Frameworks and requirements
A framework, such as SOC 2, ISO 27001, or HIPAA, is a set of requirements your company has to meet. You meet each requirement through controls, which are the things your company does, and one control can count toward requirements in several frameworks. The Program page under Compliance shows how far along each of your frameworks is and which requirements still need work.
Members, Auditors, Admins, and Owners can view the Program page, which appears only in workspaces that include compliance. Only the Oneleet team can enable or remove a framework.
Requirements and controls
Section titled “Requirements and controls”Each framework enabled for your workspace brings its own list of requirements, and each requirement is linked to the controls that satisfy it. A control linked to requirements in several frameworks counts toward each of those frameworks’ totals and completion percentages.
A requirement is Met when it has at least one linked control and every linked control is Passing. Otherwise, it’s Unmet. A framework adds only the kinds of controls enabled for it, so some of its requirements start with no linked controls and show as Unmet.
Control statuses
Section titled “Control statuses”Each control has one of six statuses, and only Passing controls count toward a framework’s progress.
| Status | Meaning |
|---|---|
| Passing | Every enabled check on the control passes, we’ve approved the control in our review, and no active evidence request on it is waiting for our review. |
| Failing | At least one check on the control is failing. |
| Needs changes | We rejected the control in our review, or one of its checks needs changes and none are failing. |
| In review | The control is waiting for our review. |
| In progress | The control isn’t passing for another reason, such as checks that all pass while the control still needs our approval or has an open evidence request. |
| Not started | The control has no checks, or its checks are pending and none pass yet. |
Our review overrides the checks, so a control we rejected shows Needs changes and a control waiting for our review shows In review, whatever its checks say.
A control whose checks all pass stays In progress until we approve it, which is why a framework’s completion can stay low while its checks look healthy. To get a control reviewed, open it and click Submit for review.
An active evidence request also keeps a control from reaching Passing until we’ve reviewed the request, even after you’ve uploaded evidence to it. Requests scheduled for a future date don’t count until that date arrives. A request we rejected stops holding the control back, but it goes back to waiting for our review when you submit new evidence to it or remove all of its evidence. Removing all the evidence from a request we approved sends it back for review as well.
Track a framework’s progress
Section titled “Track a framework’s progress”On the Program page, click the Frameworks tab. Under Active frameworks, each card shows the framework’s Completion, which is the percentage of controls linked to its requirements that are Passing. The Overview tab shows the same completion percentage for each framework.
Click a card to open the Controls tab filtered to that framework.
The Overview, Controls, and Requirements tabs share a framework filter. It starts with every active framework selected, and your selection is kept in the page URL, so it stays in place as you switch between those tabs. At least one framework always stays selected.
Work through unmet requirements
Section titled “Work through unmet requirements”-
On the Program page, click the Requirements tab.
-
Click Unmet. Each row shows a requirement and its linked controls with their statuses.
-
Click a control’s title to open that control, or click anywhere else in the row to open the requirement’s page.
A requirement’s page shows its description and every linked control, along with each control’s owner, evidence, and evidence requests. Assign owners from this table, or select several controls to act on them together.
Click Export to download the requirements as a CSV file, with one row for each link between a requirement and a control. The file covers only the frameworks selected in the framework filter and follows your current search and Met or Unmet filter.
To see only the controls linked to specific requirements, pick those requirements in the Requirement filter on the Controls tab. The filter lists requirements from every active framework, including frameworks the framework filter leaves out.
To work from a control instead, open its page. The Requirements section of the sidebar lists the requirements the control satisfies, grouped by framework, and links to each one.
Request a new framework
Section titled “Request a new framework”On the Frameworks tab, Available frameworks lists frameworks your workspace doesn’t have yet. Each card shows a description, an Estimated readiness percentage, and an Effort estimate when one exists. A NEW badge means the framework was added to Oneleet’s catalog recently.
Estimated readiness is the percentage of the kinds of controls a framework needs that your workspace already has a Passing control for. It counts every passing control in your workspace, including controls that aren’t linked to any active framework. That makes it a measure of how much of your existing work carries over, not of how ready you are for an audit.
