dt-obs-compliance-assistant

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Compliance Assistant

合规助手

Track, manage, and investigate EU DORA compliance posture using real-time observability and security insights from the Dynatrace Compliance Assistant app.

借助Dynatrace Compliance Assistant应用的实时可观测性和安全洞察,跟踪、管理并调查欧盟DORA合规状态。

Critical Disclaimer

重要免责声明

The Dynatrace compliance score and all outputs from Compliance Assistant are indicative metrics based on real-time observability data and automated systems. They do not replace comprehensive or formal compliance assessments and do not constitute a legal determination of a company's compliance status under EU DORA or any other regulation.
Never claim that a score, tier, or Compliance Assistant output means an organization is legally compliant or non-compliant with EU DORA. Always present results as operational indicators to support remediation decisions, not as legal or regulatory verdicts.

Dynatrace合规评分以及Compliance Assistant的所有输出均为基于实时可观测性数据和自动化系统的指示性指标。它们不能替代全面或正式的合规评估,也构成对公司在欧盟DORA或任何其他法规下合规状态的法律判定。
**切勿声称评分、等级或Compliance Assistant的输出意味着组织在法律上符合或不符合欧盟DORA要求。**始终将结果作为支持整改决策的运营指标呈现,而非法律或监管裁决。

When to Use This Skill

何时使用此技能

Use for:
  • EU DORA compliance posture, compliance score, compliance snapshot, score tier
  • Critical or Important Functions (CIFs): health, KPI monitoring, impact analysis, setup questions
  • Incident lifecycle under DORA: unclassified problems, potential major incidents, classified major incidents
  • ICT risk inputs: vulnerabilities, security detection findings, misconfigurations (ICT asset configuration results)
  • Incident classification under EU DORA: materiality thresholds, duration criteria, economic impact
  • DQL queries for
    compliance.incident
    bizevents, CIF health, or unclassified problems on CIFs
  • Onboarding, permissions, and settings for Compliance Assistant
Do not use for:
  • Regulatory frameworks other than EU DORA — SOC2, PCI-DSS, HIPAA, ISO 27001 are not supported by this app
  • Generic Davis problems with no DORA, CIF, or compliance context → use
    dt-obs-problems
  • Generic vulnerability or security finding queries not scoped to compliance or DORA → use application security skills
  • Generic "score" queries without "compliance" or "DORA" — Dynatrace has many scores
  • Configuring Business Flow or defining business process steps → see Business Flow documentation
  • Configuring Security Posture Management rules → see SPM documentation
  • General DQL syntax help → use
    dt-dql-essentials

适用场景:
  • 欧盟DORA合规状态、合规评分、合规快照、评分等级
  • 关键或重要功能(CIF):健康状况、KPI监控、影响分析、设置相关问题
  • DORA下的事件生命周期:未分类问题、潜在重大事件、已分类重大事件
  • ICT风险输入:漏洞、安全检测结果、配置错误(ICT资产配置结果)
  • 欧盟DORA下的事件分类:重要性阈值、时长标准、经济影响
  • 针对
    compliance.incident
    业务事件、CIF健康状况或CIF上未分类问题的DQL查询
  • Compliance Assistant的入门配置、权限及设置
不适用场景:
  • 欧盟DORA以外的监管框架——此应用不支持SOC2、PCI-DSS、HIPAA、ISO 27001
  • 无DORA、CIF或合规上下文的通用Davis问题→使用
    dt-obs-problems
  • 未限定为合规或DORA范围的通用漏洞或安全结果查询→使用应用安全技能
  • 无“compliance”或“DORA”关键字的通用“score”查询——Dynatrace有多种评分
  • 配置Business Flow或定义业务流程步骤→查看Business Flow文档
  • 配置Security Posture Management规则→查看SPM文档
  • 通用DQL语法帮助→使用
    dt-dql-essentials

Prerequisites

前提条件

Installation

安装

Install Compliance Assistant from Dynatrace Hub.
Dynatrace Hub安装Compliance Assistant。

