ATALAIA
  1. Home
  2. Services
  3. Policies, Compliance & Risk
17Station 17 · Program

Policies, Compliance & Risk

Short policies people follow, risk assessments that change decisions, and audit evidence pulled from the line itself.

From the framework to the line

Each control maps to evidence your line already produces. Nobody takes a screenshot.

The framework asksThe controlThe evidence, from the line
SOC 2 · CC8.1 change managementEvery change reviewed and approvedMerged PRs with approvals, exported monthly
SOC 2 · CC6.1 logical accessProduction access by role, reviewedIAM review record for each release
DORA · Art. 28 third-party riskDependencies and vendors trackedAn SBOM per build, plus the vendor list
DORA · Art. 24 resilience testingTesting after every major changePentest tickets and retest results
ISO 27001 · A.8.28 secure codingCode scanned, risky paths reviewedScan results and review comments on PRs

Evidence from the line

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Pick the frameworks

SOC 2, ISO 27001, DORA, NIS2, CRA: what you actually need.

CISOPartners ask for SOC 2. The bank partner asks for DORA.

ATALAIAThen those two. ISO can wait; most controls overlap.

Leaves the roomFrameworks: SOC 2 and DORA

Step 2Write short policies

One page each, owned by a person.

ATALAIANine policies, one page each, each with a person's name on it.

DEV LEADOne page I'll actually read.

Leaves the room9 policies, one page, one owner

Step 3Wire the evidence

Controls proven by the line, not by screenshots.

ATALAIAChange-management evidence comes from merged PRs and approvals.

PLATFORMSo no screenshots this year?

ATALAIANone. The pipeline exports it every month.

Leaves the roomEvidence from pipelines and tickets

Step 4Assess the risk

A method, a cadence and decisions recorded.

ATALAIAPartner webhook without signatures: likelihood medium, impact high.

CTOFixed next quarter. We accept it until then.

CISORecorded, with an expiry date.

Leaves the roomRisk register, decisions recorded

  • ATALAIA
  • CISO
  • DEV LEAD
  • PLATFORM
  • CTO

Before and after

Before

Policies written for auditors are not read by engineers. Evidence gathered by hand once a year is late and expensive.

  • Policies are long, and nobody can name one
  • Audit season means screenshots
  • Risk registers never change a decision
After
  • A short policy set, mapped to the frameworks you need
  • A risk assessment method your leadership uses
  • Evidence collected from pipelines, registries and tickets
  • An audit-ready control map

Typical shape: Four to eight weeks, then quarterly reviews.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.