Where you stand¶
How to read the Where you stand screen, what each count means, and how to close what is open.
Choose Standing in the left-hand menu to open Where you stand. It reads your record against one framework at a time and shows, requirement by requirement, where you are. It is built from your approved record and updates as new work is approved. Reading it does not change your controls or decisions. The one thing it can add to your history is a note, if someone exports the audit pack without a recorded licence and gives a reason.
People with the Auditor role do not have Standing in their menu. They read the record and the Audit log instead.
Before anything is approved¶
The reading needs real work to stand on. Until at least one control has been approved, the screen says there is nothing to read yet and offers a prompt to copy into your AI. It asks your AI to record one control your company already runs. Once you approve that control, the reading appears. Controls are placed against requirements when you approve the links between them. You do not need to pick a framework first.
The counts¶
Across the top are counts, one for each state a requirement can be in. When the requirement details are shown, each count is also a filter: select it to show only those requirements, and Show all to clear it. For a copyrighted framework without your licence on record, you see the counts only.
- Covered. A control that satisfies the requirement is in place and backed by dated evidence at the reading date.
- Open. The requirement was decided as applying to you, or a control was placed against it, but it is not covered yet.
- Only in this framework. No decision or control is recorded against it, and no published reference in Kanonik links it to NIST CSF 2.0.
- Not assessed. Nobody has looked at it yet. It is not a gap, and it never counts as covered.
- Not applicable. You decided it does not apply, and the reason is on the record.
There is no percentage. Counts are what the record supports; a percentage would hide which requirements were never looked at.
A requirement can also be partly covered through a published reference from another framework. Partly covered is a reference between two frameworks, not proof that the requirement is met.
If your framework needs a reason for every exclusion and one is missing, the screen shows how many exclusions need a justification. An auditor may ask you to justify each one.
Choosing a framework¶
The screen reads one framework at a time; switch between the ones on your record. NIST CSF 2.0 is included on every plan. For a copyrighted framework such as ISO/IEC 27001:2022, the requirement numbers show once your own licence is on record. See Framework licences. Manage frameworks takes you there.
Closing what is open¶
Under the counts, To seal and export lists the next steps in order, for example "Cover the applicable requirements" or "Justify the exclusions", each with how many requirements, risks, findings or control references need attention. Each step comes with a prompt: copy it into your AI. Your AI proposes the controls, links or decisions, you approve them, and the reading updates from your record.
You can also open any requirement to see the controls placed against it, the applicability decision and its reason.
Exporting a snapshot¶
Export sealed evidence produces a sealed snapshot of where you stand, included in your plan at no charge. It lists every open item and never claims certification or readiness. When every requirement has a decision and the completeness checks pass (applicable requirements covered, exclusions justified, no broken control references, findings and risk treatment in order), the screen says your applicability record is complete. Exporting your evidence for an audit covers the full audit package.
Asking from your AI¶
Your AI can read the same reading for you: ask it "where do we stand on ISO 27001?". See Asking your record a question.
More help¶
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.