Required Permissions

所需权限

PermissionPurpose
storage:buckets:read
Read buckets
storage:events:read
Read events
storage:entities:read
Read entities table
storage:metrics:read
Required for Istio discovery findings rule
storage:filter-segments:read
Read filter segments
settings:objects:read
Read Log ingest settings
settings:schemas:read
Read settings schemas
state:app-states:read
Read app state
hub:catalog:read
Read app version
storage:security.events:read
Fetch security events
权限用途
storage:buckets:read
读取存储桶
storage:events:read
读取事件
storage:entities:read
读取实体表
storage:metrics:read
Istio发现结果规则所需
storage:filter-segments:read
读取过滤片段
settings:objects:read
读取日志摄入设置
settings:schemas:read
读取设置模式
state:app-states:read
读取应用状态
hub:catalog:read
读取应用版本
storage:security.events:read
获取安全事件

Required Data Sources

所需数据源

SourcePurpose
Business FlowCIF monitoring and incident detection on business processes — required for incident classification
Vulnerability eventsContinuous vulnerability assessment (DORA requirement)
Detection finding eventsContinuous cyber threat assessment (DORA requirement)
Compliance eventsICT asset secure configuration baseline verification (DORA requirement) — powered by Security Posture Management

来源用途
Business FlowCIF监控和业务流程事件检测——事件分类所需
漏洞事件持续漏洞评估(DORA要求)
检测结果事件持续网络威胁评估(DORA要求)
合规事件ICT资产安全配置基线验证(DORA要求)——由Security Posture Management提供支持

Core Concepts

核心概念

Compliance Framework

合规框架

Compliance Assistant currently supports EU DORA (Digital Operational Resilience Act) only. It consolidates observability and security insights into a single compliance posture view for this framework. Support for additional frameworks is planned.
Compliance Assistant目前仅支持欧盟DORA(Digital Operational Resilience Act)。它将可观测性和安全洞察整合为该框架的单一合规状态视图。计划支持更多框架。

Dynatrace Score (Compliance Snapshot)

Dynatrace评分(合规快照)

A real-time, tiered score summarizing current ICT risk posture across potential incidents, security detection findings, vulnerabilities, and misconfigurations. The score tier is determined by the most severe active condition; within a tier, the score is reduced by a penalty for each criterion met.
Score tiers:
TierMax scoreTriggered when…
On Track100No criteria met across incidents, security detection findings, vulnerabilities, misconfigurations
Low99Any low-severity finding in security detection findings/vulnerabilities/misconfigurations
Medium79Any medium-severity finding, or ≥1 unclassified incident
High59Any high-severity finding, or ≥5 unclassified incidents
Critical34Any critical security detection finding/vulnerability/misconfiguration, or ≥1 potential major incident
Major5 (fixed)≥1 confirmed classified major incident — short-circuits to a fixed score of 5
Penalty mechanic: Within a tier, score = tier max − (6 × number of criteria met in that tier). For example, Medium tier with 2 criteria met: 79 − 12 = 67.
This score is a high-level operational indicator. It does not confirm regulatory compliance or legal status.
实时、分层的评分,汇总当前ICT风险状态,涵盖潜在事件、安全检测结果、漏洞和配置错误。评分等级由最严重的活跃状况决定;在同一等级内,每满足一项标准,评分就会扣除相应罚分。
评分等级:
等级最高分触发条件…
正常100事件、安全检测结果、漏洞、配置错误均未满足任何标准
低风险99安全检测结果/漏洞/配置错误中存在任何低严重度结果
中风险79存在任何中严重度结果,或≥1个未分类事件
高风险59存在任何高严重度结果,或≥5个未分类事件
关键风险34存在任何关键严重度的安全检测结果/漏洞/配置错误,或≥1个潜在重大事件
重大风险5(固定值)≥1个已确认的已分类重大事件——直接固定为5分
罚分机制: 在同一等级内,评分=等级最高分 − (6 × 该等级内满足的标准数量)。例如,中风险等级满足2项标准:79 − 12 = 67。
此评分是高级别的运营指标,代表监管合规或法律状态。

Critical or Important Functions (CIFs)

关键或重要功能(CIF)

