Does JupiterOne's SOC2 automation have any manual processes?
Answers
-
Hi,
Great question. JupiterOne has automated evidence collection prebuilt for SOC2 Security, CIS AWS, CIS Azure, CIS GCP, and HIPAA compliance. If you use our prebuilt security controls, JupiterOne has pre-mapped the evidence collection questions to these standards/benchmarks.
These questions will run daily and collect compliance status. You may want to refine or tweak the questions if desired. You will need to manually upload evidence for the security controls that don't have a data source integrated to collect data from.
JupiterOne allows users to customize automation for any requirement. If you are using a framework not listed above or custom controls, you have to map the evidence to the controls/the controls to the compliance requirements.
If you use the "Add Evidence" button, you can select from "Add Question" which links a question that will automatically poll for the latest compliance status. You can use link control to link a pre-existing control that has evidence mapped to it already.
You an also upload or link to manual evidence.
Hope this helps!
-Akash1
This Month's Leaders
Categories
- 336 All Categories
- Featured Categories
- 7 About the AskJ1 Community
- 11 Product Announcements
- From Mission Control
- 1 Rapid Response
- 3 How J1 Uses J1
- Topics
- 131 Asset Management
- 56 Compliance & Reporting
- 65 Security Operations
- 40 Security Engineering
- 5 Open Source
- 18 News, Careers and More