Compliance¶
Control-framework mappings, the engagement guide, and the policy library for running SOC 2, ISO 27001, HIPAA, and CIS Azure engagements with SnowOps automation.
Looking for the evidence stores? The actual evidence-as-code — compliance snapshots, restore-drill reports, and the client's written policy library — lives in
compliance/at the repo root (snapshots, restore drills, and policies are operational data, not documentation, so they aren't part of this docs site). This section covers the documentation that explains and drives that evidence.
Start here¶
- Compliance Engagement Guide — how to scope, sequence, and close a certification engagement end to end: which framework fits which client, the discovery → gap analysis → remediation → evidence → auditor-readiness flow, and framework-specific notes (SOC 2 / ISO 27001 / HIPAA / CIS Azure).
Control mappings¶
Each maps every framework control to the SnowOps asset that implements it (✅ automated / 🔧 partial / 📋 manual / ⏳ roadmap / ❌ out of scope), the evidence it produces, and — at the bottom of each — a "What SnowOps Does NOT Automate" table for the items that stay management- or client-owned.
| Framework | Control mapping | Notes |
|---|---|---|
| SOC 2 | Trust Services Criteria — Control Mapping | CC1–CC9 + Availability/Confidentiality/Privacy categories |
| ISO 27001 | ISO/IEC 27001:2022 — Control Mapping | Clauses 4–10 (ISMS) + Annex A.5–A.8 |
| HIPAA | Security Rule — Control Mapping | §164.308/310/312/316 (Administrative/Physical/Technical Safeguards) |
| CIS Azure | Foundations Benchmark — Control Mapping | Sections 1–9 (config benchmark, no certification) |
Policy library¶
- Policy Library Guide — the minimum written-policy
set every framework's mapping marks 📋 Manual (InfoSec, IR, BCP, change
management, vendor management, …), where it lives (
compliance/policies/), and the naming/versioning convention to use until the Policy Repo Template (V1) automates it.
How these pieces fit together¶
G-series discovery audit ──► Gap analysis ──► Control-mapping cross-reference
│ │
▼ ▼
remediation_asset_id ✅ / 🔧 / 📋 / ⏳ coverage symbol
│ │
▼ ▼
F/H/L/M/N/J-series modules ───────────────► E0 snapshot + S2 dashboard
(the controls) (the evidence)
│
▼
Policy Library (📋 manual items)
│
▼
Auditor-readiness checklist
Related documentation¶
- Asset Glossary — decode every asset
code (
E0,H1,L4,N3, …) referenced in these mappings - Service Packages — Baseline
[B]/ Advanced[A]package definitions referenced throughout the engagement guide - Client Guides — per-package handover guides, each cross-referencing the relevant control-mapping file
- Gap Register — tracks staleness and improvement items found in these docs (e.g. G21/G22)
- Incident Response and Disaster Recovery runbooks — the operational procedures behind the K1/K2/L-series evidence these mappings cite