The BSTS point of view
Moving compliance from periodic evidence collection toward continuous control assurance.
The standard model is a questionnaire, a spreadsheet, a folder of screenshots, and a point-in-time assessment. It tells you what someone believed was true on the day they were asked. It does not tell you whether the control held for the eleven months in between.
Compliance is still mostly asking people whether things are true.
A questionnaire asking whether MFA is enabled
The actual configuration, read from the system
A screenshot taken the week before the audit
Evidence collected continuously, with a timestamp
A point-in-time assessment
Drift detected when the control changes, not months later
Evidence reassembled every cycle
Evidence that is already organized when the auditor asks
The model
From system evidence to audit-ready evidence.
Six steps, each feeding the next. The interesting property is that the last step stops being a project — the evidence an examination needs becomes a by-product of operating the control correctly.
Step 01
System evidence
Configuration and activity read from the systems themselves, rather than described by the person who administers them.
Step 02
Control validation
Compare what the system actually reports against what the control says should be true.
Step 03
Framework mapping
One validated control satisfies its corresponding requirement in every framework that asks for it.
Step 04
Drift detection
When a control stops holding, that is a finding on the day it happens — not a surprise during fieldwork.
Step 05
Remediation
A tracked, owned path back to the intended state, with the fix itself recorded as evidence.
Step 06
Audit-ready evidence
The artifact the examination needs, assembled as a by-product of operating the control.
Available today
Delivered in engagements now.
- Readiness assessment
- Control mapping
- Evidence organization
- Manual control validation
- Evidence automation where current systems support it
Future direction
Not available today. This is what BSTS is building toward.
- Continuous system evidence
- Automated control validation
- Drift detection
- Continuously organized assurance evidence
Where this stands today
This is the direction BSTS is building toward, not a product available today. In current engagements we apply the same thinking manually and automate evidence collection where a client's existing systems support it.
Common control framework
One control. Many frameworks.
Organizations that treat every framework as a separate program end up maintaining several overlapping security programs at once — duplicated policies, duplicated evidence, duplicated effort, and a different answer depending on who you ask.
The alternative is to define the control once, at the organizational level, then map it to each framework that asks for it. Where requirements genuinely differ, they stay separate. Where they overlap — and most access, logging, encryption, and change-management requirements overlap heavily — the work is done once.
One organizational control
“Access to production is granted by role, reviewed quarterly, and revoked within 24 hours of departure.”
- SOC 2
- NIST CSF 2.0
- ISO 27001
- HIPAA
- CMMC
Mapped once. Evidenced once. Answered everywhere it is asked — with genuinely unique requirements kept separate rather than forced into the overlap.
Frameworks we help clients map and prepare against
SOC 2
Trust Services Criteria readiness and evidence preparation
NIST CSF 2.0
Alignment across Govern, Identify, Protect, Detect, Respond, Recover
NIST SP 800-53
Control mapping and implementation support
NIST AI RMF
AI risk management alignment
ISO/IEC 27001
Control mapping and readiness support
HIPAA
Safeguard mapping and implementation support
NIST SP 800-171
Control implementation support for CUI environments
CMMC
Readiness and control-implementation support
CJIS
Policy-area mapping support
FedRAMP-related environments
Control-mapping support
BSTS provides readiness, mapping, alignment, implementation support, control validation, and evidence preparation. BSTS is not an accreditation body, a certification body, or an audit firm, and references to these frameworks do not imply certification, accreditation, or endorsement by any of their governing organizations.
An important distinction
BSTS does not issue SOC 2 reports. SOC 2 examinations and attestation reports are performed by qualified independent CPA firms.
BSTS prepares organizations for that examination: scoping, control inventory and mapping, gap assessment, remediation tracking, evidence preparation, and coordination with control owners. Where your systems support it, we automate the evidence collection so the next cycle costs less than the last one.
Start here
Find out what you could actually prove today.
The assessment includes a control and evidence review — which controls you operate, which you could demonstrate on request, and which currently exist only as intentions.
References to security and AI frameworks such as SOC 2, NIST CSF 2.0, NIST SP 800-53, the NIST AI Risk Management Framework, ISO/IEC 27001, HIPAA, and CMMC describe the practices that inform our methodology and the requirements we help clients prepare for. They do not imply certification, accreditation, endorsement, or an audit opinion. BSTS does not issue SOC 2 reports. SOC 2 examinations and attestation reports are performed by qualified independent CPA firms.