Skip to content

Compliance

The Comply module allows organizations to define compliance frameworks, monitor compliance status in real time, and generate compliance reports for auditors. It provides a structured way to map regulatory requirements to audit log data, track whether those requirements are being met, and produce documented evidence of compliance activity.


Understanding compliance management:

The compliance module enables you to:

  • Define compliance frameworks such as GDPR, HIPAA, SOX, and PCI-DSS
  • Create compliance rules linked to specific audit events and operations
  • Monitor compliance status across all frameworks in real time
  • Generate compliance reports for auditors and stakeholders
  • Track compliance violations and remediation actions
  • Configure alerts for compliance violations

Accessing the Comply module:

  1. Log in to the LT Auditor MP web portal
  2. Navigate to Comply in the main navigation menu
  3. The Comply page displays:
    • Compliance Frameworks — high-level compliance categories
    • Compliance Rules — specific requirements within each framework
    • Compliance Status — overall compliance score
    • Recent Violations — recent non-compliant events

Creating a compliance framework:

Compliance frameworks group related compliance requirements under a single structure.

Requires appropriate permissions.

  1. Click Add Compliance Framework
  2. Configure the framework details:
Field Description
Name Framework name (e.g., GDPR Compliance, HIPAA)
Description Purpose and scope of the framework
Reference Code Standard identifier (e.g., GDPR-2016/679)
Category Industry or regulation type
Priority Critical, High, Medium, or Low
  1. Click Save

Creating compliance rules:

Compliance rules define specific requirements within a framework and how LT Auditor MP monitors them against collected audit data.

  1. Select a compliance framework
  2. Click Add Rule
  3. Configure the rule details:
Field Description
Rule Name The specific requirement (e.g., Access Logging Required)
Description Detailed explanation of the requirement
Reference The section or clause number from the framework
Severity Impact level if the rule is violated
  1. Link the rule to audit data:
Field Description
Environment Which environment this rule applies to
Category Which log category to monitor
Operations Which specific operations must be logged
Required Frequency How often events should occur
Alert Threshold When to trigger a compliance alert
  1. Define compliance criteria:
Criteria Type Description
Must Exist Certain events must be present in the audit data
Must Not Exist Certain events must never occur
Count Thresholds Minimum or maximum event counts required
Time Constraints Events must occur within defined timeframes
  1. Click Save

Linking reports to compliance rules:

Associate reports with compliance rules to automate evidence collection for audits:

  1. Open the compliance rule configuration
  2. Navigate to the Linked Reports tab
  3. Click Link Report
  4. Select one or more reports that provide evidence of compliance for this rule
  5. Click Save

Linking reports provides:

  • Automated compliance evidence collection
  • Audit-ready documentation
  • Trend analysis for compliance metrics over time

Monitoring compliance status:

  1. Navigate to the Compliance Dashboard
  2. Review key metrics:
Metric Description
Overall Compliance Score Percentage of rules currently met
Compliant Rules Rules currently satisfied
Non-Compliant Rules Rules with active violations
Pending Rules Rules awaiting validation
  1. Click into any framework to drill down into individual rule status
  2. Click a specific rule to view:
    • Compliance Status — Met, Violated, or Pending
    • Last Check — when the rule was last evaluated
    • Violation Count — number of violations detected
    • Evidence — links to supporting audit logs and reports

Compliance rule evaluation:

Compliance rules are evaluated against audit log data in three ways:

Scheduled evaluation:

  • Rules are evaluated automatically on a defined schedule (e.g., hourly, daily)
  • The system queries audit logs for evidence of compliance
  • Compliance status updates automatically after each evaluation

Real-time evaluation:

  • Critical rules can be evaluated in real time as events arrive
  • Violations trigger immediate alerts
  • Useful for security-critical compliance requirements

Manual evaluation:

  1. Navigate to a compliance rule
  2. Click Evaluate Now
  3. The system checks audit logs against the rule criteria immediately
  4. Compliance status updates and evaluation results are available instantly

Compliance alerts:

