Control-based compliance reporting

Connect technical evidence to the controls it supports.

Cyobik maps collected technical and operational data to predefined CIS Benchmark, PCI DSS and ISO/IEC 27001 controls and reports results by asset, control and framework.

Supported frameworks

Predefined mappings, maintained with the product.

CIS

CIS Benchmarks

More than 1,598 controls across applicable products and asset types.

PCI DSS

Payment security controls

Map collected technical and operational data to applicable predefined PCI DSS controls.

ISO 27001

Information security controls

Map available evidence to applicable ISO/IEC 27001 controls within technical visibility.

Assessment statuses

Make the result and the evidence gap explicit.

StatusMeaningOperational value
CompliantAvailable evidence satisfies the mapped control logic.Supports traceable reporting at asset and control level.
Not CompliantAvailable evidence indicates the mapped requirement is not satisfied.Highlights technical control gaps and available remediation guidance.
Not ApplicableThe control does not apply to the evaluated asset or context.Prevents irrelevant controls from distorting results.
Insufficient DataCyobik does not have enough evidence to determine the result.Separates an evidence gap from an actual control failure.
Evidence reuse

One data point can support multiple controls.

Collected asset, configuration, vulnerability and operational data can contribute to multiple mapped controls or frameworks without being recollected for each report.

Review levelAsset
Review levelControl
Review levelFramework
GuidanceWhere available
Management reporting

Move from aggregate status to affected assets.

Use framework-level views for management reporting and drill down to the controls and assets producing each result.

Predefined mappingsMappings change through product updates rather than ad-hoc user editing.
Scheduled deliveryUse scheduled email reports for recurring review cycles.

Cyobik does not replace an organisational audit or certification process

Controls outside technical visibility are not evaluated automatically. Cyobik provides control-based technical evidence and reporting; governance, policy, human-process and certification activities remain outside the product’s automated scope.

Keep compliance evidence inside your controlled environment.

Review the deployment model, access controls, audit logging and update paths designed for security-sensitive organisations.

Deployment