Use case · Audit and Compliance

Evidence for the examiner who asks “show me” rather than “tell me.”

Control documentation describes the program you designed. An examiner increasingly wants the program you run. CINQUE produces observed behavior per persona, with the source of every assertion attached.

Entitled against observedProvenance on every entityEight regulatory frameworks
Book a Discovery WorkshopGet a demo
The problem

The gap between the control narrative and the environment.

Most evidence packages are assembled from exports, screenshots, and attestations gathered the month before the examination. They describe a point in time that was prepared for. What they cannot show is whether the control behaved that way for the other eleven months.

Attestation is not observation

A signed access review proves that somebody signed. It does not prove the access was appropriate.

Evidence is assembled, not produced

If the package takes six weeks of manual collection, it is a project, not a control.

Scope is asserted

Defining which systems are in scope from an asset inventory rather than from observed access is a guess with a signature on it.

Findings without provenance

An examiner's first question about any number is where it came from. A finding that cannot answer that is a finding you will defend twice.

What CINQUE does

What CINQUE produces for the file.

Entitled against observed, per persona
The reconciliation regulators keep asking for: what a role permits, next to what the identities in that role actually did.
The journey attached to every finding
Authentication through data access on one timeline, so a finding arrives with its own evidence rather than a pointer to another console.
Source system on every entity
Every entity CINQUE surfaces carries where it was observed, which is the provenance answer an examiner asks for first.
Scope derived from behavior
Protect surfaces mapped from observed access rather than from an asset list, so the scope you present is the scope that exists.
A baseline that persists
The documented normal is maintained continuously, so evidence is a query rather than a collection exercise.
Where the mapping lives

Framework mapping, by industry.

Industry
Frameworks mapped
Where the mapping lives
Healthcare
Proposed HIPAA Security Rule updates
Asset inventory, access management, and the observed evidence behind each. See the Healthcare datasheet.
Financial services and insurance
NYDFS Part 500, DORA, PCI DSS v4.x, CRI Profile
Entitled against observed access for privileged and non-human identities. See the Financial Services and Insurance datasheets.
Manufacturing and energy
IEC 62443, NERC CIP
IT and OT identities read together, with the crossing points made explicit. See the Manufacturing and Energy & Utilities datasheets.
Oil, gas, rail, and transportation
TSA security directives
Contractor and vendor access paths toward operational systems, with the full journey attached. See the Oil & Gas and Rail datasheets.

Framework mappings are carried in full in the industry datasheets, each of which maps CINQUE outputs to the specific control families that framework examines.

Scope

What CINQUE does not do.

Stated plainly, so nobody is surprised in month two.

  • CINQUE is not a GRC platform. It does not manage policies, track remediation tasks, or produce a certification.
  • CINQUE does not assert compliance with any framework. It produces observed evidence; your auditors and your second line draw the conclusions.
The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your first evidence package built from observed behavior.