Under EU DORA, financial entities must identify and monitor business functions that, if disrupted, could significantly impact financial performance or service continuity. In Compliance Assistant, CIFs are configured by linking Business Flow business processes to the DORA framework. Smartscape on Grail provides end-to-end visibility by linking each CIF to its underlying IT components.
根据欧盟DORA要求,金融机构必须识别并监控那些一旦中断可能严重影响财务业绩或服务连续性的业务功能。在Compliance Assistant中,通过将Business Flow业务流程关联到DORA框架来配置CIF。Smartscape on Grail通过将每个CIF与其底层IT组件关联,提供端到端可见性。

Incident Lifecycle

事件生命周期

Davis-detected problems affecting CIF business processes move through three states:
StateDefinition
Unclassified problemA Davis problem affects a CIF but fewer than 2 DORA materiality thresholds are breached
Potential major incident≥2 monitored DORA materiality thresholds are breached
Classified major incidentManually confirmed as major in Compliance Assistant; generates a
compliance.incident
bizevent snapshot
EU DORA materiality thresholds monitored:
ThresholdCriterion
CIFs affectedBlast radius across critical or important functions
Incident duration24-hour threshold
Economic impact€100,000 threshold, calculated from estimated cost per minute of affected CIFs × incident duration
Classification is always a manual step performed in the Compliance Assistant app. Do not classify incidents on behalf of the user.
Once classified, the generated
compliance.incident
bizevent can trigger automations via Dynatrace Workflows (e.g., creating a ServiceNow incident or Jira ticket enriched with compliance impact details).
Davis检测到的影响CIF业务流程的问题会经历三个状态:
状态定义
未分类问题Davis问题影响CIF,但未违反2项以上DORA重要性阈值
潜在重大事件≥2个受监控的DORA重要性阈值被违反
已分类重大事件在Compliance Assistant中手动确认为重大事件;生成
compliance.incident
业务事件快照
受监控的欧盟DORA重要性阈值:
阈值标准
受影响的CIF关键或重要功能的影响范围
事件时长24小时阈值
经济影响10万欧元阈值,由受影响CIF的每分钟预估成本 × 事件时长计算得出
分类始终是在Compliance Assistant应用中执行的手动步骤。请勿代表用户对事件进行分类。
分类完成后,生成的
compliance.incident
业务事件可通过Dynatrace Workflows触发自动化操作(例如,创建包含合规影响详情的ServiceNow事件或Jira工单)。

ICT Risk Inputs

ICT风险输入

Signal typeSourceDORA requirement
VulnerabilitiesVulnerability findingsContinuous vulnerability assessment
Security detection findingsDetection finding eventsContinuous cyber threat assessment
ICT asset configuration resultsCompliance events via Security Posture ManagementSecure configuration baseline verification

信号类型来源DORA要求
漏洞漏洞检测结果持续漏洞评估
安全检测结果检测结果事件持续网络威胁评估
ICT资产配置结果通过Security Posture Management获取的合规事件安全配置基线验证

