Compliance frameworks and control mapping
G8KEPR maps its security controls to the frameworks your auditors and customers care about, so you can answer "which control covers this?" without rebuilding the mapping yourself.
Frameworks G8KEPR tracks
The platform covers a set of assessment frameworks (the ones you're actively evaluated against) plus reference frameworks you can map to. Across them, a large library of individual controls is mapped to platform capabilities — so a requirement like "log and monitor access to sensitive systems" points to the specific G8KEPR features that satisfy it.
Mapping your controls
- 1.Open your dashboard and go to Compliance.
- 2.Pick the framework you're being assessed against.
- 3.Review each control's status and the G8KEPR capability that supports it.
- 4.Export the mapping as evidence (see Exporting compliance evidence).
Reading the status honestly
A control showing as "covered" means G8KEPR provides a capability that supports that requirement — not that your entire organization is compliant with the framework. Compliance spans people, process, and systems well beyond one platform. Use the mapping as a head start on your evidence, not as a certification.
For framework-specific detail, see HIPAA evidence and BAAs and SOC 2 and ISO 27001: where we are.