LT Auditor MP includes built-in compliance reporting for a wide range of regulatory frameworks. Compliance reports provide structured, audit-ready documentation of your environment’s security activity, mapped to the specific requirements of each framework.
Supported frameworks include:
- HIPAA
- NIST 171
- GDPR
- NIS2
- ISO 27001
- DORA
- FFIEC
- FDIC
- PCI-DSS
Setting up a compliance framework:
- Navigate to Compliance in the Web UI
- Click Add Compliance Framework
- Configure the framework details:
- Name โ the framework name (e.g., “GDPR Compliance”)
- Description โ purpose and scope
- Reference Code โ the standard identifier (e.g., “GDPR-2016/679”)
- Category โ industry or regulation type
- Priority โ Critical, High, Medium, or Low
- Click Save
Creating compliance rules within a framework:
Compliance rules define the specific requirements within a framework and how the system monitors them.
- Select the compliance framework you just created
- Click Add Rule
- Configure the rule details:
- Rule Name โ the specific requirement (e.g., “Access Logging Required”)
- Description โ a detailed explanation of the requirement
- Reference โ the section or clause number from the framework
- Severity โ the impact level if the rule is violated
- Link the rule to audit data:
- Environment โ which environment this applies to
- Category โ which log category to monitor
- Operations โ which specific operations must be logged
- Define compliance criteria:
- Must Exist โ certain events must be present in the audit data
- Must Not Exist โ certain events must never occur
- Count Thresholds โ minimum or maximum event counts
- Time Constraints โ events must occur within defined timeframes
- Click Save
Linking reports to compliance rules:
Associating reports with compliance rules automates evidence collection for audits.
- Open the compliance rule configuration
- Navigate to the Linked Reports tab
- Click Link Report
- Select the reports that provide evidence of compliance for this rule
- Click Save
Generating compliance reports on demand:
- Navigate to Compliance โ Reports
- Select the compliance framework
- Choose the time period to cover
- Select which rules to include:
- All Rules
- Non-Compliant Rules Only
- Critical Rules
- Custom Selection
- Click Generate Report
- Download the report in your preferred format:
- PDF โ for auditor submission
- Excel โ for detailed internal analysis
- CSV โ for data processing
Scheduling compliance reports:
- Navigate to Compliance โ Scheduled Reports
- Click Add Schedule
- Configure the schedule:
- Framework โ which framework to report on
- Frequency โ Weekly, Monthly, Quarterly, or Annually
- Recipients โ email addresses for report delivery
- Format โ PDF, Excel, or CSV
- Click Save
Monitoring compliance status:
- Navigate to the Compliance Dashboard
- Review key metrics:
- Overall Compliance Score โ percentage of rules currently met
- Compliant Rules โ rules currently satisfied
- Non-Compliant Rules โ rules with active violations
- Pending Rules โ rules awaiting validation
- Click into any framework to drill down into individual rule status
- Click a specific rule to view violation details, last evaluation time, and supporting evidence
Configuring compliance alerts:
Set up notifications so your team is informed immediately when a compliance violation is detected.
- Open a compliance rule
- Navigate to the Alerts tab
- Click Add Alert
- Configure:
- Trigger Condition โ when to send the alert
- Recipients โ email addresses or user groups
- Alert Frequency โ Immediate, Daily, or Weekly
- Escalation โ who to notify if the violation is not resolved
- Click Save
Best practices:
- Group related rules logically within each framework for easier navigation
- Always link reports to compliance rules to automate evidence collection
- Define clear, measurable criteria for each rule so compliance status is unambiguous
- Schedule reports in advance of known audit periods
- Regularly review rules to ensure they reflect current regulatory requirements
- Restrict compliance configuration access to authorized personnel only
- Document remediation actions taken when violations are detected