Continuous Monitoring & Scans
Reviewing Past Compliance Scans
Looking back at previous continuous monitoring scans is a good way to judge how far your business has come along its compliance journey. You can access Scan History by selecting Review Compliance History on the Continuous Monitoring Dashboard. Once on the page, scroll down slightly to Scan History. You will see a page similar to the example below (as long as continuous monitoring has been enabled and a scan has taken place): An example of the previous compliance scans paPopularChanging Continuous Monitoring Settings
If you need to update any of your Continuous Monitoring configurations, these can be changed within relevant connections area. To access these settings, select Manage, located underneath the Connections section of Continuous Monitoring Dashboard. See below: Navigation guidance on accessing the connection area of continuous monitoring (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-28-1439031e3ap8l.png =900x230) On this page you will sPopularActioning Compliance Scans
Your Compliance Scans act as the blueprint for your entire compliance journey, instructing you on where to place focus, and informing you of any gaps within your security. Let's learn how to respond to any alerts from a scan. Once you have accessed your Scan History, and if there have been any issues detected by a recent scan, you will see a header labelled Scans Requiring Action, as shown by the example below: An example of compliance scans that require attention and have not bePopularCompliance at a Glance Results
The Compliance at a Glance area allows you to quickly review your compliance progress by checking the results of your most recent continuous monitoring scan. You can access this area by selecting Dashboard from the Scanning dropdown in the main navigation menu. Here's an example of what this area may look like: An example of the continuous monitoring dashboard (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-28-102943m1edx6.png =500x269) APopularScan History Graphs
The OneClickComply platform outputs all of your compliance and continuous monitoring data into graphs, allowing for easy exporting and to act as a quick way to demonstrate progress to co-workers, clients, and auditors. You can access these graphs by selecting Review Compliance History, within the Continuous Monitoring Dashboard, and then scrolling down. These graphs will show your compliance history over the course of different timeframes, such as monthly and quarterly. As withSome readersReviewing Information Assets
Assets stored within the Information Asset Register should be regularly review and updated to ensure they meet any recent changes in policy, process, or organisational structure. These assets can be examined in more detail by selecting View Details on the desired asset. as indicated below: An example of an information asset (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-24-152716m0qyr9.png =1098x99)Once selected, a new window will open, displayingFew readersStarting New Penetration Tests
Penetration Tests on the OneClickComply platform allow you to check your websites and applications for potential vulnerabilities. Once you have navigated to the Penetration Testing area of the platform, you will see a page similar to the following: Screenshot showing the penetration testing page (https://storage.crisp.chat/users/helpdesk/website/-/2/f/1/a/2f1af62ef894ca00/screenshot-2025-03-19-135407751rdp.png =1098x324) A scan has already taken place and been completed, and some high leFew readersReviewing Completed Penetration Tests
Once your Penetration Test has completed, it will show the Finished status on the main results table, similar to the following: Screenshot showing a completed penetration test (https://storage.crisp.chat/users/helpdesk/website/-/2/f/1/a/2f1af62ef894ca00/screenshot-2025-03-19-135407phppvl.png =1098x324) This table will provide a quick, high-level overview of the scan results. Let's go through the information available to us: Scan ID: A unique identifier for the scan Scan Type: WFew readers
Policies
Accessing Policy Templates
Creating accurate policies is essential for compliance with standards like SOC 2 and ISO 27001. The OneClickComply AutoComplete Policy Generator houses templates for many of the most common policies for compliance, such as Data Protection and Patch Management. By default you will land on the templates area when you select AutoComplete from the navigation bar, but you can also select Templates inside the policy area as well. See below for a visual aid: Navigation guidance for accessinSome readersUsing Policy Templates
You can start using policy templates as soon as you get access to the platform. Simply choose one of the templates you want to work on and click Create New. See below for an example: A screenshot showing how to create a new policy (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-25-184233ow7pfh.png =1098x274) From here, you can now edit the template by selecting the associated tab on the template list. In the previous example we selected DP-01 DaFew readersReviewing and Editing Policies
You can edit all of your policies by selecting Review on the desired task within the Templates area of OneClickComply. This will take you to the Edit and Publish page for policy templates. Here's what this page looks like: An example of the data protection policy page (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-01-23-15253617j9ziz.png =980x500) We've already covered the Status, Last Modified and Modified by tags in a previoFew readers
