CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Compliance

Audit evidence as a by-product of detection.

Framework packs map live events to controls automatically, so the quarterly audit is an export rather than a project.

Framework packs

Five shipping packs, plus an EU CRA bridge on the roadmap.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
How mapping works

Event → control → evidence → report.

01

Event

A network or identity event lands in the Kafka pipeline and is normalized.

02

Auto-map

The compliance auto-mapper links the event to framework controls — around seven controls per network event.

03

Evidence

Mapped controls are sealed into the hash-chained vault with signatures and reason codes.

04

Report

Auditor packets, CISO monthly digests, and board PDFs are generated from the same records.

Worked examples

What an auto-mapped control actually looks like.

FrameworkControlEvidence produced
IEC 62443-3-3SR 6.1 — Audit log accessibilityHash-chained detection and approval records exportable per zone and conduit.
NERC CIPCIP-007 — System security managementProtocol-level access observations tied to asset and Purdue level.
NIST CSF 2.0DE.CM — Continuous monitoringPassive OT capture coverage with per-collector transport health.
ISO 27001:2022A.8.16 — Monitoring activitiesCorrelated incidents with analyst decisions and timestamps.
SOC 2CC7.2 — Anomaly detectionKill-chain incidents with W15/W60/W24 window provenance.
IEC 62443-3-3SR 5.1 — Network segmentationZone-crossing events flagged against your declared conduit map.

Export

Evidence Vault for the auditor

  • Hash chain verify + ZIP export.
  • Read-only role can export without mutating incidents.
  • PoV metric: saved a week of manual correlation.
CyberDragon Evidence Vault
Evidence integrity

Why an auditor can trust the export.

01

Capture

Detection, response action, and approval decisions are written as immutable records.

02

Hash

Each record is hashed and chained to its predecessor — any edit breaks the chain.

03

Sign

Ed25519 signatures seal the chain using Vault-backed key material.

04

Verify

Chain verification runs on demand; lab run verified 66 entries OK.

05

Export

Auditor-ready ZIP packets with policy reason codes, including OT denials.

FAQ

Frequently asked questions.

Does mapping replace my auditor?
No. It replaces the manual log correlation your team does before the auditor arrives. The output is a signed evidence packet your auditor can verify.
Which frameworks ship today?
IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, and SOC 2. EU CRA bridge mapping is on the roadmap.
Can we add internal controls?
Yes. Framework packs are extensible, and partner or internal control sets can be mapped alongside the shipping packs.

Generate an auditor packet from your own events.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.