Continuous controls monitoring

Compliance you can open, down to the evidence.

CCM assesses every application against your master framework from the evidence your tools already hold, derives compliance with the other frameworks you report on, and turns each failing control into a gap that a named person confirms, plans and closes.

pillars, from inventory to report
4
agents, each with a stated limit
5
reports, in four formats
4
stages in a gap's lifecycle
6
From telemetry to a signed decisioncontinuous
WizWizCrowdStrike FalconCrowdStrike FalconMicrosoft Defender for EndpointQualys VMCyberArkControl testseach control checked against the records, on a schedule
01AssessmentEvery control of the master framework, for every application.
02Gap registerEach failing control: risk score, SLA, owner, signed trail.
03ReportsBoard, framework, application and gap reports, exported.
The lifecycle

Four pillars, in the order the work runs.

The platform's navigation is grouped the same way, so what is described here is where it is found.

  1. 01Prerequisites

    Every application in an inventory with an owner, a criticality and the business service it supports. One master framework, chosen once, that everything is assessed against.

    Application inventoryCriticality C1 to C3Master frameworkRoles
  2. 02Frameworks and integrations

    Other frameworks are mapped onto the master, control by control, so compliance with them is derived rather than assessed twice. Tools are connected, and what they send is minimised before it is admitted as evidence.

    Framework mappingConnected toolsFields kept, hashed or dropped
  3. 03Continuous monitoring

    Control tests run on a schedule against the tools' records. Vendors' SOC 2 reports are read and mapped. Each application is assessed every month and on demand, all controls, every time.

    Control testsSOC 2 reportsMonthly and on-demand assessments
  4. 04Reporting and gap register

    A control that fails is a gap: confirmed by a person, scored for risk, given an SLA, planned, treated and verified by the next assessment. Reports are built from the record when they are opened.

    Gap lifecycleRisk acceptanceFour reports, four formats
Integrations

Evidence from the tools you already run.

CCM does not scan. It reads what your security tools already know about each application, keeps only the fields a control test needs, and says which tool every result came from.

WizWizCloud configuration findings: storage, network exposure, encryption at restdaily
Microsoft Defender for EndpointDevice compliance: disk encryption, session lock, host firewalldaily
CrowdStrike FalconCrowdStrike FalconEndpoint policy checks: sensor coverage, prevention policies, host intrusion detectiondaily
CyberArkPrivileged account posture: multi-factor authentication, vaulting, rotationdaily
Qualys VMVulnerability and policy compliance results: patch levels, hardening baselinesdaily
BrinqaBrinqaConsolidated findings with their remediation statusdaily
ServiceNow CMDBServiceNow CMDBThe asset inventory the other records are matched againstdaily
Akamai KonaWeb application firewall coverage of externally exposed applicationsweekly
More connectors in the catalogue
  • Qualys SSL Labs
  • Snyk
  • Aqua Security
  • Azure DevOps
  • Auth0
  • Cloudflare WAFCloudflare WAF
  • AWS WAFAWS WAF
  • Cisco Meraki
  • Okta
  • Microsoft Sentinel
  • Splunk EnterpriseSplunk Enterprise
  • Tenable.ioTenable.io
  • GitHub
  • SentinelOneSentinelOne
  • Palo Alto Panorama
  • ZscalerZscaler
Agents

Five agents. Each does one job and says what it will not do.

An agent here is a bounded piece of work with named tools. Two of them call no model at all, and every run of every one can be played back.

01No modelAssessment Agent

Scores one application against every control of the master framework from the evidence on record.

Calls no model and changes no evidence. A control with no evidence is not compliant.
02Calls a modelSOC mapper

Reads a vendor's SOC 2 Type II report and maps the controls its auditor tested onto the master framework.

Never marks a control met without a tested control in the report to rest on.
03Calls a modelFramework mapper

Maps the master framework onto another framework, control by control.

Assesses nothing. It only says which controls stand for which requirements.
04Calls a modelRemediation Agent

Drafts a remediation plan for one gap from its record: the control, the evidence, what the control tests found and the mapped clauses.

Never approves its own plan and never invents a source: citations it was not given are dropped.
05Calls a modelAssistant

Answers questions about the estate from the record, with the figures the pages show.

Changes nothing unless the person asking confirms it in words.
A model only where reading is needed

Reading a SOC 2 report, matching two frameworks and drafting a plan use a model. Scoring and testing do not.

Citations, not assertions

A drafted plan cites the record items it was given on every step. A citation the model was not given is dropped.

Every run has a transcript

Tool calls, reasoning, what was written and where a person decided, with tokens and cost where a model was used.

Governance

The agents do the reading. People take the decisions.

What runs on its own, what waits for a named person, and what is never automated are fixed by the platform, not by a prompt.

01Runs on its own
Control tests on their schedule, the monthly assessment of every application, and the scoring of each control.These are deterministic: a test is a query over the tool's records and a score is arithmetic over the evidence. No model is called.
02A person decides
Confirming a gap, approving or rejecting a remediation plan, accepting a risk, and closing a gap.Each decision is signed with the name and role of the person signed in. A risk acceptance is decided by someone other than the person who asked, and lasts a year at most.
03Never automated
Changing evidence, marking a control compliant without evidence, and an agent approving its own work.A control with no evidence is not compliant. A gap is verified by the next assessment, not by a person's say-so.
Roles

Viewer, assessor, compliance lead and administrator. Reading needs a session; changing a record needs a role that allows it.

A signed trail

Every move of a gap through its lifecycle is an entry with a date, a name and a role. Nothing is edited after the fact.

Data minimisation

On sync, each field from a tool is kept, hashed or dropped by rule before anything is admitted as evidence, and the sync shows which.

Runs you can replay

Every agent run has a transcript: what was read, what the model reasoned, what was written, with tokens and cost where a model was used.

See it on your own applications.Every figure in the platform opens to the records behind it, and every record to its evidence.
Sign in
CCMAccess is managed by your organisation’s identity provider.inventory · frameworks · monitoring · reporting