Skip to main content
Programme context · Not legal advice

An auditor does not ask what you monitor. They ask what it did, and on which date.

ShadowMap is a monitoring platform, not a compliance adviser. What it produces for an RBI file is evidence that a control was operating — the window a scan ran in, the estate it covered, the state each finding was given, who worked it, and when it closed.

Said plainly, and not in a footer: this is programme context, not legal advice. Evidence is an input to a regulatory decision, never the decision itself. The assessment work — what an instrument requires of you, and whether you meet it — belongs to Security Brigade.

One line of the file

What the argument reduces to

Everything further down this page is a longer way of saying that these fields exist, carry their own dates, and were written while the work was happening rather than afterwards.

Illustrative evidence export — synthetic data, demo tenant
Evidence export · external monitoring acmecorp · demo tenant
Period
01–30 Apr 2026 · exported 02 May 2026
Scan window
03 Apr 2026, 02:14 → 05:41 IST
Scope at run
1,284 attributed assets · inventory as at 03 Apr 2026
Finding
SM-4471 · credential exposure · corporate SSO
State at capture
Maybe Working — probe inconclusive (MFA interstitial)
Validation
Session CART-04-118 · scope: 2 hosts, non-destructive
Not tested
SSO host — exploitation outside the authorised scope
Workflow
assigned 03 Apr 14:22 · acknowledged 16:05 · closed 07 Apr 11:38
Against your SLA
4d 21h elapsed, against the 7d target in your agreement
Audit
11 access and change entries retained
  1. A window, not a moment

    Two timestamps: when the run opened and when it finished. Both are already in the past by the time anybody asks about them, which is the whole of why they answer the question.

  2. A count and an as-at date, together

    Either one alone is worth little. A count with no as-at date is a number somebody could have produced this morning, and a date with no count says nothing about what was covered.

  3. The state as at capture

    Findings carry the state they held when they were written, not the one they turned out to deserve. A later upgrade adds a state beside it rather than replacing it.

  4. The line that records what was not done

    Validation is bounded to a stated scope and everything outside it is written down as untested rather than left silent. The least impressive line in the export, and the one that survives questioning best.

  5. Both endpoints and the target

    Elapsed time is stored with the target it was measured against, so adherence is a query rather than a reconstruction from somebody’s calendar.

The boundary

This page is about artefacts, not obligations

Whether a given paragraph binds your organisation, and what it demands of you, is an assessment. That work belongs to somebody who takes responsibility for the answer.

There is a genre of vendor page that lists a regulator's paragraph numbers in one column and product features in the other, and it is nearly always wrong within a year. The mapping is a claim about what a regulator requires, made by a party with an obvious interest in the answer, and it stops being true the moment an amendment lands. So this page does not attempt one, and does not cite paragraph numbers of its own. It sets out something narrower and more durable: the records the platform already keeps, and the questions those records happen to answer.

Two conversations

Two requests, and the answer each one actually needs

Neither of these is hypothetical. They are the two moments at which an external monitoring programme either has a file or discovers that it does not.

01 Review period

“Show me that external monitoring was operating through the quarter.”

What usually gets handed over
A console screenshot, a vendor invoice, and a slide saying continuous external monitoring is in place. Between them they establish that a subscription exists.
Why it does not hold
None of it is dated to the period under review. The screenshot shows today, the invoice shows a contract, and the slide shows an intention. The question was about April, and nothing in the pack is about April.
What the record answers with
The scan windows that opened and closed in April, the attributed estate each one covered, and the findings each one produced — exported as a dated artefact rather than described in a meeting.
02 Follow-up

“And what did you do about what it found?”

What usually gets handed over
A spreadsheet of findings with a status column, rebuilt from memory and from a ticketing system that has since been migrated.
Why it does not hold
A status column records the present. It cannot show when the finding was raised, who it went to, what was decided, or whether the decision was to accept the risk knowingly — which is a defensible answer, but only if it was recorded at the time.
What the record answers with
Workflow history kept rather than overwritten: assignment, comment, state change and closure, each carrying its own timestamp — and, where the finding was validated, the session identifier and the scope that validation was bounded to.

