Compliance Essentials for Splunk
Compliance Essentials helps teams organize compliance-related monitoring and self-assessment activities in Splunk. The app provides workflows for configuring system boundaries, monitoring searches, evidence runs, assessments, POA&M, baselines, assets, artifacts, and audit activity so teams can review their own environment against selected compliance requirements.
Compliance Essentials does not determine whether an organization is compliant, does not provide a certification decision, and should not be treated as legal, audit, or compliance advice. Compliance conclusions remain the responsibility of the organization, its assessors, and its authorized compliance or legal advisors.
Supported Frameworks
Compliance Essentials 3.0.1 supports:
- CMMC 2.0
- NIST RMF Rev. 4
- NIST RMF Rev. 5
Legacy framework experiences outside CMMC and NIST RMF are no longer part of the active 3.0.1 experience.
Start Here
- Install Compliance Essentials
- Complete initial setup
- Review upgrade notes
- Read release notes
Recommended First-Run Workflow
- Run App Setup.
- Enable frameworks in Framework Setup.
- Create or import system boundaries.
- Add or import assets.
- Set control applicability for each boundary.
- Configure monitoring searches in Saved Search Inventory.
- Run evidence searches and review results in Evidence Run Explorer.
- Create or import assessments.
- Review self-assessment and monitoring status in Compliance Posture and Control Health.
- Track gaps and remediation through Control Gaps and POA&M.
User Guide
Reference
Removed/Replaced in 3.0.1
The following workflows are removed (or have been replaced) from the active 3.0.1 experience:
- Custom Content page (replaced by Monitoring Dashboards and Search Catalog)
- System Health page
- System Overview page (replaced by System Boundaries Overview Page)
- Domain/Control Overview page
- Executive Overview (replaced by Compliance Posture Page)
- Individual Control Dashboards (replaced by Control Detail Page)
- Audit, Artifact, and Training Entry Panels (replaced by Assessment, Artifact, and Training Management Pages)
Help
This app is not formally supported. Feedback and questions are handled on a best-effort basis and can be sent to mariedur@cisco.com.