FEATURE - Compliance Scores

Hopefully the correct place for a feature request. I’d love to see a way to get an overall compliance score. Not simply how many controls are missing things but an overall score based on efficacy of each compliance package. This gives a quick idea of our overall compliance and can be tracked year over year to show high-level improvement.

1 Like

Hi!, I agree 100% with this request, it would be great to get this Scores as a simple metrics or charts.

  • Package Compliance based on Package’s Compliance Analysis (“Ok” over all items. “Ok” equals 4 conditions: No Last Audit Failed, No Policy Review Expired, No Last Audit Expired, No Open Issues)

  • Control’s Last Audit (Passed over all items)

  • Policies (Not-Expired over all items)

I’m currently doing it manually every time by exporting CSVs from each module and building the charts offline for each compliance package (ISO27001, PCI-DSS, NIS2, GDPR, MLPS), filtered controls, and filtered policies. It would be great to see this improvement, Thank you.

It seems like the custom status feature would do what you’re wanting to do just fine. What’s missing from it for this?

Hi David, Custom Status is just reflected for each item individually, what is missing is showing the Scores as overall metrics or charts in the tool, so we don’t need to export and manually build each metric & chart in google sheets every time. Thank you

I understand the concept, but in my opinion having a global “Compliance Score” will only work in certain scenarios, and only if you agree with the default statuses and do not use any custom criteria/status to measure your Compliance score.

If you have solutions assigned to all your compliance items and all the default non-compliant statuses (audit failures, expired policies, expired audits, opened issues, etc.) are off, that would mean your compliance score is 100%, right?

But if you are tracking something custom for your score, let’s say your compliance requirements are reviewed by two teams, and both teams need to add a comment and give their approval, that is what defines a good score for you, because those teams have signed off on it, then your score criteria will be different.

That is exactly why Eramba has dynamic statuses, so you can decide for yourself what it means to be compliant and what score criteria you have. And because everyone can define that differently, building a global “Compliance Score” that satisfies everyone is quite a challenge :sweat_smile: