Compliance
Every finding category in FirewallIQ Secure is mapped — by us, reviewed annually — to controls across seven frameworks. CI gates ensure no finding category ships without complete coverage.
Compliance
Every finding category is mapped — by us, reviewed annually — to the controls in every framework you care about. CI gates ensure no category ships without a complete mapping.
Requirements 1, 2, 10, 11
Annex A — A.8, A.12, A.13
PR.AC, PR.PT, DE.CM
AC, SC, SI families
Controls 4, 12, 13
Article 32 — security of processing
Section 8(5) — safeguards
SOC 2 mapping
Coming in v2
This is a small slice — the actual library covers every finding category × every framework.
| Framework | Control | Description | Finding categories |
|---|---|---|---|
| PCI-DSS v4.0 | 1.2.1 | Limit inbound/outbound traffic to that necessary for the CDE | exposure.rdp_internet_facingrule.any_any_allowrule.no_egress_filter |
| PCI-DSS v4.0 | 2.2.5 | Insecure services and protocols disabled | exposure.telnet_openexposure.smb_v1_openexposure.ftp_open |
| ISO 27001 A.8.22 | A.8.22 | Segregation of networks | segmentation.violation_zone_to_zonesegmentation.unintended_path_to_cde |
| NIST CSF 2.0 | PR.AC-05 | Network integrity protected | rule.any_any_allowexposure.management_interface_external |
| CIS Controls v8 | 4.4 | Implement and manage a firewall on servers | exposure.rdp_internet_facingrule.any_any_allow |
| GDPR | Art. 32(1)(b) | Confidentiality, integrity, availability, resilience | exposure.weak_tls_versionrule.allow_without_logging |
| DPDPA 2023 | Sec. 8(5) | Reasonable security safeguards | exposure.*rule.*segmentation.* |
We map a finding to a broader control when in doubt. Never overclaim narrow coverage.
New framework version? We ship a new mapping file. Old findings keep their original mapping version.
Reports note that perimeter validation is one input to a broader program — never a complete verdict.
A 30-minute demo on real findings. We'll walk through scope signing, a live scan, and a signed compliance report — all on a customer-style sandbox.
No credit card. No agent install. Authorized-only by design.