# DSALTA Help Center ## Guides ### Getting Started - [Welcome to DSALTA](https://help.dsalta.com/guides/getting-started/welcome.md): Everything you need to manage compliance frameworks, controls, and evidence in one place. - [Key Concepts](https://help.dsalta.com/guides/getting-started/key-concepts.md): Understand the core building blocks of DSALTA: frameworks, controls, policies, documents, tests, and evidence. - [Onboarding Roadmap](https://help.dsalta.com/guides/getting-started/onboarding-roadmap.md): Follow the guided setup to configure your compliance program step by step. - [Dashboard](https://help.dsalta.com/guides/dashboard/overview.md): Your compliance command center — track framework progress, tasks, vendor risk, and audit readiness at a glance. - [My Tasks](https://help.dsalta.com/guides/tasks/my-tasks.md): Manage all compliance tasks assigned to you, organized by urgency and SLA. ### Compliance #### Frameworks - [Active Frameworks](https://help.dsalta.com/guides/compliance/frameworks-active.md): View and manage the compliance frameworks your organization has activated. - [Available Frameworks](https://help.dsalta.com/guides/compliance/frameworks-available.md): Browse and activate from the 44 supported compliance frameworks. - [Framework Detail](https://help.dsalta.com/guides/compliance/framework-detail.md): Explore areas, criteria, controls, and readiness metrics for any active framework. #### Controls - [Controls](https://help.dsalta.com/guides/compliance/controls.md): View and manage all compliance controls across your active frameworks. - [Control Detail](https://help.dsalta.com/guides/compliance/control-detail.md): View evidence, monitoring, risk scenarios, and cross-framework mappings for any control. #### Tests - [Tests](https://help.dsalta.com/guides/compliance/tests.md): View and manage the automated compliance tests that run against your connected integrations and your DSALTA workspace. - [Test Detail](https://help.dsalta.com/guides/compliance/test-detail.md): View test results, source data, historical runs, and remediation guidance. - [Understanding Test Results](https://help.dsalta.com/guides/compliance/test-results.md): What Completed, Failed and the Source Data result codes actually tell you about your compliance posture. #### Policies - [Policies](https://help.dsalta.com/guides/compliance/policies.md): Create, approve, assign, and track acceptance of your organization's security and compliance policies. - [Policy Detail](https://help.dsalta.com/guides/compliance/policy-detail.md): View, edit, approve, and manage individual policy documents. #### Documents - [Documents](https://help.dsalta.com/guides/compliance/documents.md): Upload, organize, and manage compliance evidence documents in one central location. #### Audits - [Audits](https://help.dsalta.com/guides/compliance/audits.md): Create, manage, and track compliance audits from start to completion. - [Audit Evidence](https://help.dsalta.com/guides/compliance/audit-evidence.md): Review, manage, and approve evidence submissions during a compliance audit. - [Audit Controls](https://help.dsalta.com/guides/compliance/audit-controls.md): Track control coverage and compliance readiness during an audit. ### People - [People](https://help.dsalta.com/guides/people/directory.md): Manage your employee directory, policy acceptances, training completion, and group-based task assignments. - [Training](https://help.dsalta.com/guides/people/training.md): Assign, track, and evidence security awareness training across your organization. - [Devices](https://help.dsalta.com/guides/people/devices.md): Track employee device compliance — encryption, screen lock, OS updates, and security agent enrollment. - [Access accounts](https://help.dsalta.com/guides/people/access-accounts.md): Run periodic access reviews across all connected systems to verify who has access to what. #### Device agent - [What Is Device Management?](https://help.dsalta.com/guides/people/device-agent/overview.md): How DSALTA Device Management continuously monitors employee devices, enforces security controls, and turns endpoint posture into audit-ready evidence. - [How Device Management Works](https://help.dsalta.com/guides/people/device-agent/how-it-works.md): The end-to-end Device Management flow — enrollment, secure activation, continuous monitoring, status evaluation, and re-checking after a fix. - [What Data Is Collected](https://help.dsalta.com/guides/people/device-agent/data-collected.md): Exactly what DSALTA Device Management collects from an employee device, which security signals are monitored, and what is never accessed or stored. - [Fix Failed Device