Private administration
Named accounts, key-based access, least privilege, MFA options and reduced public exposure.
Compliance depends on working technical controls. CraftSupport implements, documents and maintains the infrastructure evidence that sits behind your policies.
We walk your current environment against the framework you are being assessed on, and tell you which controls already hold.
Delivered as part of ordinary server management, not as a separate compliance project.
Named accounts, key-based access, least privilege, MFA options and reduced public exposure.
Scheduled package updates, supported rebootless kernel patching and documented maintenance windows.
Availability, capacity and security signals routed to someone able to investigate them.
Detection and review of unexpected changes to important system and application paths.
Centralised records, useful retention periods and a clearer investigation history.
Off-site, versioned backups with integrity checks, restricted deletion and documented restoration.
The controls below are delivered as part of ordinary server management, not as a separate compliance project.
| Control | Obligation | What it does | Tooling |
|---|---|---|---|
| File integrity monitoring | PCI DSS 11.5 | Detects unauthorised modification of critical files and alerts on change. Required for merchants handling cardholder data. | Wazuh |
| Log collection and retention | PCI DSS 10 | Records and retains access to system components so an incident can be reconstructed afterwards. | Wazuh |
| Vulnerability detection | PCI DSS 6, 11 | Continuously identifies unpatched packages and known CVEs on the host. | Wazuh |
| Security patching | PCI DSS 6.3 | Critical patches are applied promptly. Rebootless kernel patching removes the usual reason for delay. | KernelCare |
| Access control and segmentation | GDPR Art. 32 PCI DSS 1, 7 | Administrative access moves off the public internet onto a private mesh with per-device identity. | Tailscale |
| Availability and restoration | GDPR Art. 32(1)(c) | Supports timely restoration of availability and access to personal data through off-site backups and a documented, rehearsed restore procedure. | Backups + integrity checks |
Scroll the table sideways to see every column.
Framework mappings. Wazuh publishes mappings to PCI DSS, GDPR, HIPAA, NIST 800-53 and the Trust Services Criteria. Exact applicability still depends on your environment and assessed scope.
A policy says what should happen. Operational evidence shows whether it did. CraftSupport produces the records that support reviews and audits, as part of ordinary server management rather than as an annual scramble.
Technical controls support compliance, but they do not guarantee certification or replace legal advice, formal assessment or accountable internal ownership. Requirements must be confirmed against the framework and scope that apply to your organisation.
Access, patching, monitoring, logging, integrity and backups, operated as part of ordinary server management. If you also need to know where your patient data sits, Iris covers that half.
Thirty minutes. We tell you which controls already hold before anything is quoted.