Services / Audit and compliance
Governance and controlAn audit result is a backlog, not a file on a shelf
OpenVAS and CIS show configuration gaps. Wazuh gives an access audit trail and a baseline. Grafana and the cloud show whether a control works every day. We map this to ISO 27001, SOC 2, DORA, or KNF, with an owner and a close date.
Scan, audit trail, edge, and rhythm after the report
An audit without operations returns in a year with the same gaps. We put OpenVAS, Wazuh, the edge, and a dashboard into one remediation program.
- A report for the board and a list for engineering are two views of the same backlog.
- A CIS exception has an owner and a review date, not a forever status.
A scan that feeds a remediation queue
Greenbone OpenVAS, including authenticated scans. A result has CVSS, exposure, and an owner. A rescan after the patch. Critical gaps do not wait for a quarterly PDF.
Scope
Hosts, panels, databases, staging, and production. A separate policy for what is visible from the internet.
Priority
CVSS together with data and exposure. A public origin before a host with no inbound traffic.
Evidence
Closure is verification by scan, not a statement in email.
Rhythm
A standing cycle plus a scan after change. A report for the board and a list for engineering.
CIS and a change audit trail in one place
SCA shows drift against the benchmark. FIM and logs say who changed a file and when. This is material for access control and for a permissions review, not a separate script once a year.
CIS
A benchmark per system. An exception has a justification and a review date.
IAM
Accounts, keys, sudo, cloud roles. Dead accounts and excess permissions go to the backlog.
Audit trail
Deploy, login, group change. Who, when, from which source.
Evidence
Export for the auditor. Retention aligned with policy, not with disk space.
The edge is subject to control too
WAF, Access, and origin hiding are a control, not decoration. Audit checks what still listens on 0.0.0.0 and whether a panel entered through identity. Edge logs close the picture together with the host.
Surface
DNS, ports, panels, API. A list of what should be public, the rest behind Access or VPN.
Rules
WAF for the application. Exceptions documented. Rate limit on login and expensive endpoints.
Identity
Grafana, cloud, and staging through SSO. Short session, login log.
Gap
An origin exposed beside Cloudflare is a finding, not a network detail.
A control that works between audits
After the report a dashboard remains: backup, certificates, IAM failures, scan. The next audit starts from what was closed, not from zero. The 30, 60, and 90 day plan has a measurable state.
Posture
Cloud and on-prem: encryption, logs, public buckets, open SGs.
Trend
Number of open P1s, age of a gap, agent coverage. A chart for the board without a marketing slide.
Mapping
ISO 27001, SOC 2, DORA, KNF. Control in infrastructure, not only in policy.
People
Owner, deadline, escalation. The auditor gets evidence, engineering gets a work list.
From scope to a 90-day plan
First business context and critical systems. Then a scan and a permissions review. Finally a backlog and a verification rhythm.
- Scope Systems, data, regulation, RTO, who signs an exception.
- Collection Scan, CIS, IAM, edge, copies, logs.
- Report Risk, cost, order, evidence for the auditor.
- Closure Change windows, rescan, trend dashboard.
We will discuss the audit scope and the remediation plan
On that basis we will prepare a review, a backlog, and a verification rhythm.
Contact us