Help center

Help center

All collectionsControlsOperate and testConnect reporting systems and monitor reporting health

Connect reporting systems and monitor reporting health

Register an external system that checks your environments, give it a signing key and the checks it may answer, decide what counts as passing, and find out quickly when it stops reporting or its reports are refused.

Register an external system that checks your environments, give it a signing key and the checks it may answer, decide what counts as passing, and find out quickly when it stops reporting or its reports are refused.

Some controls are best checked by a machine: a cloud configuration scanner, an endpoint agent or a scheduled script. A reporting system is such a check that you run yourself. It sends ComplyTrain signed reports of what it observed, for example "examined 47 storage buckets, 47 encrypted". ComplyTrain holds no credentials for your systems and the reporting system never says whether the control passed: ComplyTrain decides that from the counts, using thresholds you set.

Who can set this up

Product location: /qms/controls/producers. Open Reporting systems in Controls.

Task

Permission

Register, enable or disable a reporting system; issue and revoke signing keys; create, enable, disable or delete bindings; set up and use Check now

Manage the estate (controls:manage_control_targets)

Add the implementation the system answers, record its design review and thresholds

Manage controls (controls:manage_controls)

Read Reporting systems, Reporting health and the reports received

View controls (controls:view_controls)

Organisation administrators can do all of these. Your plan sets how many implementations can be reported by an external system; see plan limits.

Prepare the implementation

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and choose the Where it runs tab.

A reporting system answers one or more implementations of your controls. Before you connect it, add the implementation on the control's Where it runs tab:

  1. Choose Add.

  2. In How it is carried out, choose Reported by an external system.

  3. In Runs on, choose the environment the system checks, for example the production AWS account.

  4. In How often, choose a schedule. A schedule is required, because the due date is what makes a missing report show as overdue.

  5. Select Start it running straight away, or switch it on later with Switch on. Reports for an implementation that is not running are refused.

Nothing is created for anyone to do. When a check falls due, ComplyTrain simply expects a report. See where and how a control operates.

Register a reporting system

Product location: /qms/controls/producers. Open Reporting systems in Controls.

  1. Open Reporting systems in Controls.

  2. Choose Register a system.

  3. Complete the fields and choose Save.

Field

What to enter

Limits

Code

The identifier the system sends with every report, for example cspm-prod.

Required. Letters, digits, dot, colon, underscore or hyphen; 2 to 100 characters; unique. Cannot be changed later, because renaming it would break the running integration.

Name

What the system is, for example "Cloud posture scanner (production)".

Required, up to 300 characters.

Who to contact

The email address of whoever runs the system.

Optional, up to 320 characters. Shown on Reporting health so someone knows whom to chase.

The system appears in the list with the state Never reported. Choose Manage to open its settings.

Issue a signing key

Product location: /qms/controls/producers. Open Reporting systems in Controls.

The system signs every report with a key, and ComplyTrain checks the signature. The key never travels with the report.

  1. In the system's Signing keys section, choose Issue a signing key.

  2. In Your signing key, choose Copy and paste the key into the reporting system's secure configuration.

  3. Choose I have saved it.

The key is shown only this once; nobody, including support, can look it up again. If it is lost, issue a new key and revoke the old one.

A system can hold two keys at once, so it can move to a new key on its own release schedule. To rotate: issue the second key, install it, wait until its Last used time shows it is signing, then choose Revoke on the old key and confirm Revoke key. A revoked key stops working immediately. While both slots are in use, Issue a signing key is unavailable.

Bind it to its checks

Product location: /qms/controls/producers. Open Reporting systems in Controls.

A binding lets the system report on one implementation, and nothing else. The bindings are listed under What it may report on, with Control, Environment, Binding reference and Reporting.

  1. In the system's settings, go to What it may report on.

  2. Add a binding and choose the implementation. Only implementations carried out by Reported by an external system can be chosen.

  3. Give the Binding reference to whoever configures the reporting system. It identifies the check the system is answering.

An implementation can have only one active binding. To move a check to a different reporting system, disable the old binding, then bind the new system. A binding that has never received a report can be deleted; once it has reported, disable it instead so its history stays. Disabled bindings show Disabled.

Let it know when to check

Product location: /qms/controls/producers. Open Reporting systems in Controls.

A reporting system always finds its work by asking ComplyTrain what is due, which works even from inside a network ComplyTrain cannot reach. Optionally, ComplyTrain can also call the system to say there is something to check now.

Setting

Options and rules

Can we tell it to check now?

No — it asks us when it is ready (default) or Yes — call this address.

Address to call

For Yes — call this address only. A public HTTPS address; addresses inside private networks are refused. Each call is signed with the system's own key.

Choose Save. If calls fail, the section shows Failing: 3 consecutive attempts and when the address was Last reached.

