Create your first audit
An audit (also called a compliance assessment) measures a perimeter against a framework such as ISO/IEC 27001:2022. Creating one takes two moves: import the framework from the library catalog, then create the audit itself. From there, the work is answering requirements one by one.
This walkthrough assumes you already have a domain and perimeter.
Import a framework
Section titled “Import a framework”-
In the sidebar, open Governance → Libraries. The catalog lists every library available to your instance — frameworks, threat catalogs, risk matrices and more.
-
Search for the framework you need, for example ISO/IEC 27001:2022, and click the import icon on its row.
-
Once loaded, the framework appears under Loaded libraries and in Catalog → Frameworks, ready to be used by audits.
Create the audit
Section titled “Create the audit”-
Open Compliance → Audits and select New Audit.
-
Give the audit a Name and pick your Domain and, optionally, your Perimeter.
-
Choose the Framework. If you have imported only one, it is selected for you.
-
Save, then open the audit. CyberGuard creates one requirement assessment per requirement in the framework — this is your worklist. You can edit the audit’s details later at any time.
Answer your first requirements
Section titled “Answer your first requirements”-
In the audit view, browse the requirement tree and select a requirement to open its assessment.
-
Record a Result: Compliant, Partially compliant, Non compliant, or Not applicable. Requirements start out as not assessed.
-
Attach what substantiates your answer: link the applied controls that satisfy the requirement (create them as you go with Add applied control), and attach evidences — a file, a link or a description — with Add evidence.
-
Update the requirement’s status as you work — To do, In progress, In review, then Done. The audit’s progress bars fill in as requirements are completed.
Because applied controls are decoupled from requirements, a control you describe once — your access management process, your backup routine — can be attached to many requirements across many audits without rewriting it. That reuse is where CyberGuard saves you the most time as your audit portfolio grows.
