Skip to content

Compliance

We help you become compliant and we give you the evidence.

How the platform supports each framework, and what it hands the auditor.

Run the whole framework, not a spreadsheet.

The vCISO module of UASR takes a framework end to end: assess it, track it, and show where you are.

  • Assess it control by control

    Work through ISO/IEC 27001, NIS2 or whichever framework applies to you inside the platform, with the question, the answer and the evidence in one place.

  • Watch the number move

    Each framework has its own completion, tracked over time, so you show progress instead of describing it.

  • Answer once, count everywhere

    Controls overlap between frameworks. An answer given for one counts wherever it maps, so the next framework starts part-done.

See the governance layer of UASR

Framework by framework.

Each piece of evidence comes from one of the three products. Here is which one.

  • NIS2

    What it asks of you

    Risk measures, incident handling, access control, accountability.

    What you hand the auditor

    • A compliance score per control

      You show progress instead of describing it.

      Provided by UASR

    • Playbooks

      Ready before the bad day.

      Provided by UASR

    • Recorded privileged sessions

      Administrators go through the bastion, and every session is recorded.

      Provided by ZT-SSE

    • Secure administration

      Administration runs in its own sealed room, apart from e-mail and browsing.

      Provided by ZT-Station

  • DORA

    What it asks of you

    ICT risk, incident reporting, resilience, third-party risk.

    What you hand the auditor

    • Asset criticality and a dependency map

      Which assets you cannot afford to lose, and what they depend on.

      Provided by UASR

    • Decision logs

      Every access decision is logged.

      Provided by ZT-SSE

    • Rooms restored in minutes

      A compromised room is reset to known-good, not rebuilt.

      Provided by ZT-Station

  • LPM, OIV and ANSSI

    What it asks of you

    Secure administration, segregated admin flows, hardening.

    What you hand the auditor

    • The multi-level workstation architecture ANSSI recommends

      One laptop, several sealed rooms. ANSSI recommends the architecture.

      Provided by ZT-Station

    • An Active Directory audit against the ANSSI guide

      How weak your Active Directory is, and what to fix first.

      Provided by UASR

    • Bastion recordings

      Privileged sessions go through the bastion and are recorded.

      Provided by ZT-SSE

  • ISO/IEC 27001

    What it asks of you

    Security management controls, access, operations, suppliers, incidents.

    What you hand the auditor

    • A control-by-control assessment

      Assessed, tracked and exportable.

      Provided by UASR

    • Gaps tracked as issues

      A security programme, not a pile of findings.

      Provided by UASR

    • A complete audit trail

      Complete, and exportable when the auditor asks.

      Provided by UASR

  • CRA and GDPR

    What it asks of you

    Vulnerability handling and updates. Breach notification and data protection.

    What you hand the auditor

    • Vulnerability history

      What was found, and when.

      Provided by UASR

    • Patch reports

      Which machines are up to date, and which are not.

      Provided by UASR

    • Data-loss event history

      Sensitive data stopped in the browser, ranked by severity.

      Provided by UASR

    • CNIL notification templates

      Ready for the day a breach has to be notified.

      Provided by UASR

Mapped to NIST CSF 2.0.

The platform is mapped to the NIST Cybersecurity Framework 2.0, the vocabulary your auditors and regulators already use. UASR leads Govern, Identify and Protect. ZT-Station leads Protect and Recover. ZT-SSE leads Protect, Detect and Respond.

See the mapping, function by function

What the platform does.

We help you become compliant and we produce the evidence your auditors expect.

One score. One policy.
One trusted system.

Start with your Cyber Score. In two weeks you know where you stand and what to fix first.