Evidence first. Assurance connected.
Bring the work your organisation does, the requirements it follows and the evidence it produces into one connected workspace.
Show me the evidence!
An organisation running their operations according to a framework (such as ISO27001, SOC-2 etc) produces evidence every day: software upgrade logs, a reviewed change, the act of someone SSHing in from a VPN with an SSH key, an Ansible playbook run, a successful restore test, an access review, a supplier update.
Making that material useful for assurance takes context. Which requirement does it support? Which service and period does it cover? Who reviewed it? What needs to improve?
It also is recorded 'as it happens', whereas frameworks tend to be structured very strictly through 'Controls' and 'Clauses'. The order of these Controls makes sense to an auditor's brain, but the reality down here in the trenches is different.
I've spent a lot of time preparing for and undergoing audits with organisations. I would assemble all the most relevant procedures and other documents which explain how infrastructure is managed. I'd collect screenshots or hyperlinks to really good examples of CI/CD jobs, Pull Requests, and other records. However, come the actual audit time, I'd find out that the auditor wants to start with a specific Control. Very quickly, we would be jumping all over the place as I scrambled to find the right thing to show.
The frustrating part has always been that I know the evidence is there. But the order in which it made sense to me to show it, was not the way the auditor would see it.
Or, I'd show a document saying what we are supposed to do, but the act of proving that's what we do do, can be trickier.
Wouldn't it be great if all the actual raw evidence was already there and already mapped appropriately to the relevant Control?
Then the auditor could simply pick the Control they're interested in, immediately see evidence, with contextual remarks explaining why that evidence is relevant to the Control (since often evidence is very 'raw' and it needs context). They could then 'sample' that evidence, ideally very safely (e.g with redactions if necessary, as well as headers/footers annotating where it has come from).
You'd also ideally want that evidence to be near 'tamper-proof', e.g in some sort of immutable storage that helps assure its provenance.
And why not also map other 'entities' to Controls, such as the documents themselves, the recognised risks, the assets in your asset tracking system?
To actually ingest that evidence and have it automatically associated with your framework is really demonstrating that you aren't just compliant: instead, your organisation is demonstrating that it lives and breathes its ISMS, day in, day out.
So, I created KEEN - the Key Evidence Engine to connect those records with frameworks, risks, audits and the Information Security Management System (ISMS). Start with an event, trace it to a control, inspect the supporting material and record your assessment.
KEEN is free and open source software . You can run it on your own infrastructure, on-premises or in the cloud, and shape its framework definitions and evidence rules around your organisation.
Where KEEN fits alongside other products
A lot of products out there are 'lip service'. You spend a lot of money on a risk management platform. But all you really get to do is tick some boxes saying 'yes, we do that'. You also pay through the nose, usually by headcount, via sales consultants under pressure to meet KPIs.
KEEN offers an open source, self-hostable approach for organisations that want to work directly with the underlying evidence and tailor the system themselves.
The starting question is: what demonstrates that this practice is operating in our organisation? In KEEN, you define how your operational events relate to your requirements, retain their context, and use them in a continuing programme of measurement, review and improvement.
That is useful when your evidence lives in bespoke systems, your business practices need specific mapping rules, or you want control over hosting and development. You choose the environment, maintain the source systems that provide the data, and decide how the assurance model evolves.
Collect from the systems you already use
Built-in ingesters in KEEN are like presets - they come with the product out of the box. These include GitHub, GitLab, Forgejo, Gitea, Jenkins, Redmine, Loki, Amazon CloudWatch Logs, Google Workspace, Taiga, BookStack and RSS/Atom feeds. You can also push data to authenticated KEEN webhooks, and add manual 'diary' evidence.
KEEN Agent is a complimentary open-source daemon which can be installed on your Linux servers. It collects things like journal syslog messages, nginx requests, package-manager activity, auditd records, and even OSSEC json logs. This is useful if you're not already shipping your logs to a central service like Loki.
For a bespoke service, there is also a API ingester builder. This lets you construct completely unique-to-you HTTP requests, credentials, pagination and event extraction in the web UI, which will then call those endpoints of your bespoke services, and attempt to ingest the response. Compatibility depends on the remote API's authentication and response format.
Redaction and masking help limit sensitive data entering evidence workflows. Administrators can pause collection and set evidence retention policies, with protection for records sampled into audits.
Map once, review the evidence in context
Mapping the evidence to controls is an act of curation - it often is spiky at the start until you climb the curve of your evidence 'patterns'.
To make it easier, you can pick an existing event and create a mapping rule from it to apply to it and all similar events both retrospectively and into the future. Keep the fields that matter, choose its framework targets, and preview matching and nonmatching records. A software-maintenance rule might select package activity; a more specific web-server rule might select a status code, path and client network.
Many organisations need to comply with multiple frameworks. KEEN includes many framework catalogues thanks in large part to work performed by others to collate and cross-reference those controls. KEEN offersr a framework editor so that you can edit or add new frameworks as you need. You can enable the frameworks your organisation needs.
