A.8.8
Management of technical vulnerabilities
- Status
- ASSERTED
- Evidence
- vuln_tracker_v4_FINAL.xlsx
- Last updated
- 94 days ago
- Owner
- left the company in March
Verified by
Nobody. The file says the control is met, but it contains no supporting evidence.
ISO/IEC 27001NIS2DORAGDPR
Kombine connects to your cloud accounts, Microsoft 365, endpoints, scanners and code. It builds your asset register, links findings to the right assets, and re-checks controls on a schedule you choose. When an auditor asks for proof, it is already there, with a source and timestamp.
From 166 EUR per month. One price for the whole company. No per-user or per-asset fees.
Hosted in the EU, or run on your own hardware.
| 14:22:07 | azure | defender.recommendations, 312 | SYNCED |
| 14:21:55 | endpoint | WS-4471, collector 2.6.1 heartbeat | OK |
| 14:20:18 | m365 | config.purview, retention policy changed | DRIFT |
| 14:19:40 | control | A.8.8 re-evaluated against 4 sources | MET |
| 14:18:02 | openvas | scan 2291, 216 hosts, 41 new findings | DONE |
| 14:16:44 | sonarqube | billing-api, 2 high severity | RAISED |
| 14:15:09 | entra | 4 privileged accounts without MFA | RISK |
| 14:13:31 | wazuh | agents reporting, 214 of 216 | OK |
Example data shown to illustrate how an evidence record looks.
The problemwhy compliance goes stale
That is why compliance becomes a yearly scramble. Someone checks a system, writes down the result, attaches a file and sets a reminder to do it again next year. The register is accurate on the day it is filled in, then it starts to age. When the auditor arrives, weeks disappear into rebuilding evidence that was once correct.
Kombine closes that gap by reading the systems directly.Every control shows which sources support it and when each source last reported.If a setting changes or an agent stops reporting, the control changes state and the owner gets a notification.
The recordone control, two realities
A.8.8
Verified by
Nobody. The file says the control is met, but it contains no supporting evidence.
A.8.8
Verified by
| Defender for Cloud | 312 findings, 0 critical open | 14 min |
| OpenVAS | scan 2291, 216 hosts in scope | 2 h |
| Wazuh agents | 214 of 216 reporting | 6 min |
| SonarQube | 4 repositories, SAST clean | 3 h |
Also satisfies
NIS2 Art. 21(2)(e)
DORA Art. 9(4)
NKSC baseline 4.3
Methodfrom collection to evidence
Use read-only credentials for cloud and SaaS, a signed agent for Windows and Linux, and an API token for scanners. Most customers start collecting evidence within one working day.
AzureAWSGCPMicrosoft 365DefenderIntuneEntra IDActive DirectoryESETWazuhOpenVASOWASP ZAPGitHubGitLabSonarQubeLansweeperSARIFNetwork sweep
A server seen in Azure, Defender, your EDR and a vulnerability scan is still one asset, not four. Ownership, classification and audit scope stay with that asset. A sync never overwrites a decision made by a person.
Asset registerAsset profilesDependency mapAttack paths
Each control is evaluated against the current asset register on your schedule. AI can draft a risk entry for a real finding and reduce noise, but a person approves it. When something drifts, Kombine creates a ticket with an owner and a deadline.
Control monitoringRisk registerNon-conformancesSLA tickets
No last-minute evidence hunt. Auditor exports, regulatory filings and management reports all use the same records, and every number can be traced back to the system that produced it.
Auditor exportNKSC filingDORA registerVDAI notificationBoard report
Contentswhat is available today
No tiers. No feature gates. Open a group to see the modules. A teal dot means the data comes from a connected system, not from manual entry.
registers and records
Modules 9Live connected 0
what you own
Modules 9Live connected 5
continuous
Modules 9Live connected 8
on demand
Modules 9Live connected 1
day to day
Modules 9Live connected 0
how you run it
Modules 9Live connected 0
Scopewhat you enable
Directive (EU) 2022/2555
Use the Article 21 measures as a live control catalogue, with incident reporting in the format NKSC expects. The 24 and 72 hour deadlines become tickets with reminders and a named owner, instead of a note in someone's calendar.
Art. 21 measures
Art. 23 reporting
NKSC filing export
2022 revision
Track all 93 Annex A controls with scores and evidence in the same record. The Statement of Applicability is generated from that data, so it stays aligned with what your controls actually say.
93 Annex A controls
Statement of Applicability
Internal audit trail
Regulation (EU) 2022/2554
Build the Article 28 Register of Information from the ICT provider and contract records you already keep, then export it as xBRL-CSV for the Lietuvos bankas Regata submission.
Art. 28 register
xBRL-CSV export
ICT third-party risk
Regulation (EU) 2016/679
A personal data incident starts its 72 hour clock to VDAI. If a notification is late, record why. If you decide not to report an incident, keep the justification in the register.
Art. 33 notification
VDAI form
Non-reportable register
Walkthroughwe reply within two working days
A 30-minute walkthrough with your frameworks enabled and one of your real systems connected. You will see what Kombine collects, how controls are checked, and what your next audit could look like.