Skip to content
Notifications
Clear all

ELI5: What exactly is a 'control' in Vanta, and why do I need so many?

1 Posts
1 Users
0 Reactions
2 Views
(@consulting_contractor_mike)
Estimable Member
Joined: 4 months ago
Posts: 123
Topic starter   [#2062]

A common point of confusion I see when teams first onboard with Vanta—or any GRC platform, for that matter—is the sheer volume of "controls" that suddenly appear. You connect your cloud accounts, SaaS tools, and HR systems, and suddenly you're looking at a dashboard demanding evidence for hundreds of items. The immediate reaction is often, "Is all this really necessary?"

Let's break down what a control actually is in this context. In simplest terms, a **control is a specific, verifiable requirement derived from a compliance framework** (like SOC 2, ISO 27001, HIPAA, or PCI DSS). It's not a vague principle like "be secure." It's a concrete, testable rule. Think of it as a question the auditor will ask: "Prove to me that you are doing X." Vanta's job is to automate the collection of evidence to answer that question.

For example, the SOC 2 framework includes the requirement (a "trust service criterion") that you "monitor system assets for anomalies." That's broad. Vanta breaks this down into granular controls, such as:
* **Control:** "MFA should be enabled for all administrative access to production systems."
* **Evidence:** Vanta automatically checks your identity provider (e.g., Okta, Google Workspace) and your cloud IAM (e.g., AWS IAM, Azure AD) to list all admin users and verifies MFA status.
* **Control:** "Unauthorized software should not be installed on company-managed endpoints."
* **Evidence:** Vanta integrates with your endpoint management tool (e.g., Jamf, Kandji, Intune) to pull a report of installed software and checks it against a blocklist.

So, why do you need *so many*? Three primary reasons:

1. **Frameworks are Comprehensive:** A standard like SOC 2 covers hundreds of discrete requirements across security, availability, processing integrity, confidentiality, and privacy. Each requirement must be mapped to one or more technical or procedural controls.
2. **Evidence Needs Specificity:** You cannot prove "we monitor for anomalies" with one piece of evidence. You need evidence for log aggregation, for alert configuration, for access reviews, for vulnerability scanning, etc. Each evidence source is often tied to a unique control.
3. **Vanta's Automation Granularity:** To maximize automated evidence collection, Vanta creates highly specific controls aligned with individual API endpoints or configuration checks. A single human resources policy might spawn separate controls for "employee onboarding checklist exists," "offboarding checklist exists," and "policy is reviewed annually," because each can be checked and evidenced differently.

The initial overwhelm is normal. The key is to not view them as individual, manual tasks. Your goal should be to configure the underlying integrations correctly—secure your cloud infrastructure, enforce endpoint policies, formalize HR workflows—so that Vanta can automatically satisfy the controls for you. The controls are merely the measurable output of your secure system. Start by focusing on the critical, high-risk controls (often highlighted as failing) and work backward to fix the root cause in your environment, not just in Vanta.

- Mike


Mike


   
Quote