For me, a killer feature that exists in KEEN is that you can associate the controls from one framework to another - what this means is that any evidence arriving and mapping to one framework's controls, automatically will map to that other framework's controls, without you needing to do anything at all!
Of course, when writing mapping rules, you can also explicitly map any number of specific controls to that evidence pattern.
Keep the ISMS connected
Most certified organisations have a wide range of documents, spreadsheets, matrices and the like in a range of different systems.
KEEN makes it possible to manage assets, people, organisational roles and charts, suppliers, access-control matrices, objectives and meeting minutes - all alongside your other ingested evidence. This means that those entities are also able to be 'related' to Controls directly. Once you start to build those relationships, you can also visualise them in interesting ways.
Write policies and procedures directly in KEEN, retain document revisions, upload existing material or link to external documents. If you are using BookStack, integration with its API can mean you can associate even specific parts of a book or a shelf to your framework.
Risk registers bring together inherent and residual assessments, 5×5 heatmaps, treatment plans and ownership by a person or organisational role. There is support for CIA (Confidentiality, Integrity and Availability) risk models, as well as PESTLE.
Not sure how to categorise your risks? The KEEN Mitigator uses a natural-language (not AI!) analysis of your description to suggest both controls that may apply as mitigation, and whether you or someone else has already defined a similar risk, to help keep your data hygiene nice and healthy.
KEEN also ships with its own informal 'KEEN Assurance Framework', as inspiration for both modelling your organisation against Controls and as a reusable 'risk library' for you to pick and choose which pre-defined risks are relevant to your business.
Measure whether the practice is effective
This is the crunch point for the auditors. It's all well and good to say you try to reach five nines, or that your data recovery procedures hope to reach a Recovery Time Objective of 20 minutes, but do they, in practice?
In KEEN you can define an 'effectiveness measurement', its unit and thresholds (be it time, percentage, a count, greater than or less than or equal to, etc), then record observationsL: either manually (with evidence!), or automatically through an inbound metric webhook from the systems that generate those metrics. KEEN gives you copyable Python and curl payload examples that KEEN expects to receive on those webhook endpoints, to help connect those reporting systems easily.
For example, measure the percentage of critical patches completed within an agreed SLA. Retain the reporting period and supporting evidence, compare the result with its target, and investigate any missed threshold.
As always, those effectiveness measurements can be directly mapped to Controls! This means the auditor, when viewing a Control, can easily find those measurements from the same page.
Audit, sample and improve
Schedule recurring audits or begin an on-demand review. Set its scope, sample evidence into the audit, document OFIs or non-conformities, and retain the assessment. Evidence can also be downloaded for review. Scope-gap views help identify areas that still need audit attention.
Auditors can questions about an event (they frequently need more context). Those and their answers are kept alongside the evidence. For more formal issues arising out of evidence, incidents can also be declared, which can integrate with your own ticket system for follow-up.
Managing use of KEEN
KEEN has its own local user management system with full RBAC for controlling who can do what, as well as support for security keys and TOTP Authenticators to help secure accounts with 2FA. An audit log also exists for actions taken in KEEN, so you can even audit the audit system!
If you don't want to use the local user auth, there is support for SSO (Google, Github, bring-your-own OpenIDConnect, or LDAP).
Work with the person who built it
Like all open source software, the onus can sometimes be on you to keep it running well. But it doesn't have to stop with you.
As KEEN's inventor and developer, I also offer professional services to help your organisation put it to work:
- Install and operate: deployment in your chosen hosting environment, configuration, upgrades, maintenance and ongoing operational support.
- Connect and adapt: ingester setup, evidence mapping, additional features and custom development for your services and workflows.
- Migrate your ISMS: I can help bring existing policies, assets, risks, ownership and evidence systems into KEEN, with a practical plan for populating and maintaining the records.
- Shape your assurance programme: If you're new to compliance, I can work through your specific framework requirements and business practices to define useful evidence, measures, mapping rules and audit routines, to help you get closer to that certification!
KEEN is a means to an end, but that end is seriously impressive: a populated, maintainable system that reflects how your organisation works - not because you say so, but because it proves it, before the auditor even has to ask.
Contact me to discuss your implementation or migration .
Try KEEN
If you need convincing, you can start a free 30-day demo at keen.cloud . Allow 5 to 6 minutes for your private, free instance to be prepared. The demo will be seeded with fictional sample records to help give a sense of the experience.
After 30 days, it will shut down and delete itself automatically. There is no obligation to continue with a paid engagement unless you want to get in touch!
You can also read the handbooks or download the illustrated brochure if you want to pass on some succinct detail to your auditor or Q/A team.
If you're 'keen', I'd love to hear from you!
- The Key Evidence Engine: evidence, frameworks, risks and audits in one workspace
- Free and open source, on-premises or in the cloud
- Ingesters for GitHub, GitLab, Forgejo, Jenkins, Loki and more