Controls that exist outside the spreadsheet.

Compliance depends on working technical controls. CraftSupport implements, documents and maintains the infrastructure evidence that sits behind your policies.

We walk your current environment against the framework you are being assessed on, and tell you which controls already hold.

The controls we help operate.

Delivered as part of ordinary server management, not as a separate compliance project.

Private administration

Named accounts, key-based access, least privilege, MFA options and reduced public exposure.

Security patching

Scheduled package updates, supported rebootless kernel patching and documented maintenance windows.

Monitoring & alerting

Availability, capacity and security signals routed to someone able to investigate them.

File change monitoring

Detection and review of unexpected changes to important system and application paths.

Logs & retention

Centralised records, useful retention periods and a clearer investigation history.

Verified backups

Off-site, versioned backups with integrity checks, restricted deletion and documented restoration.

Which part of the stack answers which obligation.

The controls below are delivered as part of ordinary server management, not as a separate compliance project.

Infrastructure controls mapped to compliance obligations
ControlObligationWhat it doesTooling
File integrity monitoringPCI DSS 11.5Detects unauthorised modification of critical files and alerts on change. Required for merchants handling cardholder data.Wazuh
Log collection and retentionPCI DSS 10Records and retains access to system components so an incident can be reconstructed afterwards.Wazuh
Vulnerability detectionPCI DSS 6, 11Continuously identifies unpatched packages and known CVEs on the host.Wazuh
Security patchingPCI DSS 6.3Critical patches are applied promptly. Rebootless kernel patching removes the usual reason for delay.KernelCare
Access control and segmentationGDPR Art. 32
PCI DSS 1, 7
Administrative access moves off the public internet onto a private mesh with per-device identity.Tailscale
Availability and restorationGDPR Art. 32(1)(c)Supports timely restoration of availability and access to personal data through off-site backups and a documented, rehearsed restore procedure.Backups + integrity checks

Scroll the table sideways to see every column.

Framework mappings. Wazuh publishes mappings to PCI DSS, GDPR, HIPAA, NIST 800-53 and the Trust Services Criteria. Exact applicability still depends on your environment and assessed scope.

Show what is actually happening.

A policy says what should happen. Operational evidence shows whether it did. CraftSupport produces the records that support reviews and audits, as part of ordinary server management rather than as an annual scramble.

evidence produced
Patch status and maintenance history
monthly
Monitoring and incident records
continuous
Access configuration and review notes
on change
Backup completion and integrity checks
daily
Restore procedures and test outcomes
as agreed
System diagrams and operational documentation
maintained

An important limitation

Technical controls support compliance, but they do not guarantee certification or replace legal advice, formal assessment or accountable internal ownership. Requirements must be confirmed against the framework and scope that apply to your organisation.

Run the controls properly.

Access, patching, monitoring, logging, integrity and backups, operated as part of ordinary server management. If you also need to know where your patient data sits, Iris covers that half.

Thirty minutes. We tell you which controls already hold before anything is quoted.