Pillar 10 of 12

Mapped from the rules
that actually fired.

Compliance mappings are carried on the detection rules themselves. A control is covered because a rule mapped to it produced evidence in your estate, not because a vendor asserted coverage on a datasheet.

nullsoc.in / compliance / pci-dss
The NullSOC PCI DSS view: requirement coverage, findings by control and per host posture.

PCI DSS coverage computed from the rules that fired in your estate.

6
Frameworks
PCI DSS, NIST 800-53, HIPAA, GDPR, TSC and GPG13.
1
Source of truth
The mapping lives on the rule, beside the detection.
6
Framework reports
One designed PDF per framework, on a schedule.
0
Manual mapping
Nobody maintains a spreadsheet of control coverage.
Frameworks

One mapping block, six frameworks.

A rule carries its control identifiers for every framework at once. Import the ruleset and thousands of mappings arrive with it. Write your own rule and you add the controls it evidences in the same file, in four lines.

  • PCI DSS, NIST 800-53, HIPAA, GDPR, TSC and GPG13 each with their own view, catalogue and report.
  • Mappings arrive with the ruleset and are editable, because your interpretation of a control may differ.
  • One block feeds everything. The page, the framework report and the case timeline all read the same mapping.
  • Names in full. Controls are shown with their titles wherever the catalogue provides one, never as a bare code.
nullsoc.in / compliance / hipaa
The HIPAA view showing safeguard coverage, findings by control and per host posture.

The same engine, a different framework. Each view is real per framework data.

Evidence

Every control opens onto the findings behind it.

An auditor asks how you know. A control here is not a green tick: it resolves to the detections mapped to it, each with a timestamp, a host, the rule that fired and the original log line that caused it.

  • Control to findings. Open a requirement and see the detections that evidence it, with counts over the period.
  • Findings to raw. Each detection keeps the identifier of the exact line on the wire that produced it.
  • Configuration checks count too. CIS assessment results carry their own control mappings into the same views.
  • File integrity counts too. Change events carry the framework codes from the rule that caught them.
nullsoc.in / compliance / nist
The NIST 800-53 view with control family coverage and the findings mapped to each control.

NIST 800-53 by control family, resolving to the findings behind each one.

Posture

Coverage per control, and per host.

An organisation level percentage hides the one server that is failing everything. Each framework view breaks coverage down by host as well as by control, so you can see whether a gap is systemic or a single machine nobody has patched.

  • Per control coverage across the estate, with the trend over your chosen window.
  • Per host posture so a single unmanaged machine cannot hide behind a good average.
  • Honest gaps. A control with no mapped rule that fired shows as no evidence, not as passing.
  • Your time window. Coverage is computed over the period you select, not a fixed reporting month.
Frameworks covered
PCI DSSpayment card industry data security standard
NIST 800-53security and privacy controls
HIPAAsecurity rule safeguards
GDPRarticles relevant to processing security
TSCtrust services criteria, SOC 2
GPG13protective monitoring controls
Mapping sourcecarried on the detection rule
Evidencefindings, resolving to the raw line
Reportone designed PDF per framework
The report

A document you can actually hand over.

Each framework has its own designed report, built from the same live queries that draw the page. Cover, executive summary, control analysis, per host coverage and notable findings, as A4 PDF for reading and Excel for the underlying data.

  • Per framework, not generic. Each report returns that framework own controls and its own coverage.
  • Same queries as the page so the document and the screen cannot disagree about a number.
  • Scheduled delivery. Cron in your timezone, delivered to a channel with the PDF attached.
  • Branded to you. Logo, organisation name and accent colour are settings, not a support request.
nullsoc.in / reporting
The NullSOC reporting page with a report template card per pillar, including a compliance group.

A report per framework, generated from the same live queries as the views.

Get started

Bring the control you always
have to explain.

Name the requirement your auditor keeps asking about. We will show you which rules evidence it and what the report looks like.

Powered by Codesecure Solutions. Self hosted, cloud or fully managed.