The evidence table

The question, the artefact, and where it comes from

The questions asked of a monitoring control are narrow and they repeat. Each one is answered by a record the platform keeps anyway, in the course of running.

What this is, and what it is notCaution As of August 2026
  • ShadowMap produces records of external monitoring activity. What those records are worth against a specific obligation is a judgement your auditor, your adviser and ultimately your regulator make — not one a product page can make for you.
  • The governing instrument for commercial banks is the Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/410), issued on 31 July 2026 with immediate effect. Other regulated entities sit under different instruments; establish which one binds you before relying on anything here.
  • Evidence is an input to a regulatory decision, never the decision. A dated scan record shows that a control ran. It does not show that the control was sufficient, and nobody should present it as though it did.

Deliberately excluded

  • We do not opine on whether you are compliant, and no ShadowMap output should be read as that opinion.
  • We do not publish a paragraph-to-feature mapping. An unmaintained mapping is worse than none, and the instrument moved on 31 July 2026.
  • We do not replace an audit, an assessment or counsel. Security Brigade does the assessment work; it is a separate engagement, on a separate site, priced separately.
Auditor question, the artefact that answers it, and the part of ShadowMap that produces it
What an auditor asksThe artefact that answers itWhere it comes from
Was the control operating during the period under review? Dated scan windows — when each discovery run against your attributed estate opened and when it finished. Attack Surface Management
Windows rather than a running total: each run is its own record, so a quarter is a set of dated runs and a gap in the set is visible as a gap rather than hidden inside an average.
Over what scope? The attributed asset inventory as it stood on the date of that run, with the evidence tying each asset to your organisation. Attack Surface Management
Scope drift is the usual failure. An estate captured at the time of the run cannot be reconstructed afterwards from today’s inventory, and an auditor asking about April is entitled to April’s scope.
What did it find, and how certain are you? Findings carrying an explicit state — including the states that say something was not established. Dark Web Monitoring
Credential findings carry one of four states: Confirmed Working, Maybe Working, Not Working and Not Tested. The last is the one that matters in a file. A record that states what was not established is more defensible under questioning than one that quietly implies everything was.
Was anything actually tested, or only asserted? A session identifier for each validation run, the scope that session was bounded to, and the evidence it returned. Continuous Automated Red-Teaming
Validation runs where it is safe and authorised, never universally. Because the record states which assets were in scope for a given session, the boundary of the claim sits in the file rather than in somebody’s recollection of a conversation.
Who saw it, and what was done about it? Workflow history — assignment, comments, state changes and closure, accumulated rather than overwritten. The finding workflow
A status column records the present tense. History answers the second question in every conversation about a finding, which is what happened next and who decided it.
How quickly did you respond? SLA records measured against the response targets in your own agreement, per finding. The finding workflow
The record, not a headline figure. We do not publish a response-time number, because the targets that matter to a supervisor are the ones you committed to, not the ones a vendor advertises.
Who in your team touched the record? Audit logs covering access to the platform and changes made within it. The finding workflow
Relevant less often than the rest of this table, and decisive when it is — usually when a finding’s closure is being questioned rather than its discovery.
And your third-party and outsourced technology providers? The same outside-in record for each vendor, produced with the identical categories, the same maths and the same bands used on your own estate. Third-Party Risk Management
Whether your file has to reach a given provider is a question for your adviser, not for us. What this settles is the part that is ours to settle: two files produced by different methods cannot be set beside each other, and these are produced by the same one.

Auditor question, the artefact that answers it, and the part of ShadowMap that produces it

Was the control operating during the period under review?

