ThreatKrusher Pillar 01 · Control and evidence plane

Keep control ownership, work, and evidence connected.

ThreatKrusher Comply organizes obligations, accountable owners, controls, systems, remediation, exceptions, artifacts, and review into a maintained readiness operation.

The operating problem

A spreadsheet can list controls without making them operational.

Readiness erodes when requirements, policies, technical changes, tickets, exceptions, owners, and artifacts live in separate systems with no dependable review cycle.

  • Control statements lack an accountable operating owner.
  • Remediation work is disconnected from the obligation it addresses.
  • Evidence becomes stale, incomplete, or impossible to reproduce.
  • Scope and system changes do not trigger reassessment.
  • Assessment preparation becomes a recurring document scramble.

Role in the ecosystem

Comply is the control and evidence plane across all seven pillars.

Obligations

Define what applies

Requirements, contracts, policies, standards, risk decisions, scope, and authoritative sources.

Ownership

Assign accountability

Business authority, control owner, service role, approver, reviewer, due date, and escalation.

Implementation

Connect safeguards

Policies, procedures, configurations, services, systems, dependencies, and client duties.

Work

Drive action

Gaps, remediation plans, tickets, milestones, exceptions, changes, validation, and acceptance.

Evidence

Preserve support

Artifacts, telemetry, approvals, tests, dates, sources, periods, integrity, and limitations.

Review

Maintain readiness

Status, sufficiency, change impact, residual risk, aging, findings, decisions, and next review.

Scope boundary

Define what Comply includes—and what remains outside the service.

Included when contracted

  • Requirement and scope analysis
  • Control ownership and implementation planning
  • Gap and remediation workflow
  • Policy, procedure, and evidence coordination
  • Readiness reviews and status reporting
  • Exception and change-impact tracking

Not implied

  • Legal or acquisition advice
  • Independent C3PAO or certification decisions
  • Guaranteed assessment results or SPRS score
  • Responsibility for unreported client facts
  • Automatic coverage of every framework or system
  • Acceptance of evidence by a third party

Client assumptions

  • Accurate scope, asset, data, user, and supplier facts
  • Named business and control owners
  • Timely access, approvals, decisions, and remediation
  • Policy approval and executive accountability
  • Risk acceptance by authorized client leadership
  • Protection of sensitive assessment artifacts

People · process · system

Make the operating model inspectable.

People

Executive sponsor, program owner, control owners, service owners, technical operators, evidence custodians, reviewers, and eTrepid delivery roles are named with authority and escalation.

Process

Scope, assess, plan, implement, validate, collect, review, remediate, approve, monitor, and respond to change through repeatable, dated workflows.

System

Approved systems of record connect obligations, controls, assets, policies, tickets, evidence, exceptions, risks, review dates, and dependencies without treating software as the decision-maker.

Evidence produced

Preserve context—not just files.

Each evidence record should explain what claim it supports, where it came from, who owns it, what period it covers, how it was reviewed, and what it does not establish.

Record

Control record

Requirement, interpretation, scope, owner, implementation statement, dependencies, status, and review date.

Work

Remediation trail

Finding, cause, planned action, accountable owner, milestone, ticket, validation, acceptance, and residual risk.

Artifact

Evidence package

Source, system, period, collector, integrity, control link, sensitivity, limitation, reviewer, and retention.

Decision

Governance record

Approval, exception, risk acceptance, change decision, authority, rationale, conditions, expiry, and review.

Maintained readiness cycle

Turn point-in-time preparation into governed operations.

01

Define

Establish scope, obligations, owners, systems, data, dependencies, and acceptance criteria.

02

Implement

Put approved safeguards, procedures, configurations, and service responsibilities into operation.

03

Evidence

Collect dated operational records with source, context, control link, integrity, and limitation.

04

Review

Evaluate implementation, sufficiency, gaps, aging, exceptions, and assessment readiness.

05

Respond

Remediate, accept, escalate, reassess, and update the record when risk or the environment changes.

Control and outcome mapping

Map only what the approved scope and evidence can support.

Comply can organize work against contractual, regulatory, policy, cybersecurity, privacy, AI-governance, and customer requirements where the applicable source, interpretation, mapping method, and service boundary are approved.

  • CMMC and the contract-defined NIST SP 800-171 baseline
  • Organization policies, risk decisions, and customer obligations
  • Security and privacy frameworks selected for the engagement
  • AI governance requirements and NIST AI RMF-aligned activities
  • Cross-framework reuse with source-specific qualification

Critical dependencies

Comply depends on the pillars that operate the safeguards.

Pillar 02

ITSM

Turns remediation, change, incidents, requests, configuration, and recurring control activities into assigned operational work.

Pillar 03

Trust

Validates security conditions and produces monitoring, testing, incident, and assurance records tied to control claims.

Pillar 04

Access

Operates identity, authentication, authorization, privilege, service-account, and access-review safeguards.

Explore the complete ThreatKrusher ecosystem →

Evidence discipline

Demonstrate the method without exposing sensitive records.

Representative control records, remediation trails, and evidence packages can be reviewed in an appropriately controlled engagement, with client identifiers and sensitive technical details protected.

Controlled proof

Any example must have appropriate permission, redaction, accessibility, framework revision, scope, dates, reviewer, and limitations. Availability depends on disclosure rights and the intended evaluation.

Common questions

Clarify responsibility before readiness work begins.

Is Comply a GRC software product?

Comply is the control and evidence pillar within eTrepid’s ThreatKrusher delivery ecosystem. It may use multiple systems, workflows, integrations, and client platforms according to the implemented and contracted operating model.

Can eTrepid assess the controls it helps implement?

eTrepid may perform internal readiness and validation activities within scope, but those are not an independent C3PAO assessment or certification decision. Required independence and authorized-assessor roles must remain explicit.

Does Comply replace the client’s control owners?

No. eTrepid can support program management and perform contracted operational work, but the client retains business authority, policy approval, accurate facts, risk acceptance, required attestations, and responsibilities that cannot be delegated.

Can evidence be reused across frameworks?

Sometimes, when the same implemented activity genuinely supports multiple obligations. Each mapping still requires source-specific interpretation, scope, context, dates, limitations, and review; apparent similarity does not prove equivalence.

CMMC readiness

Start with scope, ownership, the evidence gap, and the next decision.

Bring the contract requirement, current scope assumptions, responsible leaders, known gaps, and non-sensitive description of the operating environment. eTrepid can then define an appropriate readiness or Comply discovery path.