Compliance
The Comply module allows organizations to define compliance frameworks, monitor compliance status in real time, and generate compliance reports for auditors. It provides a structured way to map regulatory requirements to audit log data, track whether those requirements are being met, and produce documented evidence of compliance activity.
Understanding compliance management:
The compliance module enables you to:
- Define compliance frameworks such as GDPR, HIPAA, SOX, and PCI-DSS
- Create compliance rules linked to specific audit events and operations
- Monitor compliance status across all frameworks in real time
- Generate compliance reports for auditors and stakeholders
- Track compliance violations and remediation actions
- Configure alerts for compliance violations
Accessing the Comply module:
- Log in to the LT Auditor MP web portal
- Navigate to Comply in the main navigation menu
- The Comply page displays:
- Compliance Frameworks — high-level compliance categories
- Compliance Rules — specific requirements within each framework
- Compliance Status — overall compliance score
- Recent Violations — recent non-compliant events
Creating a compliance framework:
Compliance frameworks group related compliance requirements under a single structure.
Requires appropriate permissions.
- Click Add Compliance Framework
- Configure the framework details:
| Field | Description |
| Name | Framework name (e.g., GDPR Compliance, HIPAA) |
| Description | Purpose and scope of the framework |
| Reference Code | Standard identifier (e.g., GDPR-2016/679) |
| Category | Industry or regulation type |
| Priority | Critical, High, Medium, or Low |
- Click Save
Creating compliance rules:
Compliance rules define specific requirements within a framework and how LT Auditor MP monitors them against collected audit data.
- Select a compliance framework
- Click Add Rule
- Configure the rule details:
| Field | Description |
| Rule Name | The specific requirement (e.g., Access Logging Required) |
| Description | Detailed explanation of the requirement |
| Reference | The section or clause number from the framework |
| Severity | Impact level if the rule is violated |
- Link the rule to audit data:
| Field | Description |
| Environment | Which environment this rule applies to |
| Category | Which log category to monitor |
| Operations | Which specific operations must be logged |
| Required Frequency | How often events should occur |
| Alert Threshold | When to trigger a compliance alert |
- Define compliance criteria:
| Criteria Type | Description |
| Must Exist | Certain events must be present in the audit data |
| Must Not Exist | Certain events must never occur |
| Count Thresholds | Minimum or maximum event counts required |
| Time Constraints | Events must occur within defined timeframes |
- Click Save
Linking reports to compliance rules:
Associate reports with compliance rules to automate evidence collection for audits:
- Open the compliance rule configuration
- Navigate to the Linked Reports tab
- Click Link Report
- Select one or more reports that provide evidence of compliance for this rule
- Click Save
Linking reports provides:
- Automated compliance evidence collection
- Audit-ready documentation
- Trend analysis for compliance metrics over time
Monitoring compliance status:
- Navigate to the Compliance Dashboard
- Review key metrics:
| Metric | Description |
| Overall Compliance Score | Percentage of rules currently met |
| Compliant Rules | Rules currently satisfied |
| Non-Compliant Rules | Rules with active violations |
| Pending Rules | Rules awaiting validation |
- Click into any framework to drill down into individual rule status
- Click a specific rule to view:
- Compliance Status — Met, Violated, or Pending
- Last Check — when the rule was last evaluated
- Violation Count — number of violations detected
- Evidence — links to supporting audit logs and reports
Compliance rule evaluation:
Compliance rules are evaluated against audit log data in three ways:
Scheduled evaluation:
- Rules are evaluated automatically on a defined schedule (e.g., hourly, daily)
- The system queries audit logs for evidence of compliance
- Compliance status updates automatically after each evaluation
Real-time evaluation:
- Critical rules can be evaluated in real time as events arrive
- Violations trigger immediate alerts
- Useful for security-critical compliance requirements
Manual evaluation:
- Navigate to a compliance rule
- Click Evaluate Now
- The system checks audit logs against the rule criteria immediately
- Compliance status updates and evaluation results are available instantly
Compliance alerts:
