ORIGINAL REDDIT POST

How do you automate compliance assessments if you have MULTIPLE dependent organizations under you without compromising their security?

I am looking to find a way to automate a custom CSF compliance assessment over some multiple organizations under our authority and I do not know if there are already any solutions that allow that assessment to be automated and secure. What would be optimal is…

Original postr/cybersecurity

I am looking to find a way to automate a custom CSF compliance assessment over some multiple organizations under our authority and I do not know if there are already any solutions that allow that assessment to be automated and secure. What would be optimal is a GRC solution that checks actual technical controls automatically (e.g. Data Classification Tags in files metadata) but we wouldn't want to be too invasive not to be their single point of failure (Make them subject to supply chain attacks etc...)

Collected discussion

4 comments

u/Kwuahh

You want to automate checking technical controls for compliance without being invasive? That sounds like an oxymoron to me.

u/Every-Earth-1193OP

emphasis on "too" invasive. There are also other models that could be automated like Bring Your Own Evidence that wouldn't be invasive at all, but I just haven't found the right tools to avoid the manual overhead.

u/Different-Sleep5573

I’d avoid trying to directly control or deeply scan every organization’s environment. That can quickly turn your compliance program into a new supply-chain risk. A better approach is centralized visibility, but decentralized execution. Have each org keep control of its own systems, then collect evidence through limited, read-only integrations, scoped APIs, exports, or attestations. For technical controls, automate checks where possible, but only against metadata or evidence that is safe to share. So instead of becoming the system that has access to everything, you become the place where evidence, status, gaps, and risk are tracked consistently across all orgs. The goal should be: automate validation, not ownership.

u/OtheDreamer

OP is looking for easy security or must have a lot of risk tolerance for this future automated solution.

How do you automate compliance assessments if you have MULTIPLE dependent organizations under you without compromising their security?