DQL Reference

DQL参考

Classified Major Incidents

已分类重大事件

Fetch
compliance.incident
bizevents generated when an incident is classified as major. To retrieve a specific incident, filter by
problem.event.id
.
dql
fetch bizevents
| filter event.provider == "dynatrace.compliance.assistant"
| filter event.type == "compliance.incident"
| filter problem.event.id == {{.incident_id:string}}
To fetch all classified incidents:
dql
fetch bizevents
| filter event.provider == "dynatrace.compliance.assistant"
| filter event.type == "compliance.incident"
Key fields (see Semantic Dictionary for the full schema):
FieldTypeDescription
compliance.cifs_impacted.names
stringDistinct list of names of the Business Flow entities configured as CIFs affected by the incident (e.g.,
Account opening; Deposit and trade flow
)
compliance.cifs_impacted.ids
stringDistinct list of unique identifiers of the Business Flow entities configured as CIFs affected by the incident
compliance.framework
stringDisplay name of the compliance framework (e.g.,
DORA
)
compliance.incident.classified
boolean
true
when the incident has been manually classified as major in line with DORA requirements
compliance.incident.comment
stringComment added by the user when classifying the incident as major (e.g.,
"The incident was classified as major due to insights on reputational damage and user impact."
)
compliance.incident.duration
durationDuration of the incident in nanoseconds, used to evaluate the 24h DORA duration materiality threshold
compliance.incident.duration_criteria
boolean
true
if the DORA 24h incident duration materiality threshold was breached
compliance.incident.economic_impact
doubleEstimated economic impact in EUR, calculated from the estimated cost per minute of affected CIFs × incident duration
compliance.incident.economic_impact_criteria
boolean
true
if the DORA €100,000 economic impact materiality threshold was breached
compliance.incident.name
stringDisplay name of the incident — matches the
event.name
of the underlying
dt.davis.problem
(e.g.,
CPU saturation
)
compliance.incident.time.classified
timestampUnix epoch timestamp (nanoseconds) when the incident was classified as major
event.provider
stringAlways
dynatrace.compliance.assistant
for Compliance Assistant incident bizevents
event.type
stringAlways
compliance.incident
for Compliance Assistant incident bizevents
problem.category
stringProblem category from the underlying Davis problem:
AVAILABILITY
,
ERROR
,
SLOWDOWN
,
RESOURCE_CONTENTION
,
CUSTOM_ALERT
,
MONITORING_UNAVAILABLE
problem.event.id
stringUnique identifier of the underlying
dt.davis.problem
— use this to correlate with problem queries
problem.status
stringStatus of the underlying Davis problem:
ACTIVE
or
CLOSED
获取事件被分类为重大事件时生成的
compliance.incident
业务事件。要检索特定事件,请按
problem.event.id
过滤。
dql
fetch bizevents
| filter event.provider == "dynatrace.compliance.assistant"
| filter event.type == "compliance.incident"
| filter problem.event.id == {{.incident_id:string}}
获取所有已分类事件:
dql
fetch bizevents
| filter event.provider == "dynatrace.compliance.assistant"
| filter event.type == "compliance.incident"
关键字段(完整架构请查看语义词典):
字段类型描述
compliance.cifs_impacted.names
string受事件影响的、配置为CIF的Business Flow实体的不同名称列表(例如:
Account opening; Deposit and trade flow
compliance.cifs_impacted.ids
string受事件影响的、配置为CIF的Business Flow实体的唯一标识符列表
compliance.framework
string合规框架的显示名称(例如:
DORA
compliance.incident.classified
boolean当事件已根据DORA要求手动分类为重大事件时为
true
compliance.incident.comment
string用户将事件分类为重大事件时添加的注释(例如:
"The incident was classified as major due to insights on reputational damage and user impact."
compliance.incident.duration
duration事件时长(纳秒),用于评估DORA 24小时时长重要性阈值
compliance.incident.duration_criteria
boolean如果违反DORA 24小时事件时长重要性阈值则为
true
compliance.incident.economic_impact
double预估经济影响(欧元),由受影响CIF的每分钟预估成本 × 事件时长计算得出
compliance.incident.economic_impact_criteria
boolean如果违反DORA 10万欧元经济影响重要性阈值则为
true
compliance.incident.name
string事件的显示名称——与底层
dt.davis.problem
event.name
匹配(例如:
CPU saturation
compliance.incident.time.classified
timestamp事件被分类为重大事件时的Unix纪元时间戳(纳秒)
event.provider
stringCompliance Assistant事件业务流的提供者始终为
dynatrace.compliance.assistant
event.type
stringCompliance Assistant事件业务流的类型始终为
compliance.incident
problem.category
string底层Davis问题的类别:
AVAILABILITY
ERROR
SLOWDOWN
RESOURCE_CONTENTION
CUSTOM_ALERT
MONITORING_UNAVAILABLE
problem.event.id
string底层
dt.davis.problem
的唯一标识符——用于与问题查询关联
problem.status
string底层Davis问题的状态:
ACTIVE
CLOSED

