Security & compliance

GDPR Compliance Tool

Evidence-based GDPR compliance scoring by article category, with trend deltas and catalog provenance.

The GDPR Compliance page provides an automated, evidence based assessment of your security posture against GDPR oriented technical control categories.

It combines scan evidence, agent test-run summaries, category scoring, finding severity, control catalog provenance and coverage metadata so teams can track risk and remediation readiness. Customer-visible controls are backed by executable technical checks; controls that cannot be evaluated from available evidence are marked not evaluable instead of treated as passing.

Accessing GDPR Compliance

  1. Use the GDPR Compliance widget for a compact summary.
  2. Open the full GDPR Compliance page for category-level findings and catalog details.

Data Scope and Source

The GDPR report is generated from recent account-group evidence already stored by CyfroSec, including:

  1. Network Discovery data
  2. Fingerprint/vulnerability scan data
  3. Asset Discovery data
  4. Endpoint-agent coverage and test-run summaries
  5. Bounded correlated relationship summaries

By default, the page shows account-group aggregate compliance posture. If no account group is selected, the page prompts you to select one.

Page Overview

The full page includes:

  1. Header and Controls
  2. Overall Score
  3. Scan Data and Catalog Metadata
  4. Category Breakdown with Drill-Down Findings

GDPR compliance page with an overall score, evidence window, and scored control categoriesThe full GDPR page: overall score, evidence window, and per-category control scoring with drill-down findings.

Header and Controls

Top actions:

  1. Refresh: Triggers report recalculation for the selected account group and reloads the page data.
  2. Refresh Catalog: Reloads report/catalog status. Catalog imports and remapping are CyfrOne admin operations and are not required for normal customer reporting.

The header also shows report timestamp and account-group context.

Overall Score

The top panel displays:

  1. Overall score (0-100)
  2. Score label (for example: Excellent, Good, Needs Improvement, Poor, Critical)
  3. Trend delta when historical points are available
  4. Critical, High, and Total finding counts
  5. Evidence coverage percentage
  6. Not-evaluable control count

Scan Data Window

When available, the page displays the report's scan data time window:

  1. Window start timestamp
  2. Window end timestamp

This helps confirm the evidence period used for evaluation.

Category Breakdown

Each category card shows:

  1. Category name and GDPR article reference
  2. Category score
  3. Finding count
  4. Severity breakdown chips
  5. Expand/collapse interaction

Categories are sorted by score (lower scores first) on the full page to surface higher-priority gaps.

Severity Filter

You can filter visible findings by severity: All, Critical, High, Medium, Low, Info. Selecting a severity auto-expands categories that contain matching findings.

Finding Details

Expanded findings include:

  1. Title and affected asset/resource
  2. Severity
  3. GDPR article reference
  4. Description
  5. Remediation guidance

Catalog Provenance and Health

The page includes a catalog section to show how controls were evaluated.

Catalog Provenance

Displays:

  1. Catalog version
  2. Catalog generation timestamp
  3. Source summary cards (display name, authority/type, status)
  4. Seeded curated catalog metadata, when the active version was created from the built-in executable catalog pack
  5. Mapping pack version and deterministic source fingerprint, when available

Catalog Health

Displays:

  1. Control count
  2. Source count
  3. Evaluation mode
  4. Sync/import status for CyfrOne-managed catalog operations
  5. Not-evaluable count for controls missing sufficient evidence

This metadata supports auditability and trust in control mapping.

Seeded Technical Catalogs

CyfroSec ships deterministic executable compliance catalogs for GDPR, CCPA/CPRA, SOC 2, and NIST CSF. Each customer-visible control maps to at least one technical check function so the UI can show whether the available evidence passes, fails, or is not evaluable.

ISO/IEC 27001 source metadata may exist for CyfrOne administrators, but it is not shown to customers until CyfroSec has an approved executable control pack for that framework.

Widget vs Full Page

Dashboard Widget

The dashboard GDPR card provides a compact snapshot:

  1. Donut score
  2. Trend delta
  3. Critical/High/Total quick counters
  4. Category score mini-bars
  5. Manual refresh button

Full GDPR Compliance Page

Use the full page for:

  1. Severity filtering
  2. Category-by-category finding drill-down
  3. Catalog provenance and health
  4. Evidence coverage and not-evaluable controls
  5. Scan data window review

Empty, Pending, and Error States

  1. No Account Group Selected: Prompt shown to select an account group first.
  2. No Report Yet: If no report exists yet, the page shows an empty state and allows manual generation via Refresh.
  3. Pending/Timeout Cases: If processing is still underway or times out, the UI may show a wait-style message indicating report generation is in progress.
  4. Error State: If loading fails, an error panel appears with retry capability.

Frequently Asked Questions

What does evidence coverage mean? It indicates how much of the control set had sufficient scan evidence for evaluation.

What are not-evaluable controls? Controls that could not be reliably evaluated from the available evidence window.

Why does score sometimes drop after new scans? New evidence can surface additional findings or change control outcomes.

Why is a framework missing from the compliance page? Frameworks are shown only when they have a published executable catalog. Source-only frameworks are hidden until their controls have approved technical checks.