Configure notifications for compliance violations:

  1. Open a compliance rule configuration
  2. Navigate to the Alerts tab
  3. Click Add Alert
  4. Configure the alert settings:
Field Description
Trigger Condition When to send the alert
Recipients Email addresses or user groups to notify
Alert Frequency Immediate, Daily, or Weekly
Escalation Who to notify if the violation is not resolved
  1. Click Save

Generating compliance reports:

On-demand generation:

  1. Navigate to Comply → Reports
  2. Select the compliance framework
  3. Choose the time period to cover
  4. Select which rules to include:
    • All Rules
    • Non-Compliant Rules Only
    • Critical Rules
    • Custom Selection
  5. Click Generate Report
  6. Download in your preferred format:
    • PDF — for auditor submission
    • Excel — for detailed internal analysis
    • CSV — for data processing

Scheduling compliance reports:

  1. Navigate to Comply → Scheduled Reports
  2. Click Add Schedule
  3. Configure the schedule:
Field Description
Framework Which framework to report on
Frequency Weekly, Monthly, Quarterly, or Annually
Recipients Email addresses for report delivery
Format PDF, Excel, or CSV
  1. Click Save

Compliance report contents:

Generated compliance reports typically include:

Section Contents
Executive Summary Overall compliance score, rules met vs. violated, critical findings, trends
Framework Coverage All rules within the framework with compliance status and evidence references
Violations and Findings Non-compliant rules, violation timestamps, affected systems or users, severity
Supporting Evidence Links to audit logs, report references, timestamps and metadata
Remediation Status Actions taken, responsible parties, resolution timelines

Compliance audit log:

Track changes to compliance configurations:

  1. Navigate to Comply → Audit Log
  2. Review compliance-related activity:
    • Framework creation, updates, and deletions
    • Rule modifications
    • Report access history
    • Alert history
  3. Filter by date, user, or framework
  4. Export the audit trail for external auditors

Compliance dashboards:

Create customized compliance dashboards for different audiences:

  1. Navigate to Comply → Dashboards
  2. Click Create Dashboard
  3. Configure the dashboard name and layout
  4. Add widgets:
Widget Description
Compliance Score Gauge Overall compliance percentage
Rule Status Chart Pie chart of met vs. violated rules
Trend Graph Compliance score over time
Violation List Recent compliance violations
Framework Summary Status by framework
  1. Click Save
  2. Optionally set as the default compliance dashboard

Exporting compliance data:

  1. Navigate to the compliance section
  2. Select the data to export:
    • All frameworks and rules
    • Specific framework
    • Violation history
    • Compliance trends
  3. Click Export
  4. Choose format: CSV, Excel, or JSON
  5. Download the file

Supported compliance frameworks:

LT Auditor MP supports compliance monitoring for the following regulatory frameworks:

Framework Focus Areas
GDPR Data access logging, deletion tracking, consent management, breach notification
HIPAA Patient data access logs, PHI auditing, security incident tracking
SOX Financial system access, change management tracking, audit trail integrity
PCI-DSS Cardholder data access, network security monitoring, access control validation
ISO 27001 Security event monitoring, incident management, access control auditing
NIS 2 Network and information security requirements
NIST 171 Controlled unclassified information protection
DORA Digital operational resilience
FFIEC Financial institution security and audit requirements
FDIC Federal deposit insurance compliance requirements

Best practices:

  • Group related rules logically within each framework for easier navigation and auditing
  • Define clear measurable compliance criteria for each rule so compliance status is unambiguous
  • Always link reports to compliance rules to automate evidence collection
  • Schedule compliance reports in advance of known audit periods
  • Review rules regularly to ensure they reflect current regulatory requirements
  • Restrict compliance configuration access to authorized personnel only
  • Document remediation actions taken when violations are detected
  • Maintain compliance reports according to your organization’s regulatory retention requirements

[Your administrator should review all configured frameworks and rules prior to any external audit to confirm accuracy and completeness, and ensure the compliance audit log is retained as evidence of the compliance monitoring program.]