Configure notifications for compliance violations:
- Open a compliance rule configuration
- Navigate to the Alerts tab
- Click Add Alert
- Configure the alert settings:
| Field | Description |
| Trigger Condition | When to send the alert |
| Recipients | Email addresses or user groups to notify |
| Alert Frequency | Immediate, Daily, or Weekly |
| Escalation | Who to notify if the violation is not resolved |
- Click Save
Generating compliance reports:
On-demand generation:
- Navigate to Comply → Reports
- Select the compliance framework
- Choose the time period to cover
- Select which rules to include:
- All Rules
- Non-Compliant Rules Only
- Critical Rules
- Custom Selection
- Click Generate Report
- Download in your preferred format:
- PDF — for auditor submission
- Excel — for detailed internal analysis
- CSV — for data processing
Scheduling compliance reports:
- Navigate to Comply → Scheduled Reports
- Click Add Schedule
- Configure the schedule:
| Field | Description |
| Framework | Which framework to report on |
| Frequency | Weekly, Monthly, Quarterly, or Annually |
| Recipients | Email addresses for report delivery |
| Format | PDF, Excel, or CSV |
- Click Save
Compliance report contents:
Generated compliance reports typically include:
| Section | Contents |
| Executive Summary | Overall compliance score, rules met vs. violated, critical findings, trends |
| Framework Coverage | All rules within the framework with compliance status and evidence references |
| Violations and Findings | Non-compliant rules, violation timestamps, affected systems or users, severity |
| Supporting Evidence | Links to audit logs, report references, timestamps and metadata |
| Remediation Status | Actions taken, responsible parties, resolution timelines |
Compliance audit log:
Track changes to compliance configurations:
- Navigate to Comply → Audit Log
- Review compliance-related activity:
- Framework creation, updates, and deletions
- Rule modifications
- Report access history
- Alert history
- Filter by date, user, or framework
- Export the audit trail for external auditors
Compliance dashboards:
Create customized compliance dashboards for different audiences:
- Navigate to Comply → Dashboards
- Click Create Dashboard
- Configure the dashboard name and layout
- Add widgets:
| Widget | Description |
| Compliance Score Gauge | Overall compliance percentage |
| Rule Status Chart | Pie chart of met vs. violated rules |
| Trend Graph | Compliance score over time |
| Violation List | Recent compliance violations |
| Framework Summary | Status by framework |
- Click Save
- Optionally set as the default compliance dashboard
Exporting compliance data:
- Navigate to the compliance section
- Select the data to export:
- All frameworks and rules
- Specific framework
- Violation history
- Compliance trends
- Click Export
- Choose format: CSV, Excel, or JSON
- Download the file
Supported compliance frameworks:
LT Auditor MP supports compliance monitoring for the following regulatory frameworks:
| Framework | Focus Areas |
| GDPR | Data access logging, deletion tracking, consent management, breach notification |
| HIPAA | Patient data access logs, PHI auditing, security incident tracking |
| SOX | Financial system access, change management tracking, audit trail integrity |
| PCI-DSS | Cardholder data access, network security monitoring, access control validation |
| ISO 27001 | Security event monitoring, incident management, access control auditing |
| NIS 2 | Network and information security requirements |
| NIST 171 | Controlled unclassified information protection |
| DORA | Digital operational resilience |
| FFIEC | Financial institution security and audit requirements |
| FDIC | Federal deposit insurance compliance requirements |
Best practices:
- Group related rules logically within each framework for easier navigation and auditing
- Define clear measurable compliance criteria for each rule so compliance status is unambiguous
- Always link reports to compliance rules to automate evidence collection
- Schedule compliance reports in advance of known audit periods
- Review rules regularly to ensure they reflect current regulatory requirements
- Restrict compliance configuration access to authorized personnel only
- Document remediation actions taken when violations are detected
- Maintain compliance reports according to your organization’s regulatory retention requirements
[Your administrator should review all configured frameworks and rules prior to any external audit to confirm accuracy and completeness, and ensure the compliance audit log is retained as evidence of the compliance monitoring program.]