Compliance dashboard
|
Compliance dashboard feature
This page is an introduction to Compliance dashboard midPoint feature.
Please see the feature page for more details.
|
|
Since 4.10
This functionality is available since version 4.10.
|
Find out what the built‑in compliance dashboard in midPoint is, how it derives its metrics from policies, policy rules, and marks, and how it helps you evaluate your compliance continuously.
What is compliance dashboard
Compliance dashboard provides aggregated overview of information and metrics related to regulatory compliance of organization. MidPoint contains a pre-configured dashboard, which provides overview of basic compliance metrics, based on pre-configured policies and policy rules.
Compliance dashboard is a pre-configured object (a.k.a. initial object) in midPoint. The dashboard can be further extended and customized as needed.
How it works
Functionality of compliance dashboard is heavily based on policies, policy rules and marks, as is described at Identity Governance Rules page. Policy rules, stored in policy objects are setting the marks, which are used by compliance dashboard for compliance reporting.
Move to proactive compliance with continuous auditing
Continuous auditing is the practice of evaluating compliance—security, regulatory, or internal—on an ongoing, automated basis rather than through periodic manual reviews.
In midPoint, policies, policy rules, and marks define the expected state of objects (e.g., required attributes, segregation of duties, prohibited configurations, etc.). The compliance dashboard visualizes the results of those evaluations in real time, and shows violations of these policies. You can set up dashboard reports to get an early warning, keep an eye on the severity of the violations, and possibly track trends over time.
By surfacing this information continuously, the dashboard enables your organization to detect drift, remediate issues promptly, and produce audit‑ready evidence without waiting for a scheduled audit cycle. Continuous auditing also reduces your staff stress levels; they no longer wake up in the middle of the night, drenched in cold sweat, screaming, "Save me, yet another audit round is coming!"
Jokes aside, it is the reality that compliance dashboards and continuous auditing transform and elevate compliance monitoring from a reactive, point‑in‑time activity into a proactive, always‑on control mechanism.
How to prove your compliance claims to an auditor
After you move to auditing compliance continuously, you may wonder how are you to demonstrate your internal compliance review process to auditors. During an audit, an auditor may want to actually see how you acquire the data you use for your compliance evaluation.
Your answer to the request can be very simple. Open midPoint on your screen and show them the live data on your compliance dashboard.