๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Compliance Scope

Show exactly what your compliance program covers, and prove that every in-scope device, application and account has a control over it.

Where to find it
Compliance (GRC) โ€บ Compliance Scope
Who can use it
Anyone with a GRC role that can view compliance data; syncing, editing items, linking and opening issues need a role that can edit
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

Compliance Scope keeps a register of the things your compliance program covers: devices, assets, applications, cloud accounts and business processes. Nothing new is collected. The items are drawn from the rest of the platform, for example the computers reporting to Lavawall, and you decide which ones are in scope, how sensitive they are and who owns them.

The first question an assessor asks is "You say this is in scope. Which control covers it?" The page answers it in both directions: which in-scope items have no control linked to them, and which in-scope controls have nothing under them.

A third view lists recent Microsoft 365 incidents, the controls each one touches, and lets you open an issue from an incident with one click.

What you see

The Compliance Scope page, with the where scope comes from, tabs, register filters, register table, coverage and incidents numbered 1 to 6.
The Compliance Scope page. Numbers match the list below.
  1. Where scope comes from: one cell per source, showing how many items are in the source and how many are in the register, when it was last seen, items not seen lately, and a sync button.
  2. Tabs: Register, Coverage and Incidents.
  3. Register filters: Search, Kind, Classification, In scope, Not seen lately and No control, with Show and Clear.
  4. Register table: Kind, Item, Classification, Owner, Links and Last seen, with a links button on each row that opens its details.
  5. Coverage: Items with no control over them, Controls covering nothing, Coverage by kind, and lists of Uncovered items and Controls with nothing under them.
  6. Incidents: Microsoft 365 incidents with Incident, Severity, Account, Controls it touches, Last event and Issue.

How to bring items into the register

  1. In Where scope comes from, find a source that has items.
  2. Select its sync button (Pull the current rows in).
  3. New items are added and existing ones refreshed. Your classification, owner, in-scope setting and notes are never changed by a sync.
  1. On the Register tab, find the item and select its links button (Links and details).
  2. Set Classification and Owner, turn In scope for compliance on or off, add Notes, and select Save.
  3. Under Covered by, choose what to link in Link to (for example a control), pick Which one, and select Add the link.
  4. To remove a link, select the Remove (ร—) button beside it and confirm Remove. The item stops being counted as covered by it.

How to find coverage gaps

  1. Open the Coverage tab.
  2. Review Uncovered items and select Link it next to one to jump to it in the register.
  3. Review Controls with nothing under them. A policy control may cover the whole organization, but a technical control with nothing under it needs attention.

How to turn a Microsoft 365 incident into an issue

  1. Open the Incidents tab.
  2. Check Controls it touches for the incident.
  3. Select Open an issue and confirm Open the issue. The issue goes into the issues register with the controls it touches. Doing it twice does not create a second issue.

Tips

  • Tick No control on the Register tab to see only items that need a control linked.
  • Tick Not seen lately to find items that have stopped reporting. Either they were decommissioned (and need a disposal record) or something stopped reporting.
  • A sync never deletes anything. Items that disappear keep their row and simply stop being seen.
  • Filtered lists have their own web address, so you can bookmark one or send it to a colleague.
  • A source that is not installed is still shown, marked "not collected here", so you know it exists.

Troubleshooting

  • "Nothing is in the register yet." Sync a source in Where scope comes from.
  • "No item matches those filters." Select Clear to reset the filters.
  • "No incidents have been recorded for this tenant." Nothing has been recorded from Microsoft 365 for this company, or Microsoft 365 is not connected.
  • "None of the mapped controls are in your catalogue." The controls this incident relates to are not in your control set, so no links are shown.
  • The sync button is missing. Syncing needs a GRC role that can edit, and the source must have items.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.