Unclassified Problems and Potential Major Incidents on CIFs

CIF上的未分类问题和潜在重大事件

Finds Davis problems affecting CIFs that have no matching
compliance.incident
bizevent — i.e., problems not yet manually classified. The
isNull(lookup.event.id)
anti-join is the key pattern.
dql
fetch dt.davis.problems, from: {{.from}}, to: {{.to}}
| expand affected_entity_ids
| join [
    smartscapeNodes "*"
  ], on: {left[affected_entity_ids] == right[id_classic]}, prefix: "entities."
| join [
    smartscapeEdges "*"
  ], on: {left[entities.id] == right[target_id]}, prefix: "edges."
| join [
    smartscapeNodes "BIZ_FLOW"
  ], on: {left[edges.source_id] == right[id]}, prefix: "nodes."
| lookup [
    fetch bizevents
    | filter event.provider == "dynatrace.compliance.assistant"
      and event.type == "compliance.incident"
  ], sourceField: `event.id`, lookupField: `problem.event.id`, executionOrder: auto
| filter isNull(lookup.event.id)
| fields display_id,
         name = event.name,
         status = event.status,
         cif = nodes.name,
         affectedEntity = entities.name,
         event.start,
         event.end,
         nodes.bizflow.id,
         category = event.category
| filter in(nodes.bizflow.id, {"{{.cif_id_1}}", "{{.cif_id_2}}"})
| summarize {
    status      = takeFirst(status),
    cifIds      = collectDistinct(nodes.bizflow.id),
    cifs        = collectDistinct(cif),
    start       = min(event.start),
    end         = max(event.end),
    duration    = max(coalesce(event.end, now()) - event.start),
    category    = takeFirst(category)
  }, by: { display_id, name }
| limit {{.max_entries:long}}
Notes:
  • Source is
    dt.davis.problems
    , not
    bizevents
  • filter isNull(lookup.event.id)
    identifies problems with no classified incident bizevent
  • in(nodes.bizflow.id, {...})
    restricts to problems whose Smartscape graph touches a configured CIF (
    BIZ_FLOW
    node)
  • Replace
    {{.cif_id_1}}
    ,
    {{.cif_id_2}}
    with actual Business Flow entity IDs from the DORA framework settings in Compliance Assistant
  • For a single CIF, use
    | filter nodes.bizflow.id == "{{.cif_id}}"
查找影响CIF且无匹配
compliance.incident
业务事件的Davis问题——即尚未手动分类的问题。
isNull(lookup.event.id)
反连接是关键模式。
dql
fetch dt.davis.problems, from: {{.from}}, to: {{.to}}
| expand affected_entity_ids
| join [
    smartscapeNodes "*"
  ], on: {left[affected_entity_ids] == right[id_classic]}, prefix: "entities."
| join [
    smartscapeEdges "*"
  ], on: {left[entities.id] == right[target_id]}, prefix: "edges."
| join [
    smartscapeNodes "BIZ_FLOW"
  ], on: {left[edges.source_id] == right[id]}, prefix: "nodes."
| lookup [
    fetch bizevents
    | filter event.provider == "dynatrace.compliance.assistant"
      and event.type == "compliance.incident"
  ], sourceField: `event.id`, lookupField: `problem.event.id`, executionOrder: auto
| filter isNull(lookup.event.id)
| fields display_id,
         name = event.name,
         status = event.status,
         cif = nodes.name,
         affectedEntity = entities.name,
         event.start,
         event.end,
         nodes.bizflow.id,
         category = event.category
| filter in(nodes.bizflow.id, {"{{.cif_id_1}}", "{{.cif_id_2}}"})
| summarize {
    status      = takeFirst(status),
    cifIds      = collectDistinct(nodes.bizflow.id),
    cifs        = collectDistinct(cif),
    start       = min(event.start),
    end         = max(event.end),
    duration    = max(coalesce(event.end, now()) - event.start),
    category    = takeFirst(category)
  }, by: { display_id, name }
| limit {{.max_entries:long}}
注意:
  • 数据源为
    dt.davis.problems
    ,而非
    bizevents
  • filter isNull(lookup.event.id)
    用于识别无已分类事件业务流的问题
  • in(nodes.bizflow.id, {...})
    将范围限制为Smartscape图触及已配置CIF(
    BIZ_FLOW
    节点)的问题
  • {{.cif_id_1}}
    {{.cif_id_2}}
    替换为Compliance Assistant中DORA框架设置里的实际Business Flow实体ID
  • 针对单个CIF,使用
    | filter nodes.bizflow.id == "{{.cif_id}}"

CIF Health (Business Flow KPIs)

CIF健康状况(Business Flow KPI)

