- Framework library
- ISO 27001:2022, SOC 2, India’s DPDP Act and SEBI CSCRF first, modeled to the same depth. NIST and CIS Controls are planned, added by mapping to the same control library rather than by starting over.
- Control model
- One control library. Each control maps to every requirement it satisfies across every framework, so a control implemented once produces evidence for all of them. Each control has an owner, an operating status and a test history.
- Policy model
- Policies are versioned, owned and mapped to the controls they govern, so a policy change shows which controls, evidence and frameworks it touches.
- Evidence model
- Evidence is scheduled with owners, due dates and escalation, collected from common platforms where feasible and otherwise filed by the owner, and kept as a versioned trail. Stale evidence is detected before an auditor finds it.
- Risk model
- A register anchored to the business, with owners, review cycles and treatment plans. Risks link to the controls that treat them and the assets they threaten, so the risk picture updates when a control fails or an assessment finds a gap.
- Control testing
- Tests are recorded against the control: what was checked, by whom, when, and with what result. Results are evidence.
- Readiness
- Computed live from control state, per framework, to control level. Readiness is a figure to watch between audits, not a feeling before one.
- Audit and remediation
- Findings are tracked to verified closure. Auditor-ready packages, with evidence references, are exported from the live system.
- Third-party risk
- Vendor assessments are held in the same system as internal risk, against the same control library.
- Boundaries
- JANUS keeps the mapping, the evidence and the readiness current. It does not certify anyone, and it does not do the work a control requires. That remains with the organization, and, where wanted, with Onion’s GRC services.