Skip to content
Frequently asked questions

How it works, who it is for, and where it is heading

Fifteen answers about the 75-control instrument, the risk assessment module and the road ahead for the product. If yours is not here, the contact form reaches the same team that runs the audits.

How the system works

From the questionnaire to the risk index, and from there to the remediation plan.

  • 01

    What exactly is Rivendel?

    It is a database administration consultancy and, at the same time, the system your audit runs on. We do not hand over a hand-written opinion: we apply an instrument of 75 controls grouped into 25 processes and 7 domains, and those answers produce a risk index that can be recalculated months later with the very same method.

  • 02

    What is the instrument of 75 controls based on?

    On the ISO/IEC 27000 family — 27002 for the controls and 27007 for how they are audited — with COBIT 4.1 covering governance. Every control states which standard it comes from, and that reference is printed in the report: whoever reads a finding can go to the source without asking us.

  • 03

    How is an audit answered?

    The auditor opens an audit for a specific organization and scope, then walks the controls one by one. Each control is answered with complies, does not comply or not applicable, a maturity level from 1 to 5, and the finding that backs that answer. Nothing forces you to finish in one sitting: progress is saved control by control.

  • 04

    How is the risk index calculated?

    With stored procedures in the database, not with a formula hidden in the application. Compliance is the ratio of complying controls to applicable controls — those marked «not applicable» leave the divisor, they do not count as failures — and the index combines that compliance with average maturity on a 1 to 5 scale.

  • 05

    What happens after an audit is closed?

    The part that actually reduces risk begins. Every failed control can open a remediation with an owner and a committed date; the system flags the ones that fall due, and scheduling the re-audit re-evaluates only what was remediated. Comparing two audits of the same organization shows what moved and what stayed put.

  • 06

    What does the system deliver in the end?

    An executive report written for two readers at once: it opens with the overall index, the domain matrix and the critical findings — for whoever signs the budget — and continues with the remediation plan control by control, each with its source standard, for whoever has to fix it. It prints or saves as PDF without the navigation chrome, and the public instrument also exports progress as CSV and JSON.

Who it is for

Who uses it, who reads it, and what it takes to start.

  • 07

    What kind of organization does it serve?

    The one that already depends on its databases and cannot say how much risk it carries: credit unions, public institutions, mid-sized companies running an ERP on an engine nobody has audited in years. You do not need a security department; you need someone who can answer how backups are taken and who holds access.

  • 08

    Who uses the system, and in which role?

    There are two roles. The auditor opens audits, answers controls and follows up remediations in their own portfolio: they cannot see another consultant's work. The database administrator additionally maintains the master catalog — domains, processes and controls — which is what everyone else is evaluated against.

  • 09

    Is it useful if I am the in-house DBA rather than a consultant?

    Yes, and that is one of the intended uses. The public instrument is answered without an account and without sending anything to any server: it works as a self-diagnosis before hiring anyone. What the internal module adds is memory — history, comparison and remediations — not different questions.

  • 10

    What do I need to get started?

    For the public instrument, a browser. For the assessment module, an auditor account and the details of the organization to be audited. We do not ask for access to your databases: the audit is built from interviews and evidence, and production credentials never leave your organization.

Proposals for future projects

What is under study for the coming stages. These are proposals, not features available today.

  • 11

    Will there be continuous database monitoring?

    That is the main proposal. The panel already carries the connected databases card, which is the preview of that module: the very list of instances monitoring would feed on. What is missing is reading latency, space, locks and last backup from each one, so the diagnosis stops being a quarterly snapshot and becomes a continuous signal.

  • 12

    Will it extend to engines other than Oracle?

    The instrument is already engine-independent: the 75 controls ask about backups, access and encryption, not about one vendor's syntax. What is under study is whether the system itself can run on PostgreSQL or SQL Server besides Oracle, swapping the data access layer without touching the views.

  • 13

    Will evidence be attachable to each finding?

    It is proposed. Today a finding is text, which forces you to describe a screenshot or a query output in words. Attaching the file to the control would close that gap, on the condition that the evidence inherits the same access control as the audit it belongs to.

  • 14

    Will there be automatic alerts and notices?

    The system already knows which remediations are overdue and shows them on entry. The proposed next step is for that notice to leave the system — an email to the owner before the due date, not after — and for the re-audit to propose itself once every remediation in an audit is closed.

  • 15

    Will an interface open up for integration with other systems?

    That is the longest-term proposal, and the one least worth rushing. Publishing the risk index and remediation status to a corporate dashboard or a ticketing system only pays off once the data model has settled; doing it earlier means maintaining a public interface on top of a schema that is still moving.

Is your question missing from the list?

Write to us and the person who audits will answer, not a form. If you would rather start on your own, the 75-control instrument is open and asks nobody for their details.