Knowledge Base

Prev Next

Overview

The Compliance Controls Knowledge Base is the central repository for your organization's DataBee compliance control documentation. It provides a structured way to manage controls, map them to industry frameworks (like NIST CSF, PCI-DSS, or CIS), and track the evidence and metrics required for successful audits.

This feature allows compliance officers and control owners to:

  • Centralize Documentation: Keep all control descriptions, owners, and guidance in one place.
  • Track Performance: Define target benchmarks and metrics.
  • Map to Frameworks: See exactly which controls satisfy specific regulatory requirements.
  • Export Artifacts: Generate auditor-ready PDF documentation with a single click.

Getting Started

To access the Knowledge Base, navigate to Knowledge Base in the sidebar or go directly to:
/compliance/documentation

On the homepage, you can also find a quick link under the Knowledge Base feature card.


1. Control Listing & Search

The main page displays a comprehensive list of all controls you are entitled to view.
Image

Key Features:

  • Search Bar: Quickly find controls by typing their name, ID, or keywords in the search box at the top of the table.
  • Sortable Columns:
    • Dashboard: The name of the control or associated dashboard.
    • Summary: A brief overview of the control's purpose.
    • Owner: The individual or team responsible for the control.
    • Last Updated: The timestamp of the last modification.
  • Instant Access: Click on any dashboard name to view its full details.
  • Quick Download: Use the download icon in the "Action" column to immediately export a PDF for that specific control.

2. Control Detail View

Each control has a dedicated page providing a "360-degree view" of its implementation.
Image

Detail Sections:

  • Hero Section: Displays the primary title and summary.
  • Key Metrics Strip: A high-level ribbon showing the Owner, Target Benchmark (e.g., ">= 95%"), and Last Updated date.
  • About This Control: Detailed implementation guidance and the specific purpose of the control.
  • Why It Matters: Explains the business value and the specific risks (e.g., "Shadow IT", "Unmanaged assets") addressed by this control.
  • Control Definition: Technical details, including links to internal policies and support information.
  • Status & Compliance: Breakdown of the target metric, including the Numerator (what is being measured) and Denominator (the baseline).
  • Related Resources: Links to associated dashboards, evidence tables, or external documentation.
  • Sidebar (Quick Reference):
    • Communications: Teams channels and email distribution lists for the owners.
    • Escalation: Direct contacts and office hours for escalation paths.
    • Data Sources: The technical systems feeding data into this control (e.g., "CrowdStrike", "AWS Config").
    • Framework References: Direct mappings to standards like NIST CSF v2.0 or PCI-DSS v4.0.

3. Managing & Editing Controls

Authorized users can customize control documentation directly from the browser.

How to Edit:

  1. Navigate to a control's detail page.
  2. Click the "Edit" button on any card or section.
  3. A dialog will appear allowing you to modify fields like summaries, target values, owners, or guidance.
  4. Click "Save" to apply changes. Modifications are tracked and the "Last Updated" timestamp will update automatically.

Resetting Changes:

If you need to revert a control to its original pre-seeded state, click the "Reset to Defaults" button in the top header. Note: This will permanently remove all custom overrides for that control.


4. Exporting for Audit (Audit Readiness)

Auditors often require point-in-time snapshots of control documentation to prove governance.

  • PDF Export: On any control detail page, click the "Download" button. This generates a professionally formatted PDF document containing:
    • Ownership and Escalation info.
    • KPI definitions and targets.
    • Evidence references and data source lineage.
    • Framework mapping.

5. Common Use Cases

For Compliance Analysts

  • Interpret Evidence: Click through to CCM dashboards to see live compliance data.
  • Support Audits: Export PDF artifacts for controls during audit cycles.

--