Compliance
We help you become compliant and we give you the evidence.
How the platform supports each framework, and what it hands the auditor.
Run the whole framework, not a spreadsheet.
The vCISO module of UASR takes a framework end to end: assess it, track it, and show where you are.
Assess it control by control
Work through ISO/IEC 27001, NIS2 or whichever framework applies to you inside the platform, with the question, the answer and the evidence in one place.
Watch the number move
Each framework has its own completion, tracked over time, so you show progress instead of describing it.
Answer once, count everywhere
Controls overlap between frameworks. An answer given for one counts wherever it maps, so the next framework starts part-done.
Framework by framework.
Each piece of evidence comes from one of the three products. Here is which one.
- UASR
- ZT-StationNew
- ZT-SSENew
NIS2
What it asks of you
Risk measures, incident handling, access control, accountability.
What you hand the auditor
A compliance score per control
You show progress instead of describing it.
Provided by UASR
Playbooks
Ready before the bad day.
Provided by UASR
Recorded privileged sessions
Administrators go through the bastion, and every session is recorded.
Provided by ZT-SSE
Secure administration
Administration runs in its own sealed room, apart from e-mail and browsing.
Provided by ZT-Station
DORA
What it asks of you
ICT risk, incident reporting, resilience, third-party risk.
What you hand the auditor
Asset criticality and a dependency map
Which assets you cannot afford to lose, and what they depend on.
Provided by UASR
Decision logs
Every access decision is logged.
Provided by ZT-SSE
Rooms restored in minutes
A compromised room is reset to known-good, not rebuilt.
Provided by ZT-Station
LPM, OIV and ANSSI
What it asks of you
Secure administration, segregated admin flows, hardening.
What you hand the auditor
The multi-level workstation architecture ANSSI recommends
One laptop, several sealed rooms. ANSSI recommends the architecture.
Provided by ZT-Station
An Active Directory audit against the ANSSI guide
How weak your Active Directory is, and what to fix first.
Provided by UASR
Bastion recordings
Privileged sessions go through the bastion and are recorded.
Provided by ZT-SSE
ISO/IEC 27001
What it asks of you
Security management controls, access, operations, suppliers, incidents.
What you hand the auditor
A control-by-control assessment
Assessed, tracked and exportable.
Provided by UASR
Gaps tracked as issues
A security programme, not a pile of findings.
Provided by UASR
A complete audit trail
Complete, and exportable when the auditor asks.
Provided by UASR
CRA and GDPR
What it asks of you
Vulnerability handling and updates. Breach notification and data protection.
What you hand the auditor
Vulnerability history
What was found, and when.
Provided by UASR
Patch reports
Which machines are up to date, and which are not.
Provided by UASR
Data-loss event history
Sensitive data stopped in the browser, ranked by severity.
Provided by UASR
CNIL notification templates
Ready for the day a breach has to be notified.
Provided by UASR
Mapped to NIST CSF 2.0.
The platform is mapped to the NIST Cybersecurity Framework 2.0, the vocabulary your auditors and regulators already use. UASR leads Govern, Identify and Protect. ZT-Station leads Protect and Recover. ZT-SSE leads Protect, Detect and Respond.
See the mapping, function by functionWhat the platform does.
We help you become compliant and we produce the evidence your auditors expect.