Map a control once and reuse it across all frameworks. This is the concept that sets iComply apart from any checklist — it’s worth understanding it properly.
Most compliance tools organise work by framework: one list for ISO 27001, another for the GDPR, and another for NIS2. The result is work being duplicated three times over and evidence scattered across different systems. iComply turns this model on its head: it organises by control, and the frameworks are then viewed in relation to those same controls.
Four objects and the relationships between them underpin everything else:
The relationships are many-to-many: one control meets several requirements, one requirement may call for several controls, and one piece of evidence may support several controls. It is this topology that eliminates duplication.
Consider the ‘Mandatory multi-factor authentication’ control. Once implemented and with supporting evidence attached, it simultaneously satisfies:
With a framework-based tool, you’d have to answer the same question six times and upload the same evidence six times. Here, you only have to answer it once.
Each control has a status that feeds directly into the dashboard and reports:
Controlos → Biblioteca and select the control.You don’t need to start this work from scratch. iComply provides pre-built mappings between the supported frameworks; your job is to validate and supplement them.
In addition to the official libraries, you can create your own controls — whether to meet a client’s contractual requirements, comply with internal policy or adhere to sector-specific legislation. A custom control behaves exactly like any other: it accepts evidence, is included in audits and can be mapped to requirements.
Recommendation: before creating a new control, check whether one already exists that covers the same measure. Libraries bloated with near-duplicate controls are the main reason why governance programmes become impossible to maintain.
In Risco → Registo, match each risk with the controls that mitigate it. This has two important effects:
A one-off check is like a snapshot; when carried out regularly, it is a vital indicator. Set the review frequency according to the level of criticality — monthly for privileged access, annually for a top-level policy. When the date arrives, the platform notifies the person in charge, the status changes to ‘Under review’ and the dashboard reflects this.
It is this mechanism that replaces the frantic rush in the weeks leading up to the audit with a stable working routine.
We’ll show you a real-world example of a control that complies with six frameworks at the same time.
Utilizamos cookies para melhorar a sua experiência no nosso site. Ao utilizar o nosso site, está a consentir a utilização de cookies.
Defina as suas preferências relativas aos cookies abaixo:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Pode encontrar mais informações na nossa Política de Cookies e na nossa Privacy Policy.