Services / Audit and compliance

Governance and control

An audit result is a backlog, not a file on a shelf

OpenVAS and CIS show configuration gaps. Wazuh gives an access audit trail and a baseline. Grafana and the cloud show whether a control works every day. We map this to ISO 27001, SOC 2, DORA, or KNF, with an owner and a close date.

Backlog A finding with an owner, a deadline, and verification
CIS A configuration baseline, with a justified exception
30/60/90 A close plan, visible to the board
Evidence An audit trail for ISO, SOC 2, DORA, or KNF
How it fits together

Scan, audit trail, edge, and rhythm after the report

An audit without operations returns in a year with the same gaps. We put OpenVAS, Wazuh, the edge, and a dashboard into one remediation program.

  • A report for the board and a list for engineering are two views of the same backlog.
  • A CIS exception has an owner and a review date, not a forever status.
Greenbone OpenVAS, scan dashboard, CVE and NVT
01, OpenVAS

A scan that feeds a remediation queue

Greenbone OpenVAS, including authenticated scans. A result has CVSS, exposure, and an owner. A rescan after the patch. Critical gaps do not wait for a quarterly PDF.

Scope

Hosts, panels, databases, staging, and production. A separate policy for what is visible from the internet.

Priority

CVSS together with data and exposure. A public origin before a host with no inbound traffic.

Evidence

Closure is verification by scan, not a statement in email.

Rhythm

A standing cycle plus a scan after change. A report for the board and a list for engineering.

Wazuh console, Debian endpoint, MITRE, SCA and vulnerabilities
02, Wazuh

CIS and a change audit trail in one place

SCA shows drift against the benchmark. FIM and logs say who changed a file and when. This is material for access control and for a permissions review, not a separate script once a year.

CIS

A benchmark per system. An exception has a justification and a review date.

IAM

Accounts, keys, sudo, cloud roles. Dead accounts and excess permissions go to the backlog.

Audit trail

Deploy, login, group change. Who, when, from which source.

Evidence

Export for the auditor. Retention aligned with policy, not with disk space.

Cloudflare Security Analytics, bot score, WAF and request log
03, Cloudflare

The edge is subject to control too

WAF, Access, and origin hiding are a control, not decoration. Audit checks what still listens on 0.0.0.0 and whether a panel entered through identity. Edge logs close the picture together with the host.

Surface

DNS, ports, panels, API. A list of what should be public, the rest behind Access or VPN.

Rules

WAF for the application. Exceptions documented. Rate limit on login and expensive endpoints.

Identity

Grafana, cloud, and staging through SSO. Short session, login log.

Gap

An origin exposed beside Cloudflare is a finding, not a network detail.

Grafana, dashboard catalog and data sources
04, Grafana

A control that works between audits

After the report a dashboard remains: backup, certificates, IAM failures, scan. The next audit starts from what was closed, not from zero. The 30, 60, and 90 day plan has a measurable state.

Posture

Cloud and on-prem: encryption, logs, public buckets, open SGs.

Trend

Number of open P1s, age of a gap, agent coverage. A chart for the board without a marketing slide.

Mapping

ISO 27001, SOC 2, DORA, KNF. Control in infrastructure, not only in policy.

People

Owner, deadline, escalation. The auditor gets evidence, engineering gets a work list.

Operations

From scope to a 90-day plan

First business context and critical systems. Then a scan and a permissions review. Finally a backlog and a verification rhythm.

  1. Scope Systems, data, regulation, RTO, who signs an exception.
  2. Collection Scan, CIS, IAM, edge, copies, logs.
  3. Report Risk, cost, order, evidence for the auditor.
  4. Closure Change windows, rescan, trend dashboard.
Talk

We will discuss the audit scope and the remediation plan

On that basis we will prepare a review, a backlog, and a verification rhythm.

Contact us