Fetches the latest KPI snapshot per CIF. KPI data is emitted by Business Flow (
event.type == "bizflow.kpis"
), not by Compliance Assistant directly.
dql
fetch bizevents, from: now()-24h, to: now()
| filter event.type == "bizflow.kpis"
| filter bizflow.id == "{{.cif_id_1}}" or bizflow.id == "{{.cif_id_2}}"
| fieldsAdd timestamp, bizflowId = bizflow.id, bizflowName = bizflow.name
| sort timestamp asc
| summarize {
    fulfillment   = takeLast(bizflow.analysis.value),
    errors        = takeLast(bizflow.errors.value),
    timestamp     = takeLast(timestamp),
    timeframe     = takeLast(bizflow.query_timeframe.hours),
    frequency     = takeLast(bizflow.query_frequency.hours),
    bizflowName   = takeLast(bizflowName),
    analysisLabel = takeLast(bizflow.analysis.label)
  }, by: { bizflowId }
Notes:
  • Returns one row per CIF;
    fulfillment
    and
    errors
    are the latest sampled KPI values
  • analysisLabel
    describes what
    fulfillment
    means for that flow (e.g., "Successful logins")
  • timeframe
    and
    frequency
    reflect the Business Flow's own configured query window
  • For a single CIF use
    | filter bizflow.id == "<id>"
    ; for multiple CIFs extend with additional
    or bizflow.id == "<id>"
    clauses
  • If data is missing, check the Business Flow monitoring frequency and evaluation timeframe (see FAQ)

获取每个CIF的最新KPI快照。KPI数据由Business Flow(
event.type == "bizflow.kpis"
)生成,而非直接由Compliance Assistant生成。
dql
fetch bizevents, from: now()-24h, to: now()
| filter event.type == "bizflow.kpis"
| filter bizflow.id == "{{.cif_id_1}}" or bizflow.id == "{{.cif_id_2}}"
| fieldsAdd timestamp, bizflowId = bizflow.id, bizflowName = bizflow.name
| sort timestamp asc
| summarize {
    fulfillment   = takeLast(bizflow.analysis.value),
    errors        = takeLast(bizflow.errors.value),
    timestamp     = takeLast(timestamp),
    timeframe     = takeLast(bizflow.query_timeframe.hours),
    frequency     = takeLast(bizflow.query_frequency.hours),
    bizflowName   = takeLast(bizflowName),
    analysisLabel = takeLast(bizflow.analysis.label)
  }, by: { bizflowId }
注意:
  • 每个CIF返回一行;
    fulfillment
    errors
    是最新采样的KPI值
  • analysisLabel
    描述该流程的
    fulfillment
    含义(例如:"Successful logins")
  • timeframe
    frequency
    反映Business Flow自身配置的查询窗口
  • 针对单个CIF使用
    | filter bizflow.id == "<id>"
    ;针对多个CIF,添加额外的
    or bizflow.id == "<id>"
    子句
  • 如果数据缺失,请检查Business Flow的监控频率和评估时间范围(查看FAQ

Common Workflows

常见工作流

Check the Compliance Score

查看合规评分

  1. Confirm the user is asking about DORA — currently the only supported framework
  2. Explain the current tier using the score tier table in Core Concepts
  3. Remind the user the score is an operational indicator, not a legal compliance determination
  4. If the score is degraded, identify which signal types are contributing (incidents, security detection findings, vulnerabilities, misconfigurations)
  5. Guide remediation using Improving the Compliance Score
  1. 确认用户询问的是DORA——目前唯一支持的框架
  2. 使用核心概念中的评分等级表说明当前等级
  3. 提醒用户该评分是运营指标,而非法律合规判定
  4. 如果评分下降,确定哪些信号类型(事件、安全检测结果、漏洞、配置错误)是影响因素
  5. 使用提升合规评分指导整改

