Skip to content

Reports

Most of what you need out of CyberGuard comes from the exports on each module’s own page. Reports is for the handful of documents that a standard or a regulator specifies in a fixed shape — where the deliverable is not “your data as a table” but a particular artefact assembled from several places at once.

The Reports page lives at /reports. The quickest route in from day-to-day work is from an ISO 27001 audit: open its export menu and choose SoA builder, which opens the Statement of Applicability report with that audit already selected.

Two report tiles ship today.

The SoA is the ISO 27001 document that states, control by control, whether a control applies, why, and how far it is implemented. The builder assembles it from an audit rather than from a separate spreadsheet.

  1. Select an audit. The picker lists the audits you can see.
  2. Choose implementation groups. The groups come from the audit’s framework. If the framework defines a group whose reference is soa, it is selected for you; otherwise every group is selected and you narrow it down.
  3. Optionally select risk assessments. This enriches the SoA with the risk scenarios and treatment decisions linked to your controls — the justification column stops being hand-written prose and starts pointing at real risk work.
  4. Generate.

The result is a table of Ref, Reference control, Applicable, Justification and Implementation. When you included risk assessments, an Additional Controls section follows it, listing the applied controls identified through risk scenarios with their Risk coverage — controls that matter to your security posture but that the framework’s own requirement tree never named.

Back to selection returns you to the form, and the PDF button prints the report. The report always prints in light theme, whatever theme you are using on screen.

The Register of Information is the structured submission DORA requires financial entities to file with their competent authority. Because a rejected submission costs weeks, the report validates before it generates.

Opening the tile runs a validation pass over your entity, third-party and contract data and reports it as a summary of Errors, Warnings, Info and Passed checks. Each finding names the category, the message and the offending field, with a Fix, Review or View link that takes you straight to the object’s edit form and brings you back afterwards. While any error remains, generation stays blocked — warnings and info do not block it.

Once the checks pass, the export options decide how the submission is packaged:

  • Entity Identifier — which of your registered identifiers names the entity in the file and its filename.
  • Reporting LevelIndividual (IND) or Consolidated (CON).
  • Naming ConventionEBA standard or NBB format, whichever your competent authority expects.

A live filename preview shows exactly what the resulting archive will be called before you generate it, which is worth checking: for most authorities the filename itself is part of the specification.