Skip to content

Configuring Compliance Reports

LT Auditor MP includes built-in compliance reporting capabilities that produce structured, audit-ready documentation of your environment’s security activity mapped to specific regulatory framework requirements. This article covers how to configure compliance frameworks, set up compliance rules, generate compliance reports, and schedule automated delivery — drawing on the full capabilities of the Comply module.


Understanding compliance reporting:

Compliance reports in LT Auditor MP are generated from the Comply module and differ from standard reports in that they are directly tied to configured compliance frameworks and rules. Each report documents the compliance status of specific requirements, provides evidence links to supporting audit log data, and highlights violations that need to be addressed.

Effective compliance reporting requires:

  • Compliance frameworks configured with the relevant regulatory requirements
  • Compliance rules linked to audit environments, categories, and operations
  • Reports linked to compliance rules as evidence sources
  • A schedule for automated delivery to stakeholders and auditors

Supported compliance frameworks:

Framework Focus Areas
GDPR Data access logging, deletion tracking, consent management, breach notification
HIPAA Patient data access, PHI auditing, security incident tracking
NIS 2 Network and information security requirements
NIST 171 Controlled unclassified information protection
ISO 27001 Security event monitoring, incident management, access control
DORA Digital operational resilience
PCI-DSS Cardholder data access, network security monitoring, access control
FFIEC Financial institution security and audit requirements
FDIC Federal deposit insurance compliance
SOX Financial system access, change management, audit trail integrity

Step 1 — Configure a compliance framework:

If a framework has not yet been created:

  1. Navigate to Comply in the main navigation menu
  2. Click Add Compliance Framework
  3. Configure the framework:
Field Description
Name Framework name (e.g., HIPAA Compliance)
Description Purpose and scope of the framework
Reference Code Standard identifier (e.g., HIPAA-45-CFR)
Category Industry or regulation type
Priority Critical, High, Medium, or Low
  1. Click Save

Step 2 — Create compliance rules:

Each compliance framework requires rules that define specific requirements and how the system monitors them.

  1. Select the compliance framework
  2. Click Add Rule
  3. Configure the rule:
Field Description
Rule Name The specific requirement (e.g., PHI Access Must Be Logged)
Description Detailed explanation of the requirement
Reference The section or clause number from the framework
Severity Impact level if violated
  1. Link the rule to audit data:
Field Description
Environment Which environment this rule monitors
Category Which log category provides evidence
Operations Which specific operations must be present
Required Frequency How often events should occur
Alert Threshold When to trigger a compliance alert
  1. Define compliance criteria:
Criteria Description
Must Exist Specific events must appear in the audit data
Must Not Exist Specific events must never occur
Count Thresholds Minimum or maximum event counts
Time Constraints Events must occur within defined timeframes
  1. Click Save

Step 3 — Link reports to compliance rules:

Linking standard reports to compliance rules automates evidence collection and makes compliance reports significantly more useful for auditors.

  1. Open the compliance rule configuration
  2. Navigate to the Linked Reports tab
  3. Click Link Report
  4. Select the reports that provide evidence of compliance for this rule
  5. Click Save

Link at least one report to each compliance rule before generating compliance reports. Rules without linked reports will not have associated evidence for auditors to review.


Step 4 — Generating compliance reports on demand:

  1. Navigate to Comply → Reports
  2. Select the compliance framework to report on
  3. Choose the time period to cover
  4. Select which rules to include:
Option Description
All Rules Include every rule in the framework
Non-Compliant Rules Only Focus on violations requiring attention
Critical Rules Include only Critical severity rules
Custom Selection Choose specific rules manually
  1. Click Generate Report
  2. Download in your preferred format:
    • PDF — for auditor submission and formal documentation
    • Excel — for detailed internal analysis
    • CSV — for data processing and further analysis

Step 5 — Scheduling compliance reports:

Automate compliance report generation and delivery ahead of known audit periods or as part of ongoing compliance monitoring:

  1. Navigate to Comply → Scheduled Reports
  2. Click Add Schedule
  3. Configure the schedule:
Field Description
Framework Which compliance framework to report on
Frequency Weekly, Monthly, Quarterly, or Annually
Recipients Email addresses for report delivery
Format PDF, Excel, or CSV
  1. Click Save

Compliance report contents:

Generated compliance reports include the following sections:

Section Contents
Executive Summary Overall compliance score, rules met vs. violated, critical findings, trends over time
Framework Coverage All rules with compliance status and evidence references
Violations and Findings Non-compliant rules, timestamps, affected systems or users, severity
Supporting Evidence Links to audit logs, linked report references, timestamps and metadata
Remediation Status Actions taken, responsible parties, resolution timelines

Monitoring compliance status between reports:

Use the compliance dashboard to monitor status in real time between scheduled report runs:

  1. Navigate to the Compliance Dashboard
  2. Review:
    • Overall Compliance Score — percentage of rules currently met
    • Compliant Rules — rules currently satisfied
    • Non-Compliant Rules — rules with active violations
    • Pending Rules — rules awaiting validation
  3. Drill into individual frameworks and rules to view violation details and evidence
  4. Manually trigger rule evaluation using Evaluate Now if immediate status is needed following a system change or incident

Compliance alerts:

Configure alerts so your team is notified immediately when a compliance violation is detected rather than discovering it during a scheduled report review:

  1. Open a compliance rule
  2. Navigate to the Alerts tab
  3. Click Add Alert
  4. Configure:
Field Description
Trigger Condition When to send the alert
Recipients Email addresses or user groups
Alert Frequency Immediate, Daily, or Weekly
Escalation Who to notify if the violation is not resolved
  1. Click Save

Compliance audit trail:

Maintain an auditable record of all changes to your compliance configuration:

  1. Navigate to Comply → Audit Log
  2. Review:
    • Framework creation, updates, and deletions
    • Rule modifications
    • Report access history
    • Alert history
  3. Filter by date, user, or framework
  4. Export the audit trail for external auditors when required

Best practices:

  • Configure all frameworks and rules well in advance of known audit periods — do not wait until an audit is imminent to set up compliance monitoring
  • Link reports to every compliance rule before generating compliance reports — rules without evidence links provide limited value to auditors
  • Schedule compliance reports to deliver automatically at a frequency appropriate for each framework — monthly for ongoing monitoring, quarterly for formal audit preparation
  • Review compliance status on the dashboard regularly between scheduled report runs so violations are identified and addressed promptly
  • Document remediation actions taken for each violation and retain that documentation alongside the compliance reports
  • Restrict compliance configuration access to authorized personnel only
  • Retain all generated compliance reports according to your organization’s regulatory retention requirements
  • Test compliance rules with sample data before relying on them for formal audit reporting

[Your administrator should review all configured frameworks and rules prior to any external audit to confirm they accurately reflect your organization’s compliance obligations and that linked reports are providing appropriate evidence.]