Skip to content

Compliance

Control-framework mappings, the engagement guide, and the policy library for running SOC 2, ISO 27001, HIPAA, and CIS Azure engagements with SnowOps automation.

Looking for the evidence stores? The actual evidence-as-code — compliance snapshots, restore-drill reports, and the client's written policy library — lives in compliance/ at the repo root (snapshots, restore drills, and policies are operational data, not documentation, so they aren't part of this docs site). This section covers the documentation that explains and drives that evidence.

Start here

  • Compliance Engagement Guide — how to scope, sequence, and close a certification engagement end to end: which framework fits which client, the discovery → gap analysis → remediation → evidence → auditor-readiness flow, and framework-specific notes (SOC 2 / ISO 27001 / HIPAA / CIS Azure).

Control mappings

Each maps every framework control to the SnowOps asset that implements it (✅ automated / 🔧 partial / 📋 manual / ⏳ roadmap / ❌ out of scope), the evidence it produces, and — at the bottom of each — a "What SnowOps Does NOT Automate" table for the items that stay management- or client-owned.

Framework Control mapping Notes
SOC 2 Trust Services Criteria — Control Mapping CC1–CC9 + Availability/Confidentiality/Privacy categories
ISO 27001 ISO/IEC 27001:2022 — Control Mapping Clauses 4–10 (ISMS) + Annex A.5–A.8
HIPAA Security Rule — Control Mapping §164.308/310/312/316 (Administrative/Physical/Technical Safeguards)
CIS Azure Foundations Benchmark — Control Mapping Sections 1–9 (config benchmark, no certification)

Policy library

  • Policy Library Guide — the minimum written-policy set every framework's mapping marks 📋 Manual (InfoSec, IR, BCP, change management, vendor management, …), where it lives (compliance/policies/), and the naming/versioning convention to use until the Policy Repo Template (V1) automates it.

How these pieces fit together

G-series discovery audit ──► Gap analysis ──► Control-mapping cross-reference
        │                                              │
        ▼                                              ▼
  remediation_asset_id                     ✅ / 🔧 / 📋 / ⏳ coverage symbol
        │                                              │
        ▼                                              ▼
  F/H/L/M/N/J-series modules ───────────────► E0 snapshot + S2 dashboard
        (the controls)                          (the evidence)
                                          Policy Library (📋 manual items)
                                            Auditor-readiness checklist
  • Asset Glossary — decode every asset code (E0, H1, L4, N3, …) referenced in these mappings
  • Service Packages — Baseline [B] / Advanced [A] package definitions referenced throughout the engagement guide
  • Client Guides — per-package handover guides, each cross-referencing the relevant control-mapping file
  • Gap Register — tracks staleness and improvement items found in these docs (e.g. G21/G22)
  • Incident Response and Disaster Recovery runbooks — the operational procedures behind the K1/K2/L-series evidence these mappings cite