Account
Managing Integrations
Integrations with third-party applications allows OneClickComply to fully utilise its automation capabilities. You can locate your connected integrations by selecting Integrations from the main menu, then clicking Marketplace. Once on the integrations page, select Manage on any of your currently connected apps. See below for an example: A screenshot of the integrations page (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-153924s9gsdy.pngPopularOnboarding Other Users & Account Types
Your OneClickComply account will have one account owner, and as many administrators and auditor profiles as required. You can access the Account User area by navigating to Settings in the main navigation menu, selecting Manage Account from the dropdown, then scrolling down to Account Users. You can see an example of this area below: A table showing the different account types within the platform (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshoSome readersUpdating Business Details
You can update your business details within the Manage Account area. You can access this by selecting Settings from the main navigation menu, then clicking Manage Account from the drop down options, as shown below: Navigation guidance for account management (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1353421se4ade.png =670x200) You can use the Business Details area to update relevant information, as well as to check the standards thaSome readers
Tasks & Compliance
Completing Tasks Manually
Sometimes you may wish to complete a task by hand, rather than completing it automatically through the OneClickComply platform. In order to move a task into the manual queue, you need to select the Add to manual list option. To start, access the Manual Task Queue and click Review on the task you wish to complete manually. See an example below: An example of an outstanding task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1518403cdgkw.pPopularUnderstanding the Report Card
An important aspect of compliance is understanding both how far you have come, but also how much more work there is left to be completed. The Report Card area allows you to gain a top-down view of your how many tasks you have remaining. This area can be accessed by selecting Reporting from the main menu, then clicking Report Card from the dropdown. Here is an example of what you may find on your Report Card. An example of compliance progress percentages (https://storage.criPopularReviewing Outstanding Tasks
Reviewing Outstanding Tasks is the bread and butter of OneClickComply, and knowing where to find crucial information about your compliance is incredibly important. Once on the Outstanding Tasks page, select Review on the right hand side of your chosen task, as shown below: An example of an outstanding task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1433391l3nccr.png =584x175) Doing this will open a new window specifically for the sPopularCompleting Outstanding Tasks Automatically
Automatically completing your Outstanding Tasks is the beating heart of the OneClickComply platform. Here's how you can complete your compliance tasks in a matter of seconds. First, navigate to your chosen task in Outstanding Tasks, then select Review, as shown below: An example of an outstanding task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1505541rqpbxy.png =663x200) This will open a new window for that task. Now navigate to thPopularTask Dependencies
Sometimes certain tasks will have pre-requisites before they can be completed. These are referred to as Dependencies. A task that is particularly complex, or requires a certain setting enabled in order to be completed, will have a yellow banner above it to highlight any tasks that must be completed beforehand. This will only be shown when reviewing the task in more detail. Here's an example: (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-01-29-121635Some readersMarking Tasks as Out of Scope
Sometimes a specific control outlined by compliance standard will not be relevant to your business. While this can be for a variety of reasons, it's important to know how to marks tasks as non-applicable to your compliance scope. First, click Review on your desired task within the Outstanding Tasks area. See below: An example of an outstanding task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-15055413wp0k0.png =663x200) From here, scrollSome readersReviewing Task History
Reviewing tasks in the Task History area is a critical component of managing your compliance. Once in Task History, select Review next to the task you wish to see in more detail. See below: An screenshot showing where to click to review the history of a task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-01-29-115157kh3mt3.png =1065x100) Doing this will open a new window within the platform providing a more in depth look a that task. Here's aSome readersReviewing Task Implications
Similar to completing a task manually, the description of the task will include an 'Implications' area, and a 'This Automation' section. These will provide more information about the affect that completing this task will have on your business. Let's look at an example: An example of a task with the automation details and manual steps highlighted (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1425031rhmg1q.png =766x500) This automation: This arSome readersReviewing Audit Logs
