Compliance assessment | Firemind
Compliance assessment

How far you are from the standard.As a cadence, not an annual audit.

Your estate assessed against the frameworks you choose and your own standards, with every exception carrying a remediation path.

CIS Benchmarks
SOC 2 Trust Services Criteria
NIST CSF 2.0
AWS Well-Architected, six pillars
Your own standards
No changes on production
The problem

Compliance is usually measured once a year, against a snapshot that is out of date by the time the report is read.

It is measured by people, and the estate has moved on before the findings are actioned.

The IT Operations Engine assesses the estate against the frameworks you choose and your own standards, on a cadence, and gives every exception a remediation path.

What a compliance report has to do

  • Score each control, and say plainly what is implemented, what is an exception, and what needs a human to judge
  • Gather the evidence read-only, across identity, encryption, backup, logging, monitoring, networking and tagging
  • Give every exception a remediation path rather than leaving it as a line in a table
  • Run again, so the second report shows a trend rather than repeating the first
  • Leave production untouched while it does all of it
What we do

Your frameworks, your standards, on a cadence.

The engine assesses accounts against external frameworks and against your own standards, ingested as a skill and applied the same way. Where a fix is a configuration change it makes it under your authority model. Where it is a code change, it raises the pull request.

CIS Benchmarks
SOC 2
NIST CSF 2.0
Well-Architected
Your own standards

Find, fix, keep green

    • Find - The engine assesses accounts against external frameworks (CIS Benchmarks, SOC 2 Trust Services Criteria, NIST CSF 2.0), against the AWS Well-Architected Framework across all six pillars, and against your own standards ingested as a skill. Each report gathers read-only evidence across identity, encryption, backup, logging, monitoring, networking and tagging, scores each control, and states what is implemented, what is an exception, and what needs a human to judge. On production accounts it makes no changes.
    • Fix - Every exception carries a remediation path. Where the fix is a configuration change the engine makes it under your authority model. Where it is a code change, such as bringing resources into line with your tagging standard, it raises the pull request.
    • Keep green - Assessment runs as a cadence. The second report is what turns findings into a trend, and the trend is what your auditors and your board actually want.

Want to see the shape of the report first?

One framework, three accounts, read-only. Enough to judge it before it runs estate-wide.

Scope a pilot →
How it starts

One framework. Three accounts. Read-only.

Enough to show the shape of the report before it runs estate-wide.

  • Choose one framework

    An external framework, or your own internal standard ingested as a skill and applied the same way.

    • CIS Benchmarks, SOC 2 or NIST CSF 2.0
    • AWS Well-Architected across all six pillars
    • Or your own standard, ingested as a skill
  • Three accounts, read-only

    Evidence gathered across identity, encryption, backup, logging, monitoring, networking and tagging. Each control scored. On production accounts, no changes are made.

    • Implemented, exception, or needs a human to judge
    • Evidence gathered read-only
    • Production accounts untouched
  • Then a cadence

    Every exception carries a remediation path, and the assessment runs again. The second report is what turns findings into a trend.

    • Configuration fixes under your authority model
    • Code fixes raised as pull requests
    • A trend your auditors and board can use
What stays with you

Preventing a non-compliant resource from being created is an organisation-level control.

A tag policy or a service control policy. We write it with you as a pull request. It stays yours.

You gain:

  • Your own internal standard can be ingested as a skill and applied the same way as an external framework.
  • On production accounts the assessment makes no changes at all.
  • Controls that need a human to judge are named as such rather than scored automatically.

FAQ

Questions.

Yes. Your standard is ingested as a skill and applied the same way as an external framework.

Start with one framework and three accounts.

Read-only, enough to show the shape of the report before it runs estate-wide. Every exception comes with a remediation path.

Your benefits:

  • Your frameworks - external standards, or your own as a skill.
  • Read-only evidence - no changes on production accounts.
  • Every exception - carries a remediation path.
  • A cadence - so the second report shows the trend.

What happens next?

Talk.

A focused discussion about the standard you are held to and by whom.

Assess.

One framework, three accounts, read-only.

Repeat.

Remediation paths worked through, and the assessment run as a cadence.

No obligation. Just a focused discussion about the standard you have to meet.

We'll only use your details to respond to your enquiry. No newsletters unless you ask for them.