Compliance is a state, not a screenshot
6 min read
The screenshot taken the week of the audit is the defining artefact of point-in-time compliance, and the reason so many programmes fail their second year.
6 min read
The screenshot taken the week of the audit is the defining artefact of point-in-time compliance, and the reason so many programmes fail their second year.
A screenshot proves one thing: that on one unspecified day, someone with access to a console saw a particular setting. It does not prove the setting held for the period under review, that it applied to the whole scope, or that it was not changed the following morning.
Assessors know this, which is why a mature assessment samples across the period rather than accepting a folder of images. The programme that cannot produce March’s position because it only ever captured today’s has a structural problem, not a documentation problem.
Automating evidence collection solves the frequency problem and creates a new one: an automated evidence item with no origin is worse than a screenshot, because at least a person can say where the screenshot came from.
Provenance is the fix. Every automated evidence item records which connector produced it, which scheduled collection run it belonged to, and when. An assessor can trace a control result back to the observations behind it and back again to the run that gathered them. That traceability is what makes automated evidence admissible rather than merely convenient.
Continuous monitoring produces a second-order problem: a dashboard that is permanently amber gets ignored, and an ignored dashboard is worse than no dashboard because it creates the appearance of oversight.
The answer is not to loosen the rule. It is to make the known and accepted deviation explicit, approved, and time-boxed. An exception with an expiry date forces a re-decision on a schedule rather than letting a temporary tolerance become permanent by inattention, and it keeps the remaining signal honest.
The question an assessor asks is rarely what your posture is today. It is what your posture was in March, and whether it has improved since.
Neither is answerable from a live view alone. Point-in-time posture snapshots, retained, are what turn a dashboard into a record. They are also what a maturity-based supervisory framework actually needs, because demonstrating improvement requires the earlier position to still exist somewhere other than in a slide deck.
Many Gulf organizations run three or four overlapping frameworks. The overlap is real, the saving is real, and claiming it badly is how a programme acquires findings.
Air-gapped can mean different things. These four questions establish what an installation actually needs from outside your network.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.