Skip to main content

Frameworks and controls

When you activate a framework, DSALTA automatically maps all relevant controls. Each framework area has criteria, and each criterion maps to specific controls. A single control can satisfy requirements across multiple frameworks.
A control shows “Needs attention” when some evidence exists but is incomplete — a test may have failed, a document is missing, or a policy is not yet approved. Click into the control to see exactly what is needed.
Audit readiness is the ratio of controls with complete evidence to total controls in your active framework. A control is “complete” when all required policies, documents, and tests are satisfied.

Policies

Yes. DSALTA uses AI to generate policies tailored to your company and activated frameworks. Customize any policy before approving. Every change is version-tracked.
Policies run on an annual cycle: approving a policy sets its next review date 365 days out. Once that date passes, the nightly Periodic review of policies completed system test fails and reports how many policies are overdue, and the controls that test backs stop passing. Watch that test for renewals — re-approving a policy counts as its review and resets the cycle for another year.

Audits

Go to Compliance → Audits → New Audit. The dialog asks for two things, both required: a framework from your active list, and your auditor’s email address. The audit belongs to whoever created it.
Auditors view evidence, controls, policies, documents, and test results. They can flag items, accept evidence, and leave comments. They cannot modify compliance data.
A failed test changes the control to “Needs attention.” Check the test detail for what failed. You can deactivate a non-applicable test — the auditor will see it was intentionally excluded.