Secureframe Comply
Run day-to-day compliance: tests, policies, personnel, risks, vendors, and evidence across your frameworks.
By Brady and 2 others3 authors98 articles
- FAQs: Frameworks and mappings: controls, tests, and cross-framework views
- Framework Resources (SOC, ISO, and more)
- Secureframe Framework offering
- Scoping Rules and Frameworks
- Creating Custom Frameworks
- Using the Frameworks Views in Secureframe
- Map Framework Requirements and Controls
- Mark Framework Requirements and Controls as N/A
- Export evidence from Controls and or Frameworks Page
- Framework Scoping - Supporting Segregated Accounts
- Policy 'Last Published' date: how it works and why it might not update
- FAQs: Policies and acknowledgments: templates, mappings, and workflows
- Overview of the Policies Page
- Linking a published Policy to a Policy Test
- How to write an effective Policy
- Create and or Edit policies
- Policy User Acknowledgement: How to publish and send policies
- Assign a policy owner
- Archive or Unarchive a policy
- Policy Changelog
- Out-of-scope personnel: why they may still show task statuses or appear in filters
- FAQs: Duplicate personnel, email addresses, and login issues
- Email domain filters: what “Included domains” really means (common gotchas)
- FAQs: Personnel management: HRIS, onboarding, and common scenarios
- Filtering Personnel by Email Domain
- Master Index: Personnel Management
- Managing Personnel
- Understanding personnel statuses & scoping
- How to handle Unlinked Accounts
- Personnel Groups
- Editing & Merging Personnel Records
- Managing Domain Changes for Personnel in Secureframe
- Access Roles / Role Based User Access (RBAC)
- FAQs: Business continuity and disaster recovery: backups, resilience, and evidence
- FAQs: Risk register, assessment scope, and certification scoping
- FAQs: Incident response and risk events: plans, playbooks, and evidence
- Enhanced Risk Management Module
- Risk Library
- Risk Management Module
- Risk Register Flexible CSV Uploads
- Comply AI for Risks
- Why a test can show Pass when evidence looks empty (null/false or missing)
- FAQs: Evidence and documentation: uploads, attachments, and proof in Secureframe
- FAQs: Tests and controls: evidence, frameworks, and troubleshooting
- GCP VPC Network and Route Logging Tests
- AI Evidence Validation for Upload Test
- Upload Test Guidance & Organizational Control
- Custom Automated Tests (CAT)
- Tests Page Overview: Test Types, Uploading Evidence, Filtering
- Test Library
- Custom Upload Tests (CUT)
- Understanding Upload Tests: Intervals, Evidence Validity, Due Dates, and Tolerance Windows
- Test Activity Dashboard
- Comply AI: Cloud Remediation test guidance
- Evidence Best Practices
- JSON evidence for integration test (AWS, GCP, Azure)
- Views and Exports
- Default Intervals
- FAQs: Vendor risk management: assessments, workflows, and evidence
- FAQs: Access review and vendor review evidence
- Vendor Risk Management (VRM) - Full Guide
- How to add, edit or view Vendors
- How to handle your first Vendor Risk Management review
- Using Comply AI in Advanced Vendor Risk Management
- Vendor Security Questionnaires and Requests for Information (RFI)