Some frameworks, such as SOC 2 and HIPAA, come in more than one version under the same name, so a framework you already have can still appear under Available frameworks as another version. Ask your Security Program Manager if you’re not sure which version you have. Frameworks that aren’t offered to workspaces, such as SOC 1, don’t appear in the list at all.
The Oneleet team enables frameworks for your workspace, so you can’t add one yourself. To talk about adding one, click Schedule call on its card, which opens your Security Program Manager’s scheduling link in a new tab. The button only books a call and doesn’t request the framework. If the card shows “Contact us on Slack to get started.” instead, reach out to us on Slack.
If your workspace has no active frameworks yet, the Program page shows a No active frameworks message instead of its tabs. Contact your Security Program Manager to choose your first framework.
What changes when a framework is enabled
Section titled “What changes when a framework is enabled”Enabling a framework also enables every framework it builds on that your workspace doesn’t already have. Your workspace gets the framework’s requirements and the controls linked to them. If your workspace already has a control of a kind the framework needs, that control is reused instead of duplicated, so the work you’ve done on it counts toward the new framework right away.
Oneleet adds the new controls’ monitors for every kind of asset your workspace’s integrations provide, including kinds you don’t have any assets of yet. New monitors don’t run right away. Each one first runs at the next trigger for its kind of asset: your workspace’s hourly monitor run (at a random minute past the hour), a new integration connection or another event that triggers monitors, or a rerun you start yourself.
New monitors can start out snoozed. During a SOC 2 Type 2 observation period, they stay snoozed until 28 days after the period ends, so a newly added check doesn’t create exceptions partway through the period. Outside an observation period, a monitor whose type was added to Oneleet’s catalog in the last seven days stays snoozed until seven days after the type was added.
Share compliance badges
Section titled “Share compliance badges”Compliance badges show a framework’s status on your website or anywhere else you share them. On the Program page, click Compliance badges, choose a theme and a badge format, and click Copy link or Copy code next to the framework you want. SVG link only copies the badge image’s URL, while HTML snippet copies code that also links the badge to your Trust center once it’s published. The Compliance badges button appears once your workspace has at least one active framework, and not every framework has a badge.
Each badge shows the framework as in progress or compliant. The modal says badges update automatically, but a badge switches to compliant only when the Oneleet team sets the framework’s status to Compliant by hand, not when your controls reach Passing. We set SOC 2 to Compliant only after you’ve had your SOC 2 audit, and we typically set other audited frameworks once your audit report is ready. HIPAA, GDPR, and similar frameworks have no certifying audit, so we set their status after an internal assessment, which we run once all their controls pass. Some audit firms attest to HIPAA alongside a SOC 2 audit, but that doesn’t change how we set the HIPAA badge.
A compliant SOC 2 badge means you’ve completed your SOC 2 audit, not that you’re certified, because SOC 2 is an attestation rather than a certification. The badge shows Type 2 unless your framework’s designation is set to Type 1. We set both a framework’s status and its SOC 2 designation (Type 1 or Type 2), so contact your Security Program Manager to change either one.
A newly enabled framework doesn’t appear on your Trust center automatically. To show or hide a framework there, ask your Security Program Manager.
Remove a framework
Section titled “Remove a framework”To remove a framework, ask your Security Program Manager. When we remove it, we delete only the controls we created for it that no other active framework uses and that have none of your work on them, such as evidence, an owner, custom text, or review history. Every other control stays. For details, see Removing a framework.
What this means for your audit
Section titled “What this means for your audit”A Completion of 100% isn’t an audit report. After your controls are in place, the Oneleet team runs an internal review of your program, and SOC 2 Type 2 then has an observation period before the audit itself. ISO 27001 has no observation period. It has a Stage 1 audit and a Stage 2 audit, followed by surveillance audits.
Passing reflects the Oneleet team’s review, not your auditor’s, and clicking Submit for review doesn’t send anything to your auditor. Your auditor sees your controls and evidence in the auditor portal once we assign their audit firm to your audit. If your SOC 2 auditor is also attesting to HIPAA for the same period, ask your Security Program Manager to include your HIPAA controls and evidence in that audit.
You can’t mark a requirement as not applicable or a control as out of scope, so every linked control counts toward a framework’s progress. If you think a requirement doesn’t apply to your company, talk to your Security Program Manager.