Compliance program
Understand how frameworks, controls, measures, tasks, evidence, and applicability records connect
A Probo organization is the boundary for a company’s compliance records and memberships. Inside it, a compliance program connects external requirements to the work and proof that demonstrate how those requirements are met.
Core model
Section titled “Core model”- A framework groups requirements from a standard or a custom program.
- A control describes an outcome the organization is expected to achieve.
- A measure describes what the organization actually operates to satisfy one or more controls.
- A task assigns a concrete piece of work, optionally with a due date.
- Evidence is a file or URL supporting the operation of a measure.
Controls and measures are many-to-many. A reusable measure such as an access review can support controls in several frameworks, which avoids duplicating the same implementation work.
Applicability
Section titled “Applicability”A Statement of Applicability records which controls apply to an organization and why. It is versioned separately from day-to-day measure work so teams can review and publish a deliberate scope.
Program records
Section titled “Program records”Frameworks, controls, measures, tasks, evidence, risks, documents, audits, and obligations can be linked rather than copied. These relationships provide traceability from a requirement to its implementation, supporting material, risks, and audit results.
Publishing a list or statement creates a stable representation for review. Draft records remain editable until the responsible team is ready to publish them.
Ownership and access
Section titled “Ownership and access”Organization membership determines access to the program. Assign work to named users and use the audit log to investigate important changes. SSO and SCIM manage access to Probo itself; access reviews review access imported from Probo and connected systems.