Checks](https://help.dsalta.com/guides/people/device-agent/fix-failed-checks.md): Step-by-step remediation for each failing DSALTA device check on Windows, macOS and Linux — disk encryption, antivirus, screen lock and password manager. ### Assets - [Inventory](https://help.dsalta.com/guides/assets/inventory.md): Track all assets in your environment — servers, databases, applications, repositories, and SaaS tools. - [Vulnerabilities](https://help.dsalta.com/guides/assets/vulnerabilities.md): Track, assess, and remediate security vulnerabilities across your infrastructure and code. - [Code Changes](https://help.dsalta.com/guides/assets/code-changes.md): Read-only evidence feed from code repositories — proves code review compliance for auditors. - [Changes](https://help.dsalta.com/guides/assets/changes.md): Track infrastructure and application changes with approval workflows and full audit trails. ### Risk - [Risk Register](https://help.dsalta.com/guides/risk/register.md): Identify, assess, and track risks across your organization with a centralized risk register. - [Risk Library](https://help.dsalta.com/guides/risk/library.md): Browse pre-built risk templates to quickly populate your risk register. - [Incidents](https://help.dsalta.com/guides/risk/incidents.md): Track, investigate, and resolve security incidents with a full audit trail. ### Vendors - [Vendor Executive Summary](https://help.dsalta.com/guides/vendors/executive-summary.md): High-level overview of your vendor risk portfolio — scores, distribution, and trends. - [Vendor List](https://help.dsalta.com/guides/vendors/vendor-list.md): Add, classify, and manage all third-party vendors in your compliance program. - [Vendor Summary](https://help.dsalta.com/guides/vendors/vendor-summary.md): AI-powered overview of a vendor's security posture, certifications, and risk score. - [Vendor Risk History](https://help.dsalta.com/guides/vendors/risk-history.md): Track security findings, severity trends, and remediation progress over time. - [Vendor Risk Assessment](https://help.dsalta.com/guides/vendors/risk-assessment.md): AI-powered detailed risk evaluation including security policies, data protection, and operational resilience. - [Fourth Parties](https://help.dsalta.com/guides/vendors/fourth-parties.md): Track the technology providers and services your vendors depend on. - [Vendor Remediations](https://help.dsalta.com/guides/vendors/remediations.md): Create, track, and manage remediation requests sent to vendors. - [Vendor Questionnaires](https://help.dsalta.com/guides/vendors/questionnaires.md): Send, manage, and track security questionnaires to assess vendor compliance. ### Trust Center - [Trust Center Overview](https://help.dsalta.com/guides/trust-center/overview.md): Showcase your security and compliance posture to customers with a customizable public page. - [Access Requests](https://help.dsalta.com/guides/trust-center/access-requests.md): Manage customer requests to view your Trust Center documents and resources. - [Trust Center Questionnaires](https://help.dsalta.com/guides/trust-center/questionnaires.md): Answer customer security questionnaires using AI-powered responses and a reusable knowledge base. - [Trust Center Settings](https://help.dsalta.com/guides/trust-center/settings.md): Configure your custom domain, SSL, and branding for the Trust Center. ### Academy - [DSALTA Academy](https://help.dsalta.com/guides/academy/overview.md): Learn about compliance concepts, platform features, and best practices. ### Settings - [My Profile](https://help.dsalta.com/guides/settings/my-profile.md): Update your name, password, and account preferences. - [Team Members](https://help.dsalta.com/guides/settings/members.md): Invite team members, assign roles, and manage access to your DSALTA workspace. - [Roles & Permissions](https://help.dsalta.com/guides/settings/roles-and-permissions.md): Understand the four predefined roles and their permission levels. - [Security Roles](https://help.dsalta.com/guides/settings/security-roles.md): Assign organizational compliance roles like InfoSec Officer, Privacy Officer, and People Ops. - [Company Information](https://help.dsalta.com/guides/settings/company-information.md): Set up your company profile for compliance documentation and Trust Center display. - [Workspace Settings](https://help.dsalta.com/guides/settings/workspace.md): Manage your DSALTA workspace settings, including how to permanently delete a workspace and all associated compliance data. - [Product / Service Profile](https://help.dsalta.com/guides/settings/product-service.md): Configure your product or service details for your Trust Center and compliance