Compliance_Essentials

Compliance Essentials for Splunk

Compliance Essentials helps teams organize compliance-related monitoring and self-assessment activities in Splunk. The app provides workflows for configuring system boundaries, monitoring searches, evidence runs, assessments, POA&M, baselines, assets, artifacts, and audit activity so teams can review their own environment against selected compliance requirements.

Compliance Essentials does not determine whether an organization is compliant, does not provide a certification decision, and should not be treated as legal, audit, or compliance advice. Compliance conclusions remain the responsibility of the organization, its assessors, and its authorized compliance or legal advisors.

Supported Frameworks

Compliance Essentials 3.0.1 supports:

Legacy framework experiences outside CMMC and NIST RMF are no longer part of the active 3.0.1 experience.

Start Here

  1. Install Compliance Essentials
  2. Complete initial setup
  3. Review upgrade notes
  4. Read release notes
  1. Run App Setup.
  2. Enable frameworks in Framework Setup.
  3. Create or import system boundaries.
  4. Add or import assets.
  5. Set control applicability for each boundary.
  6. Configure monitoring searches in Saved Search Inventory.
  7. Run evidence searches and review results in Evidence Run Explorer.
  8. Create or import assessments.
  9. Review self-assessment and monitoring status in Compliance Posture and Control Health.
  10. Track gaps and remediation through Control Gaps and POA&M.

User Guide

Reference

Removed/Replaced in 3.0.1

The following workflows are removed (or have been replaced) from the active 3.0.1 experience:

Help

This app is not formally supported. Feedback and questions are handled on a best-effort basis and can be sent to mariedur@cisco.com.