Skip to content

Compliance Reports

Open Reports > Compliance Reports to review evidence against selected security frameworks, inspect individual controls, and prepare evidence bundles.

Telovix reports the evidence available from the monitored environment. It does not certify compliance or replace the organizational, legal, and technical assessments required by a framework.

Choose a framework

Control Evidence offers:

FrameworkReview focus
CIS Controls v8Asset, configuration, logging, and monitoring evidence. This is not a CIS operating-system Benchmark scan.
NIS2Evidence relevant to cybersecurity risk-management and incident review.
NIST CSF 2.0Evidence organized around cybersecurity outcomes.
ETSI NFV-SECSecurity evidence for network-function virtualization environments.
O-RAN WG11O-RAN interface and runtime security evidence, available in telecom mode.

Telecom reporting also includes 3GPP and telecom-specific assessments where supported. A framework's presence does not mean every requirement can be assessed from sensor data.

Select a reporting period

Choose Last 7 days, Last 30 days, or Last 90 days. Thirty days is the default.

Confirm the selected scope and evaluation time. A reporting window cannot recover evidence outside your configured retention period.

Understand evidence status

StatusMeaning
Evidence check metThe available evidence meets this Telovix check. It does not establish full compliance with the standard.
Partial evidenceSome supporting evidence exists, but further review is needed.
Needs reviewThe check found a condition that requires investigation or remediation.
Not assessedThe available evidence does not support an assessment.

The Evidence score gives full credit to checks met and half credit to partial evidence. Unassessed controls are excluded. When all controls are unassessed, the report shows Not assessed, not a zero score.

A healthy sensor or an absence of detected attacks does not establish compliance. Open the underlying control to understand what was assessed.

Review controls

  1. Open Control Evidence.
  2. Choose the framework and period.
  3. Select a control.
  4. Read its evidence summary and available observations.
  5. Record any organizational or manual evidence required outside Telovix.
  6. Recheck after remediation.

The Summary tab provides an overview and available score history. Compare like-for-like scopes and periods when assessing changes.

Create an evidence bundle

Evidence bundles capture a point-in-time report. They do not update automatically when the fleet changes.

  1. Open Evidence Bundles.
  2. Select Generate Bundle.
  3. Choose Framework and Date range in the form.
  4. Select the form's Generate Bundle button and wait for completion.
  5. Use Download on the completed bundle.

Generation and download require Operator or Admin access with unrestricted fleet scope. Bundle review requires Analyst or higher with unrestricted fleet scope.

NIS2-labelled bundles organize evidence for incident review. Their 24-hour, 72-hour, and 30-day windows are evidence lookbacks, not a calculation of your notification deadlines. Telovix does not determine legal entity classification or whether an event is a legally significant incident.

A bundle's signature helps check whether its contents changed. Establish the signer's trusted identity separately before relying on it as external evidence.

Reporting schedules

Use the reporting schedule controls when regular reports are needed. Review the selected framework, period, and delivery configuration before enabling a schedule. Schedule management requires unrestricted fleet scope.

Verify a completed report and delivery result rather than relying only on the schedule's enabled setting.

Troubleshooting

SymptomWhat to check
A framework has no scoreOpen its unassessed controls and review missing coverage or evidence.
A control needs reviewInspect its supporting observations and required follow-up.
A telecom framework is missingCheck that telecom mode and the relevant sensor coverage are enabled.
A period contains little evidenceCheck retention, selected scope, and sensor observation times.
A bundle action is unavailableCheck your role and fleet scope.
A report differs from the current fleetCompare its evaluation time with current reports; generated bundles are snapshots.

Released under the Telovix Commercial License.