documentation. - [Security & Legal URLs](https://help.dsalta.com/guides/settings/security.md): Configure your privacy policy, terms of service, and security contact information. - [Notifications](https://help.dsalta.com/guides/settings/notifications.md): Control which alerts and emails you receive from DSALTA. - [Compliance Frameworks (Settings)](https://help.dsalta.com/guides/settings/compliance-frameworks.md): Activate or deactivate compliance frameworks from the Settings page. - [Vendor Risk Settings](https://help.dsalta.com/guides/settings/vendor-risk-management.md): Configure vendor tiers, portfolios, and risk management preferences. - [Integrations (Settings)](https://help.dsalta.com/guides/settings/integrations.md): Manage connected integrations from the Settings page. ### FAQs - [General FAQ](https://help.dsalta.com/guides/faq/general.md): Answers to the most common questions about DSALTA. - [Compliance FAQ](https://help.dsalta.com/guides/faq/compliance.md): Answers to common compliance and audit-related questions. - [Pricing FAQ](https://help.dsalta.com/guides/faq/pricing.md): Answers to questions about DSALTA pricing and plans. ### Changelog - [Changelog](https://help.dsalta.com/changelog.md): Stay up to date with the latest features, improvements, and changes to DSALTA. - [Integrations (587 pages)](https://help.dsalta.com/_llms/integrations.md): Documentation for Integrations. ## Compliance Tests ### Overview - [Compliance tests](https://help.dsalta.com/tests/overview.md): Every automated check DSALTA runs, what it looks at, and how to fix a failure. ### Checks across integrations - [All change tickets should have an assignee](https://help.dsalta.com/tests/all-change-tickets-should-have-an-assignee.md): Checks that all change tickets have an assignee. - [At least one change management system should be connected](https://help.dsalta.com/tests/at-least-one-change-management-system-should-be-connected.md): Checks that at least one change management system is connected. - [Branch Protection rules should be enforced for admins](https://help.dsalta.com/tests/branch-protection-rules-should-be-enforced-for-admins.md): Flags minimum-reviewer policies that are not marked as blocking. - [Branch protection should be enabled on repositories](https://help.dsalta.com/tests/branch-protection-should-be-enabled-on-repositories.md): Checks that branch restrictions exist on repositories. - [Change request ticket should be resolved within 30 days](https://help.dsalta.com/tests/change-request-tickets-should-be-resolved-within-30-days.md): Checks that change request tickets are resolved within 30 days. - [Code changes should be reviewed by peers before merging](https://help.dsalta.com/tests/code-changes-should-be-reviewed-by-peers-before-merging.md): Mirrors peer-review policy enforcement on default branches. - [Code repo should be classified](https://help.dsalta.com/tests/code-repositories-should-be-classified.md): Ensures Git repositories are not left in generic/default project layouts without distinct naming. - [Infra entity should be classified](https://help.dsalta.com/tests/infrastructure-entities-should-be-classified.md): Infrastructure entities should have classification. - [Merging of code changes should require passing status-checks](https://help.dsalta.com/tests/merging-code-changes-should-require-passing-status-checks.md): Ensures merges require green pipelines / status checks. - [MFA should be enabled for all users](https://help.dsalta.com/tests/mfa-should-be-enabled-for-all-users.md): Checks that MFA is enabled for all users. - [Offboarded users should not have active access](https://help.dsalta.com/tests/offboarded-users-should-not-have-active-access.md): Checks that offboarded employees no longer have active access. - [Password policy should meet minimum requirements](https://help.dsalta.com/tests/password-policy-should-meet-minimum-requirements.md): Checks that the password policy meets minimum security requirements. - [Peer review should be enforced for code changes](https://help.dsalta.com/tests/peer-review-should-be-enforced-for-code-changes.md): Checks approvals or CODEOWNERS-backed review gates before merges. - [Reported incident should be closed](https://help.dsalta.com/tests/reported-incidents-should-be-closed.md): Checks that incidents reported in are resolved and closed. - [Ticketing system for change management should be setup](https://help.dsalta.com/tests/ticketing-system-for-change-management-should-be-configured.md): Checks that a ticketing system for change management is set up. - [User access to Critical System should be valid](https://help.dsalta.com/tests/user-access-to-critical-system-should-be-valid.md): Checks