Compliance
Evidence as a byproduct of the work
Findings carry their control context, so the inventory and remediation history you maintain day to day is the same artifact an assessor asks for. Mapping is a starting point for your assessor's scope, not a certification claim.





| Framework | Relevant controls | Evidence produced |
|---|---|---|
| ISO 27001 | A.5.16, A.5.18, A.8.2, A.8.9 | Identity inventory with owners, privilege review records, credential lifecycle log |
| SOC 2 | CC6.1, CC6.2, CC6.3, CC7.2 | Continuous monitoring of logical access for nonhuman identities and remediation history |
| NIST 800-53 | AC-2, AC-6, IA-5, CA-7 | Account management, least privilege, authenticator management, continuous assessment |
| FedRAMP | AC-2, IA-5, CA-7 | Inventory and monitoring artifacts for service and workload identities |
| HIPAA Security Rule | §164.308(a)(4), §164.312(a)(1), §164.312(d) | Access authorization, unique identification, and authentication management for system accounts |
Bring machine identities into your control narrative
Walk through how findings map to the frameworks in your current scope.