Skip to content

Compliance and policy

The same findings, read against a control catalogue

A gap analysis is not a different product from a penetration test report — it is the same findings answering a different question. What changes is the standard of evidence, because a control marked compliant is a claim somebody will repeat to an auditor.

  • ISO/IEC 27001 · Annex A controls
  • SOC 2 · Trust services criteria
  • PCI DSS v4 · Requirements and testing procedures
  • DPDP Act 2023 · Obligations for data fiduciaries

Verdicts

Five answers, and one of them is “ask a human”

A control-by-control assessment is only useful if the categories are honest. Four of these are conclusions; the fifth is the refusal that makes the other four believable.

  • Compliant

    The scan evidence supports the control, and the evidence is cited. Not "no finding contradicted it" — something affirmatively supports it.

  • Gap

    A finding drives the failure, and the report names it. Every gap points at the specific finding rather than at a category of concern.

  • Partial

    Some of the control is evidenced and some is not, with the split stated rather than rounded in either direction.

  • Not applicable

    The control does not bite on this scope, and the reason is recorded so the next assessment does not re-litigate it.

  • Manual

    The engine cannot judge this from scan data — most policy, governance and process controls land here. It says so, and the report states plainly what was assessed automatically and what was not.

“Manual” never renders as a pass. A tool that quietly counts what it could not check as satisfied produces a document that reads well and fails an audit, and that is a worse outcome than a shorter report with holes in it that you can see.

How the mapping works

From a weakness class to a control, with the reasoning attached


Findings carry weakness classifications, and controls are mapped to those classifications with a written rationale rather than a keyword match. A mapping you disagree with is therefore something you can read and argue with, which is the only way this kind of automation earns its place in an assessment.

Where a finding drives several controls, it appears against all of them rather than being assigned to whichever matched first. Where a control is driven by several findings, the report shows them together — an auditor asking "why is this a gap" gets the whole answer.

None of this is a certification, and the software will not tell you that you are compliant with anything. It assembles the evidence a qualified assessor works from, in a form they can check, and stops there.

Policy generation

Policies from the same catalogue, not from a blank prompt

The third drafting path in the engine produces security policies — scope, roles, enforcement, review cycle — written against the same control catalogue the gap analysis reads. A policy that cites a framework clause that does not exist is the same defect class as a fabricated CVE, and it is gated the same way.

  • Structure asserted against the framework rather than invented per document

  • Every clause traceable to the control it implements

  • House phrasing reused where a firm has its own, through retrieval scoped to that organisation

  • A draft until somebody with the authority to set policy signs it

The limit of it

A practitioner signs the assessment, not the software

A gap analysis is evidence assembled for somebody qualified to judge it, and the output says so on its own face: what was assessed from scan data, what was not, and which controls the engine declined. The software cannot mark its own homework in this domain, so it does not try — it does the bookkeeping an assessor would otherwise do by hand, and leaves the conclusion where it belongs.

Which framework would you actually put in front of an auditor?

Four catalogues, and control mappings written with the reasoning attached so you can argue with them. If your assessments live or die on a framework that is not listed, tell us which one.

Get in touch

Talk to the people building it

No chatbot and no ticket queue. Tell us what your security reporting actually looks like — which tools you live in, how long a deliverable takes, what a client has sent back — and someone who works on the software will reply.

info@legosphere.com

Please keep live incident details, credentials and customer data out of this box — it is an ordinary enquiry form, not a secure channel.