Investigate an Incident

调查事件

  1. Confirm whether the user is asking about a classified incident (has a
    compliance.incident
    bizevent) or an unclassified/potential major problem
  2. For classified incidents: run the classified incidents DQL query, filter by
    problem.event.id
    if a specific incident is referenced
  3. For unclassified/potential major: run the unclassified problems query scoped to the relevant CIF IDs
  4. Surface the materiality threshold breach status:
    compliance.incident.duration_criteria
    ,
    compliance.incident.economic_impact_criteria
    ,
    compliance.cifs_impacted.*
  5. Do not classify an incident on behalf of the user — classification is a manual step performed in the Compliance Assistant app
  1. 确认用户询问的是已分类事件(存在
    compliance.incident
    业务事件)还是未分类/潜在重大问题
  2. 对于已分类事件:运行已分类事件DQL查询,如果涉及特定事件,按
    problem.event.id
    过滤
  3. 对于未分类/潜在重大事件:运行针对相关CIF ID的未分类问题查询
  4. 展示重要性阈值违反状态:
    compliance.incident.duration_criteria
    compliance.incident.economic_impact_criteria
    compliance.cifs_impacted.*
  5. 请勿代表用户对事件进行分类——分类是在Compliance Assistant应用中执行的手动步骤

Review CIF Health

查看CIF健康状况

  1. Identify the CIF's Business Flow ID from the DORA framework settings in Compliance Assistant
  2. Run the CIF health query with the relevant
    bizflow.id
    values
  3. Surface
    fulfillment
    ,
    errors
    , and
    analysisLabel
    per CIF
  4. If data is missing or stale, check the Business Flow monitoring frequency — see FAQ

  1. 从Compliance Assistant的DORA框架设置中获取CIF的Business Flow ID
  2. 使用相关
    bizflow.id
    值运行CIF健康状况查询
  3. 展示每个CIF的
    fulfillment
    errors
    analysisLabel
  4. 如果数据缺失或过时,请检查Business Flow的监控频率——查看FAQ

Improving the Compliance Score

提升合规评分

The Dynatrace score reflects current ICT risk posture in real time. To improve it:
  1. Address incidents promptly — resolve potential major incidents and unclassified problems affecting CIFs
  2. Remediate security detection findings and vulnerabilities — see Gain insights and How do I fix detected vulnerabilities?
  3. Fix ICT asset misconfigurations — see Stay compliant with Security Posture Management
  4. Ensure monitoring coverage — confirm that real-time protection and monitoring are enabled across all CIFs
Improving the score reduces observable ICT risk. It does not constitute formal compliance or legal readiness.

Dynatrace评分实时反映当前ICT风险状态。要提升评分:
  1. 及时处理事件——解决影响CIF的潜在重大事件和未分类问题
  2. 整改安全检测结果和漏洞——查看获取洞察如何修复检测到的漏洞?
  3. 修复ICT资产配置错误——查看通过Security Posture Management保持合规
  4. 确保监控覆盖——确认所有CIF均已启用实时防护和监控
提升评分可降低可观测的ICT风险,但代表正式合规或法律就绪。

FAQ

FAQ

How often are CIF insights updated in Compliance Assistant?

Compliance Assistant中的CIF洞察多久更新一次?

CIF KPI insights (fulfillment and errors) are updated based on the configured generation frequency of KPI monitoring in Business Flow. The evaluation timeframe is also defined per business flow configuration.
To ensure reliable KPI evaluation and avoid missing data from long-running processes, set the evaluation timeframe to at least 3–4× the process's average duration. For example, if a CIF's average duration is 5 minutes, set the evaluation window to at least 15–20 minutes.
CIF KPI洞察(完成率和错误数)根据Business Flow中KPI监控的配置生成频率更新。评估时间范围也由每个业务流的配置定义。
为确保可靠的KPI评估并避免遗漏长流程的数据,请将评估时间范围设置为至少流程平均时长的3–4倍。例如,如果CIF的平均时长为5分钟,请将评估窗口设置为至少15–20分钟。

Why are configured CIFs not updating?

已配置的CIF为何未更新?

If you have recently edited or added business processes configured as entities and selected them as CIFs in Compliance Assistant, it may take up to the maximum defined monitoring frequency for those business processes to be updated. Adjust the monitoring frequency in the business flow configuration to reduce the delay.

如果您最近编辑或添加了配置为实体的业务流程,并在Compliance Assistant中将其选为CIF,可能需要最长达到业务流程定义的监控频率的时间才能更新。调整业务流配置中的监控频率可减少延迟。

References

参考资料