Table of Contents
Summary
The Assurance Center assists visitors to your profile in quickly accessing information on the security status of your product or organization.
To use the Assurance Center on a Whistic Profile, the following criteria must be met:
- It is only available for paid profiles (Basic Profiles are not eligible)
- The Whistic Profile must be set to Subscription (Snapshot profiles are not eligible)
The Assurance Center is specific to each selected profile. If you have multiple profiles, you will need to set up the Assurance Center for each one individually, as different products may have unique content you wish to highlight.
Steps
- Navigate to the Whistic Profile section in Whistic and select the profile on which you would like to enable the Assurance Center.
- Click "Edit Profile" and scroll down to the Assurance Center section. Click the arrow to expand the section if it is collapsed
- When the Assurance Center is expanded you will see "Domains" and "Sub-domains" in a table with toggles next to the name of each. The toggles control the visibility of the Domain or Sub-domain. If the toggle is grey then that Subdomain or entire Domain will not be visible in your profile. There is also a toggle at the top to turn off the visibility for the entire Assurance Center. Make sure the top level toggle is in the On (blue) position and all Domains and Subdomains have the toggle turned on so that the Assurance Center will appear as you intend within your profile.
- To add content, click on a Domain and then click a Subdomain that you would like to show in your Assurance Center. When you click the Subdomain, a panel will appear with:
- Control Definition
- Compliance Selection Dropdown
- Evidence Section-
- Evidence from Questionnaires
- Comment Section
- Documents
-
- For a subdomain to appear in the Assurance Center, you must add at least one of the following in the panel:
- Select a Compliance Status
- Add a Questionnaire Answer
- Add a Comment
- Add at least one Document
If you turn the visibility toggle for a subdomain to the ON position but do not add at least one item from the list above, then the subdomain will still not be visible in your Assurance Center as there is no content to show.
- Select a Compliance Status ( Not Required)
- Select a Questionnaire Answer as Evidence (Not Required)
If you have existing questionnaires available in your profile it is possible to use the answers from these previously completed questionnaires as evidence. We have mapped the answers from specific standard questionnaires to the subdomains in and controls in the Assurance Center so if you have completed a questionnaire with an answer that is mapped to an Assurance Center subdomain/control you have select to showcase that answer by clicking the check box next to the questionnaire answer. You can select as many answers as you wish to include. If there are no answers available to select this means that you do not have an existing questionnaire completed with an answer that is mapped to that subdomain/control. Completing additional questionnaires and adding those questionnaires to your profile will help you to complete the Assurance Center setup faster and make your profile stronger.
- Add a Comment
Click the check box to include a Comment. You can type or copy/paste a comment in the provided text box. The comment section also accepts hyperlinks, feel free to include those here as well.
- Add a Document
Click the "+" icon to add a document as evidence.
The documents must be added to your profile and available in the Additional Documents section of your profile to be included.
After clicking the "+" icon a popup will appear. Select the document you want to add as evidence and click "Submit".
Click the Trash icon to remove the document from the evidence - Repeat these steps for all Domains and Subdomains you want to showcase in your Assurance Center and make sure to turn all the visibility toggles to the ON position.
- Check by Downloading the Assurance Center
If you want to check all the information that you have included in the Assurance Center, click the Download icon to download a CSV where you can verify all the domains, subdomains, and evidence that will be visible in your profile. The download functionality will only download information that you have completed and turn the toggle to the ON position. The download functionality will also be profile viewer-facing so that customers can download all content you have made visible as well. - Click "Done" to publish the Assurance Center to your profile.
Current Mapped Questionnaires
Below is a list of the questionnaires currently supported for mapping to the Assurance Center if added to your Whistic profile:
- Custom BCBS Questionnaires
- CAIQ
- CAIQ Lite
- CIS Top 5
- CIS Top 20
- SIG
- SIG Core
- SIG Lite
- SIG Full
- VSA
- VSA Core