Written for the auditor, not the brochure
Each study takes a technology risk framework, walks its requirements in order, and says which ones the platform evidences, which need configuration, and which are not ours to close. No institution is named in any of them.
What are DevOpsArk case studies?
DevOpsArk case studies are anonymised, control-level write-ups of regulated programmes: what a framework requires, what the platform evidences, and what stays with the institution.
Frameworks written up so far
Questions about these write-ups
Because the institutions in them are regulated, and because the name is the least useful part. A logo tells you nothing about whether a control is evidenced. Each profile is a composite of real engagements, and everything technical in the write-up is specific enough to check against the published framework.
No. They are technical descriptions of which requirements a delivery and operations platform can evidence and which it cannot. Compliance is assessed against your institution as a whole, by your regulator, and every page here states plainly where the platform stops.
Usually, yes. The underlying controls repeat across technology risk regimes: asset inventory, change control, segregation of duties, patching, access, availability measurement, log retention and vulnerability management. If your framework is not written up here, bring the clause list and we will map it.
Mapping a framework of your own?
Bring the clause list or your existing gap analysis. We will tell you which requirements the platform evidences and which are yours, before you buy anything.