Compliance

Everything you set up in the onboarding journey feeds your compliance posture: the systems you connected and the findings they produce are mapped to ISM controls, tracked for readiness, and packaged for IRAP assessment with evidence-backed control statuses.

Frameworks

Frameworks shows your enabled compliance frameworks and posture against each:

Frameworks view showing enabled compliance frameworks with posture against each

QuantAssure ships with the Australian Government ISM control catalogue (1,000+ controls), Essential Eight, and IRAP-oriented tooling. Controls carry per-org status (applicability, compliance state) and link to evidence: findings, resolutions, policies, and scan activity collected by your runs — so control status is backed by artefacts, not assertions.

ISM & IRAP

For agencies and suppliers facing IRAP assessment, QuantAssure maintains ISM control statuses with AI-assisted applicability assessment and links each control to the evidence your runs collect continuously. Findings from connectors arrive pre-mapped to ISM controls where the source event implies one (e.g. CloudTrail "logging stopped" → ISM logging controls). The SOA export and compliance reports package this for your assessor.

New to IRAP or the ISM? The IRAP compliance guide and ISM controls guide cover the background; this section documents the product workflow.

How It Works

The compliance workflow has four phases:

  1. Connect — Set up systems with integrations to collect security data (learn more)
  2. Assess — AI maps findings to ISM controls and suggests compliance status
  3. Evidence — Automated and manual evidence is collected against controls
  4. Readiness — Track your compliance posture and export your SOA for assessors

Setting Up a Compliance Target

  1. Navigate to Compliance → Add Target
  2. Select your framework (e.g., ISM OFFICIAL: Sensitive)
  3. Set your target certification date
  4. Define scope (full or partial) with scope notes
  5. Optionally enter auditor information and audit dates
You can track multiple frameworks simultaneously.

What's Automated vs Manual

Automated Manual
Findings from pipeline scans Implementation notes per control
Policy sync from Google Drive Evidence for physical/procedural controls
AI compliance status suggestions Applicability determinations
Asset inventory from integrations Custom evidence uploads
Finding-to-control mapping Assessor review via SOA import

System Boundaries

  • Evidence is scoped to registered systems and assets
  • Register all systems in scope for your assessment
  • Configure integrations for each system
  • Run scans regularly to keep evidence fresh
  • Assets not registered won't have automated evidence
If a system or asset isn't registered in QuantAssure, its security data won't appear in your compliance view. Register everything in scope before starting your assessment.

Learn more about asset registration

Guides in This Section