that everyone with access is an active employee on the People page. ## Framework Guides ### Security & Trust - [SOC 2](https://help.dsalta.com/frameworks/soc2/overview.md): Achieve SOC 2 compliance with automated controls, evidence collection, and audit preparation. - [ISO 27001:2022](https://help.dsalta.com/frameworks/iso27001/overview.md): Implement and certify your Information Security Management System (ISMS) with DSALTA. - [ISO 27701:2019](https://help.dsalta.com/frameworks/iso27701/overview.md): Extend your ISMS to a Privacy Information Management System (PIMS) for managing PII. - [ISO 27017:2015](https://help.dsalta.com/frameworks/iso27017/overview.md): Apply cloud-specific security controls as an extension to ISO 27001. - [ISO 27018:2019](https://help.dsalta.com/frameworks/iso27018/overview.md): Protect personally identifiable information (PII) in public cloud environments. - [HITRUST CSF](https://help.dsalta.com/frameworks/hitrust/overview.md): Achieve HITRUST certification with a comprehensive, risk-based security framework. - [CSA STAR](https://help.dsalta.com/frameworks/csa-star/overview.md): Demonstrate cloud security assurance with the Cloud Security Alliance STAR program. - [Cyber Essentials](https://help.dsalta.com/frameworks/cyber-essentials/overview.md): Achieve the UK government-backed baseline for cyber hygiene. - [Cyber Essentials Plus](https://help.dsalta.com/frameworks/cyber-essentials-plus/overview.md): Validate your cyber hygiene with a hands-on independent technical audit. ### NIST & CIS - [NIST CSF v2.0](https://help.dsalta.com/frameworks/nist-csf-v2/overview.md): Manage and reduce cybersecurity risk with the NIST Cybersecurity Framework version 2.0. - [NIST CSF](https://help.dsalta.com/frameworks/nist-csf/overview.md): Implement the original NIST Cybersecurity Framework (v1.1) across five core functions. - [NIST 800-171](https://help.dsalta.com/frameworks/nist-800-171/overview.md): Protect Controlled Unclassified Information (CUI) for US government contractors. - [CIS Controls v8.1](https://help.dsalta.com/frameworks/cis-v8/overview.md): Implement prioritized cybersecurity best practices with the CIS Controls framework. - [CIS Controls v8.0](https://help.dsalta.com/frameworks/cis-v8-0/overview.md): Implement the prior version of the CIS Critical Security Controls. - [FIPS 140-3](https://help.dsalta.com/frameworks/fips-140-3/overview.md): Validate cryptographic modules against US federal security requirements. ### Privacy & Data Protection - [GDPR](https://help.dsalta.com/frameworks/gdpr/overview.md): Meet EU data protection requirements with automated privacy controls and evidence collection. - [UK GDPR](https://help.dsalta.com/frameworks/uk-gdpr/overview.md): Comply with the United Kingdom's data protection regime following Brexit. - [HIPAA](https://help.dsalta.com/frameworks/hipaa/overview.md): Protect healthcare data with HIPAA-compliant administrative, physical, and technical safeguards. - [PIPEDA](https://help.dsalta.com/frameworks/pipeda/overview.md): Comply with Canada's federal private-sector privacy law. - [US Data Privacy](https://help.dsalta.com/frameworks/us-data-privacy/overview.md): Comply with US state data privacy regulations including CCPA, CPRA, and emerging state laws. - [US FERPA](https://help.dsalta.com/frameworks/ferpa/overview.md): Protect the privacy of student education records under US federal law. - [Tennessee Information Protection Act](https://help.dsalta.com/frameworks/tipa/overview.md): Comply with Tennessee's consumer data privacy law. - [Microsoft SSPA](https://help.dsalta.com/frameworks/microsoft-sspa/overview.md): Meet Microsoft's Supplier Security and Privacy Assurance requirements. ### Payment Security - [PCI DSS](https://help.dsalta.com/frameworks/pcidss/overview.md): Secure payment card data with PCI DSS controls for both version 3.2.1 and 4.0.1. ### AI Governance - [NIST AI RMF](https://help.dsalta.com/frameworks/nist-ai-rmf/overview.md): Manage AI system risks with the NIST AI Risk Management Framework. - [ISO 42001:2023](https://help.dsalta.com/frameworks/iso42001/overview.md): Establish an AI Management System (AIMS) for responsible AI development and deployment. - [EU AI Act](https://help.dsalta.com/frameworks/eu-ai-act/overview.md): Comply with the world's first comprehensive AI regulation — risk classification, transparency, and governance. - [Colorado AI Act](https://help.dsalta.com/frameworks/colorado-ai-act/overview.md): Comply with Colorado's law governing high-risk artificial intelligence systems. - [AIUC-1](https://help.dsalta.com/frameworks/aiuc-1/overview.md): Demonstrate trustworthy AI agent