Audit logs serve as a record of any changes or alterations made within a businesses IT systems. Auditors can use these record to examine configurations, cross-reference settings against security standards, and determine whether a business has been in compliance with a cyber security framework or standard. You can access your audit logs by clicking Reporting on the main menu, and then selecting Audit Log from the drop down. Once in the Audit Log area, you will see a table similar toSome readersMeasuring Compliance
The Report Card area contains different metrics to measure your compliance progress. You can access this area by selecting Reporting from the main menu, and then clicking Report Card from the drop down. See below: Navigation guidance for accessing the report card (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-26-093853p70kcb.png =800x176) The most important statistic within this page is your Compliance Progress. An example of this areaSome readersMarking Tasks as Manual
In order to move from your Outstanding Tasks area to the Manual Task Queue, they need to be marked as manual first. You can mark tasks within the Review area. First, navigate to your desired task in Outstanding Tasks, then select Review. See below: An example of an outstanding task (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-12-1505541s101oz.png =663x200) Once in the Review window, scroll down to the bottom section of the tSome readersReviewing Outscoped Tasks
Just like with your Outstanding Tasks, or your Task History, sometimes you will need to review an outscoped task in a bit more detail, or even return a specific task to 'Within scope'. To do this, click Review on any of the tasks within the Outscoped Tasks area. See below for an example: An example of an outscoped task within the Outscoped Tasks area (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-01-29-1052261mjs6xu.png =965x225) Selecting RFew readersCreating & Reviewing Incidents
Documenting and responding to risks is a core component of compliance with standards such as ISO 27001 and SOC 2. The OneClickComply platform allows you to collate all of the incidents that have occurred within your business, and document them in one central place. Let's have a look an example incident on the main Incident Management screen: An example screenshot of the incident management page (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-17-1132Few readersUsing the Information Asset Register
The Information Asset Register allows you to store, review, and update various information assets within your organisation. This area can be accessed through the ISMS area of the Compliance tab. Once inside the Information Asset Register area, you will see a page similar to the following: Example screenshot of the information asset page (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-24-1518221bnnyl.png =1098x221) As shown above, there is anFew readersFinding risks within the Risk Register
The Risk Register allows you to create and maintain an accurate record of risk that your business faces, and can be accessed through the ISMS area within the Compliance tab. Once in Risk Register area, you will see a table of all the risks that have been created within the OneClickComply platform, similar to the following: A screenshot showing risks to the business (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-20-1136531r3mgxw.png =11Few readersReviewing and Updating Risks
Risks within the Risk Register should be regularly reviewed and update to match any increase in likelihood or impact to the business. They can be examined in more detail within the OneClickComply platform by selecting Review on the associated risk, as shown below: Navigation guidance on how to review risks in greater detail (https://storage.crisp.chat/users/helpdesk/website/2f1af62ef894ca00/screenshot-2025-02-20-120220niyrct.png =1033x100) Once selected, a new page will be opened, eFew readersViewing Completed Cyber Essentials Questionnaires
Once you have clicked the Submit button at the end of answering your Cyber Essentials questionnaire, the document will then start generating. The OneClickComply platform will combine your answers with the technical controls that you have implemented through the platform, creating a document that accurately reflects the processes that you have in place at the moment. You can access your in-progress and completed documents within Questionnaires area of the Cyber Essentials QuestionnairFew readersCompleting the Cyber Essentials Questionnaire
Using the OneClickComply platform, you can easily complete the self-assessed questionnaire needed for Cyber Essentials certification. Any tasks that you have automatically fix, or completed manually, will be automatically inputted into the relevant areas of the questionnaire, ensuring that your answers are fully aligned with the security processes that you have in place. Let's have a look at the steps needed to complete a questionnaire within the OneClickComply platform. When you first click oFew readersCompleting Cloud Platform Tasks
The process of completing Outstanding Tasks for cloud platforms such as AWS, Azure, and Google Cloud is nearly identical to the process for Microsoft 365 and Google Workspace. Once you have identified which task you would like to manage, select the Review button. Let's look at the task below as an example. This task requires users to ensure that CloudTrail logging is enables for all regions currently in use. Screenshot of an outstanding aws task (https://storage.crisp.chat/users/helFew readers