Skip to main content

Compliance Frameworks

Open Security > Compliance to review framework-level posture and control details.

What the page shows

  • Framework score.
  • Passing and failing checks.
  • Account context.
  • Last scan time.
  • Control details and related findings.

Active frameworks

Admins can choose active frameworks from Settings > General. Active frameworks drive what the organization focuses on in dashboards and reports.

Acknowledged vs accepted risk

StateWhat it means for compliance
AcknowledgedThe finding has been reviewed but still counts as failing.
Accepted riskThe organization has accepted the risk. Active accepted-risk items are treated as passing for compliance scoring.
ResolvedThe finding is no longer active after scanning.

Review workflow

  1. Start with the lowest-scoring framework.
  2. Open failing controls.
  3. Review related findings and resources.
  4. Decide whether each issue should be fixed, acknowledged, or accepted as risk.
  5. Re-scan after changes.