Compliance Report — FAQ

Compliance Report — FAQ

What is the SiteWALL Compliance Report?
It's a monthly report generated automatically from your Compliance Center that documents the technical security controls SiteWALL WAF has in place, maps those controls to specific clauses in regulatory and industry frameworks, and summarizes attack activity, vulnerability status, and configuration changes for the period.

How often is it generated?
Monthly. A new report is generated on the 1st of each month and covers the full previous calendar month (for example, a report generated on 1st August covers 1–31 July).

Where do I find my reports?
In the SiteWALL Menu, under Reports  → Compliance Center → Compliance Reports. Reports are listed by month with their generation date, and each can be viewed inline or downloaded as a PDF.

Who prepares the report?
It's compiled automatically by the SiteWALL platform from live configuration and log data, on behalf of PageNTRA Infosec Pvt Ltd. No manual write-up is needed on your end.

Is the report meant to be shared externally, e.g. with an auditor?
Yes — that's its main purpose. It's built as audit-ready evidence you can hand to an internal auditor, external assessor, or regulator. The report is marked "For Internal Use Only" as a default confidentiality label; check with your compliance team before onward distribution if your organisation has stricter data-handling requirements.

What sections does the report contain?

  1. Executive Summary
  2. Organisation Environment Snapshot (applications protected, deployment model, policy level)
  3. Compliance Mapping Matrix (four control domains — see below)
  4. Security Highlights for the period (attacks blocked, vulnerability assessment, critical incidents, WAF uptime)
  5. Configuration & Enforcement Controls (control status + full configuration change audit trail)
  6. Log Management & Audit Readiness
  7. Recommendations & Next Steps
  8. Conclusion
  9. Annexure (links to the underlying regulations)

What are the four control domains in the Compliance Mapping Matrix?

  • Access & Authorization Controls — RBAC, MFA, least-privilege enforcement
  • Logging & Monitoring Controls — continuous monitoring, security event logging, log retention, log accessibility for investigations
  • Network & Application Protection Controls — OWASP Top 10 protection, mandatory WAF, DDoS/bot mitigation, secure public portals, malware protection, vulnerability/zero-day mitigation, secure SDLC support, network security
  • Cryptography & Configuration Controls — TLS/cipher enforcement, secure configuration and change management.
Each mapping row has a "What the Regulator Expects" and "Outcome for Audit" column — what are those for? They translate a regulation's requirement into plain language, then state what that specific SiteWALL control gives you to show an auditor. You can hand an auditor the matrix row directly instead of explaining the mapping yourself.

What does the "Security Highlights" section cover?

  • Total malicious requests blocked in the period, with a day-by-day chart
  • Top 10 applications under attack
  • Attack categorization (Threat Intel, Web Crawler/Bot, Blacklist, Scan, Brute Force, etc.) and OWASP Top 10 breakdown
  • Top attack origin countries and web traffic ratio (desktop/bot/mobile/script/scanner)
  • Top 10 targeted URIs and top 10 bots seen
  • A per-application vulnerability table (Low/Medium/High + letter grade)
  • A short list of critical incidents for the period, with IR numbers
  • WAF service availability (% uptime) for the month

What's in the Configuration & Enforcement Controls section?
A control-status table (OWASP Core Ruleset, Rate Limiting/Bot Protection, IP Reputation, Custom Rules, SSL/TLS enforcement — all should read Enabled), a per-application configuration audit table (WAF, VA, Defacement, Webshell/Malware status), and a full, timestamped log of every configuration change made during the month, by application and by user.

Why does the same application sometimes show a different vulnerability score month to month?
The Vulnerability Assessment section reflects the most recent scan results at report-generation time. If a new vulnerability was found or an existing one remediated since the last report, the score and grade will move accordingly. See the separate Vulnerability Management datasheet for how scanning and grading works.

Does this report mean we're certified compliant?
No. The report states this explicitly: it provides evidence of technical controls, but "final compliance determinations remain subject to the organisation's governance framework, scope definition, and independent audit or regulatory validation." Certification, where applicable, is a separate process your organisation runs with its auditor or regulator — SiteWALL's report is one input to that process, not a substitute for it.

What do the four summary cards at the top of Compliance Center mean?

  • Protected Apps — number of applications currently onboarded to SiteWALL WAF
  • Vulnerable Apps — applications with at least one open vulnerability in the last 30 days
  • Attacks Blocked — total malicious requests blocked in the last 30 days
  • Policy Level — the WAF security policy currently applied (e.g. Advanced Security / Performance-Optimized)

What does the "Configuration Status" row show?
A live count of applications where a given protection is currently disabled — WAF, Vulnerability Assessment (VA), Defacement monitoring, and Webshell/Malware scanning. These are flagged so you can see at a glance where coverage has gaps; a non-zero number is worth reviewing even outside the monthly report cycle.

In the Compliance Reports table, what does "All Feature Enabled: No" mean?

It means that, at the time the report was generated, at least one application had at least one of WAF / VA / Defacement / Webshell protection turned off. It's a rollup of the Configuration Status counts for that month. "Yes" would mean every protection was enabled on every application for the full period.

What does "Vulnerable Apps: Yes" in that same table mean?

At least one application had an open vulnerability finding during that reporting period. Open the report (or the Vulnerability Management module) to see which application and what was found.

Can I download a report for a month that isn't the most recent?

Yes. The Compliance Reports table keeps every past monthly report; use the view (eye) or download icon on any row to open or save that month's PDF.

Who do I contact if a report looks wrong or incomplete?
Email SiteWALL Support at support@pagentra.com with the report month and application name, and the team will investigate.