To ask for a result now, choose Check now on a binding. The result says how many checks were notified straight away, how many will be picked up at the system's next check and how many could not be reached. For a system that only asks, the page reminds you it will pick the work up on its next check. A successful notice does not mean a result has arrived; watch Reporting health.

Review the check's design

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose the Where it runs tab and choose Review design on the implementation.

A report says how many items passed the check, not whether the check was worth running. Until a person reviews its design, the control's effectiveness stays Not yet known, however many good results arrive.

  1. On the control's Where it runs tab, choose Review design on the implementation.

  2. Under Record a review, answer Is this check well designed? with Yes — it would catch what this control is for or No — it would miss the thing this control is for.

  3. Write What did you conclude?; it is required when you mark the check deficient.

  4. Choose Record the review.

If the implementation's configuration or frequency changes later, the headline changes to This check has changed since it was reviewed and the control returns to Not yet known until someone reviews it again. Withdraw the review removes your review.

Under What counts as passing, set the thresholds and choose Save thresholds:

Field

Meaning

Default

Passing percentage

Share of examined items that must be satisfactory for the result to read fully effective.

100%, so every item must pass.

Partially effective from

At or above this share, a result reads partially effective rather than ineffective.

1%, so only a complete failure reads ineffective.

Leave a field empty to inherit the value shown as Currently inherited. When you save, results already received are re-evaluated. Any result whose verdict changes is kept and marked as replaced, with the reason.

Read what it sent

Product location: /qms/controls/producers. Open Reporting systems in Controls.

On a binding, choose View what it sent. Reports received lists every report, newest first, with Received, Outcome (Accepted or Refused), What it found, for example 44 of 47 passed, and Period.

Each accepted report is recorded as a test result for the check that was due, and counts toward the control's effectiveness like any other test. A refused report records nothing but its reason. A report with a wrong or missing signature is not recorded at all, so it looks like silence.

Monitor reporting health

Product location: /qms/controls/reporting-health. Open Reporting health in Controls.

Open Reporting health in Controls; its Reporting systems link returns to the list of systems. Automated checks counts every active binding; the other tiles count them by state. Choose a tile to filter the table and read advice for that state.

State

Tile

Meaning

Who should act

Reporting

Reporting normally

Reports are arriving within the expected interval.

Nobody.

Never reported

Never reported

Nothing has been accepted since the binding was created. Usually the setup: wrong key, wrong binding reference, or the system was never deployed.

Whoever set up the system.

Stopped

Stopped reporting

It reported before but has been silent for more than twice its schedule, for example more than 2 days for a daily check or 62 days for a monthly one.

Whoever runs the system, or the owner of what it watches.

Being refused

Being refused

Reports are arriving and being refused. The latest reason is shown under the state.

Whoever runs the system.

The table shows Control, Reporting system with its contact, State, Last reported or Never, and Waiting: how many due checks are still waiting for a report. An implementation's missing report also shows as overdue on the Due board.

The Automated Control Reporting Health report in Reporting gives the same states as a report you can export and schedule.

Fix a silent or refused check

Product location: /qms/controls/producers. Open Reporting systems in Controls.

What you see

Check

Never reported, nothing under Reports received

The system has the current signing key, the right code and the right binding reference, and it is actually running.

Being refused

The refusal reason. Common causes: the implementation is not running, the environment has been decommissioned, or the report's period or counts are invalid.

Stopped

The system itself, and whether it can still reach ComplyTrain. Contact the person in Who to contact.

Check now reports failures

The Address to call is reachable from the internet and accepts the signed call.

Disable a system

Product location: /qms/controls/producers. Open Reporting systems in Controls.

Choose Disable this system to stop every binding of that system at once, for example when it is decommissioned or a key may be compromised. Enable this system turns it back on. Disabling keeps the system, its bindings and every report it sent, because those reports are evidence of what was answered.

Example: nightly encryption scan

Product location: /qms/controls/producers. Open Reporting systems in Controls.

Your control "Encrypt stored customer data" must hold on the production AWS account.

  1. On the control's Where it runs tab, add an implementation Reported by an external system, running on the production AWS account, Every day, switched on.

  2. Register the system cspm-prod, "Cloud posture scanner (production)", with the platform team's address.

  3. Issue a signing key and hand it to the platform team through your password manager.

  4. Bind cspm-prod to the new implementation and send the Binding reference to the platform team.

  5. Choose Review design, record Yes — it would catch what this control is for ("scans every bucket, including new ones"), and set Passing percentage to 100.

  6. Next morning, Reporting health shows the binding as Reporting, and View what it sent shows 47 of 47 passed. The control's Tests tab shows the result.

  7. Weeks later the binding moves to Stopped. The contact finds the scanner's credentials expired, fixes them, and reports resume.

Did this answer your question?
😞
😐
😁