security and governance with the AIUC-1 standard. ### US Government - [US FedRAMP](https://help.dsalta.com/frameworks/fedramp/overview.md): Achieve Federal Risk and Authorization Management Program authorization for US government cloud services. - [TX-RAMP](https://help.dsalta.com/frameworks/tx-ramp/overview.md): Achieve Texas Risk and Authorization Management Program certification for state agencies. - [CMMC v2.0](https://help.dsalta.com/frameworks/cmmc/overview.md): Achieve Cybersecurity Maturity Model Certification for the US defense supply chain. ### EU Regulations - [DORA](https://help.dsalta.com/frameworks/dora/overview.md): Achieve Digital Operational Resilience for financial entities under the EU's DORA regulation. - [NIS 2](https://help.dsalta.com/frameworks/nis2/overview.md): Meet the EU's expanded cybersecurity requirements for essential and important entities. - [EU Cyber Resilience Act](https://help.dsalta.com/frameworks/eu-cra/overview.md): Meet EU cybersecurity requirements for products with digital elements. ### Financial Services - [Title 23 NYCRR Part 500](https://help.dsalta.com/frameworks/nycrr500/overview.md): Meet New York's cybersecurity requirements for financial services companies. - [APRA CPS 234](https://help.dsalta.com/frameworks/apra-cps234/overview.md): Meet Australian prudential information security requirements for regulated financial entities. - [US SOX](https://help.dsalta.com/frameworks/us-sox/overview.md): Meet Sarbanes-Oxley requirements for internal control over financial reporting. - [COSO](https://help.dsalta.com/frameworks/coso/overview.md): Implement the COSO Internal Control–Integrated Framework. - [SAMA Cyber Security Framework](https://help.dsalta.com/frameworks/sama-csf/overview.md): Comply with the Saudi Central Bank's cybersecurity framework for financial institutions. - [RBI SAR (Data Localization)](https://help.dsalta.com/frameworks/rbi-sar/overview.md): Meet the Reserve Bank of India's data localization and security requirements. - [IFSCA Cyber Security Guidelines](https://help.dsalta.com/frameworks/ifsca/overview.md): Meet the cybersecurity requirements of India's International Financial Services Centres Authority. - [SEBI CSCRF](https://help.dsalta.com/frameworks/sebi-cscrf/overview.md): Meet the Securities and Exchange Board of India's Cyber Security and Cyber Resilience Framework. ### Industry Specific - [TISAX](https://help.dsalta.com/frameworks/tisax/overview.md): Achieve automotive industry information security certification through TISAX assessment. - [ISO 9001](https://help.dsalta.com/frameworks/iso9001/overview.md): Implement a Quality Management System (QMS) to demonstrate consistent product and service quality. - [ISO 22301:2019](https://help.dsalta.com/frameworks/iso22301/overview.md): Build organizational resilience with a Business Continuity Management System (BCMS). - [21 CFR Part 11](https://help.dsalta.com/frameworks/21-cfr-part-11/overview.md): Meet FDA requirements for electronic records and electronic signatures. ## Troubleshooting ### Common Issues - [Integration Errors](https://help.dsalta.com/troubleshooting/integration-errors.md): Fix common issues with connecting and syncing integrations. - [Connection error messages](https://help.dsalta.com/troubleshooting/connection-error-messages.md): Every message DSALTA shows when a connection fails, what it actually means, and what to do. - [Evidence Not Syncing](https://help.dsalta.com/troubleshooting/evidence-not-syncing.md): Troubleshoot automated evidence collection issues. - [Audit Issues](https://help.dsalta.com/troubleshooting/audit-issues.md): Troubleshoot common audit problems including auditor login, document access, comments, and evidence export. - [Trust Center Issues](https://help.dsalta.com/troubleshooting/trust-center-issues.md): Fix problems with your Trust Center display, access, or custom domain. - [Login & Access Issues](https://help.dsalta.com/troubleshooting/login-and-access.md): Resolve sign-in problems, password resets, and access errors. ### Contact - [Contact Support](https://help.dsalta.com/troubleshooting/contact-us.md): Get in touch with the DSALTA support team via email or book a one-on-one session for onboarding and troubleshooting help. > The links below point to documentation indexes. Follow each `/_llms/` index recursively until you reach documentation pages. ## Indexes - [Integrations (587 pages)](https://help.dsalta.com/_llms/integrations.md): Documentation for Integrations. - [Integrations / Cloud Infrastructure (193 pages)](https://help.dsalta.com/_llms/integrations/cloud-infrastructure.md): Documentation for Integrations / Cloud Infrastructure.