmental laws, adhering to health and safety standards, or abiding by financial reporting rules.
Controls
A rule or standard that is defined/implemented by documentation and continuous evidence collection.
For a control to be considered successfully implemented, it must be maintained over a defined period of time, i.e. 3 to 6 months, a year, indefinitely.
Continuous Compliance is a term for how organizations consistently remain in compliance with controls because a control is only effective if an organization sticks to it.
Popular Generalist Frameworks
SOC2, ISO-27001, CISv8, NIST CSF & NIST CSF 2.0, CMMC
Self-Attestation
The idea is that organizations attest to meeting specific security controls and requirements without third-party validation.
Empowers the MSP to vouch for the authenticity of a document without the help of a public notary.
To verify the document by themselves.
Not nearly as common as TPA.
Third Party Attestation (TPA)
Certifying the processes of outsourced service providers to ensure the proper procedures are being followed.
Organizations will receive a report that verifies their adherence to controls for a framework.
Third Party Attestation is paid for.
Custom Assessments
Assessments created by the MSP that is specific to their organization or clients.
These can be tied to different controls within different frameworks.
Use case where the MSP want to get a little bit more information from their clients OR they want to compare them with their own standard that wouldn’t be included in the common assessment.
Common Assessments
Approx 1200 questions that are tied to different frameworks based on what controls are present in those frameworks.
Integrations
- ScalePad (Lifecycle Manager)
- Nodewear
- CyberCNS
- Breach Secure Now
- Threatmate