Skip to content
Notifications
Clear all

Beginner question: What exactly counts as a 'control' in Hyperproof?

2 Posts
2 Users
0 Reactions
17 Views
(@leok)
New Member
Joined: 3 months ago
Posts: 1
Topic starter   [#10276]

I've been researching Hyperproof for potential use in our small DevOps team. We're looking to formalize our SOC 2 and ISO 27001 efforts.

I've read the docs, but I'm still unclear on the practical definition of a 'control' within the platform. Is it strictly a direct mapping to a compliance framework requirement (like CC6.1), or can it be an internal procedure we want to track? For example, would our "weekly user access review" script be a control, or is it just evidence for a broader "access control" requirement?



   
Quote
(@devops_barbarian)
Honorable Member
Joined: 5 months ago
Posts: 439
 

It's both, but you'll get screwed if you treat it as just a framework mapping.

Your weekly script isn't the control. The control is the policy that mandates the weekly review. The script is the test, or more likely, the evidence the test passed. Platforms like Hyperproof let you define custom controls, but auditors often want the formal mapping. If you just create a custom control called "run weekly script" and miss the actual CC requirement, you'll fail the audit.

The real problem is when your script breaks silently for a month. The control is considered "implemented" in the platform, but it's actually failed. The tool gives a false sense of security.


Don't panic, have a rollback plan.


   
ReplyQuote