1. Knowledge Base Home
  2. Controls
  3. Continuous Control Monitoring (CCM)

Automatically monitor controls using Wiz CSPM

Supported 6clicks Authorities are:

  • ISO 27001:2013 AnnexA
  • ISO 27001:2022 AnnexA
  • NIST CSF 2.0
  • NIST CSF
  • Essential-8

Getting started

Once the connection is established following the steps here, you can proceed to Controls and automate them.

  1. Navigate to the control set and ensure the status is set to Edit
  2. Select the control you want to configure for automation
  3. Choose Linked data
  4. Click on the test that you intend to automate

You will be directed to your test side panel to configure automation for that specific test.

  1. Enable Automatically monitor using CSMP integration 
  2. Under Data source select Wiz
  3. Enter your External URL/ID which si obtained from your Wiz environment
  4. Hit Save

After completing the automation setup for your tests, return to the control status and switch it to Published to apply the automation settings. To view which tests within a specific control set have been integrated with Wiz and automated, navigate to:

  1. Click on your control 
  2. Go to Linked data
  3. The symbols indicate whether your test is automated with wiz and any results will be fetched in automatically every 24hrs  or whether it has been set up manually. 
    wiz

Error Scenarios

There are two scenarios when the system will give you an error. 

  1. If you are using a provision from an authority that is not supported, for instance, you want to create a test for "Address Unauthorized Assets" which is from ISO/IEC 2700:2013 authority. 

You will receive the following error "We're unable to monitor this control". 

2.  You will get an error if you try to automate a test which has no authority provision linked to that control, please see the example below. 

You will receive the following error "Link control to authority provisions".