The artefact that answers it
Dated scan windows — when each discovery run against your attributed estate opened and when it finished.
Where it comes from
Attack Surface Management

Windows rather than a running total: each run is its own record, so a quarter is a set of dated runs and a gap in the set is visible as a gap rather than hidden inside an average.

Over what scope?

The artefact that answers it
The attributed asset inventory as it stood on the date of that run, with the evidence tying each asset to your organisation.
Where it comes from
Attack Surface Management

Scope drift is the usual failure. An estate captured at the time of the run cannot be reconstructed afterwards from today’s inventory, and an auditor asking about April is entitled to April’s scope.

What did it find, and how certain are you?

The artefact that answers it
Findings carrying an explicit state — including the states that say something was not established.
Where it comes from
Dark Web Monitoring

Credential findings carry one of four states: Confirmed Working, Maybe Working, Not Working and Not Tested. The last is the one that matters in a file. A record that states what was not established is more defensible under questioning than one that quietly implies everything was.

Was anything actually tested, or only asserted?

The artefact that answers it
A session identifier for each validation run, the scope that session was bounded to, and the evidence it returned.

Validation runs where it is safe and authorised, never universally. Because the record states which assets were in scope for a given session, the boundary of the claim sits in the file rather than in somebody’s recollection of a conversation.

Who saw it, and what was done about it?

The artefact that answers it
Workflow history — assignment, comments, state changes and closure, accumulated rather than overwritten.
Where it comes from
The finding workflow

A status column records the present tense. History answers the second question in every conversation about a finding, which is what happened next and who decided it.

How quickly did you respond?

The artefact that answers it
SLA records measured against the response targets in your own agreement, per finding.
Where it comes from
The finding workflow

The record, not a headline figure. We do not publish a response-time number, because the targets that matter to a supervisor are the ones you committed to, not the ones a vendor advertises.

Who in your team touched the record?

The artefact that answers it
Audit logs covering access to the platform and changes made within it.
Where it comes from
The finding workflow

Relevant less often than the rest of this table, and decisive when it is — usually when a finding’s closure is being questioned rather than its discovery.

And your third-party and outsourced technology providers?

The artefact that answers it
The same outside-in record for each vendor, produced with the identical categories, the same maths and the same bands used on your own estate.
Where it comes from
Third-Party Risk Management

Whether your file has to reach a given provider is a question for your adviser, not for us. What this settles is the part that is ours to settle: two files produced by different methods cannot be set beside each other, and these are produced by the same one.

None of the above is a statement that a control was adequate, or that an obligation has been discharged. It is a statement that something ran, over a stated scope, on a stated date, with a stated result — which is the part of the conversation a platform can settle. The rest is an assessment, and it routes to Security Brigade.

The life of one record

Where an evidence line comes from

Nothing in this sequence is produced for an audit. It is the ordinary operating record of a monitoring platform — which is exactly why it survives being read closely.

When the instrument moves

The framework changed on 31 July 2026

Evidence has a shelf life. So does anybody's tidy mapping of features to paragraph numbers.

The Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 were issued on 31 July 2026 under reference RBI/DoS/2026-27/410, with immediate effect, replacing the framework that had governed commercial banks until then. A good deal of vendor and consultancy material still in circulation describes the instrument that was replaced — which is a reason to check the date on anything you read about this, including this page. What exactly the change repeals, what it leaves standing and what either means for you is covered by the RBI advisory practice at Security Brigade, which is maintained against the instrument itself.

ShadowMap tracks advisories and directives as programme context, so that a change reaches the people running the programme rather than arriving through an auditor six months later. It reports that something moved and matches it against what has actually been discovered on your estate. It does not tell you what the change requires of you — see Regulatory Intelligence for what that tracking does and, just as importantly, where it stops.

Questions this page gets asked

Before you put any of this in a file

Does using ShadowMap make us compliant with the RBI framework?

No — and anyone who tells you a tool does that is selling something they cannot deliver. Compliance is a determination made about your organisation by your auditor and ultimately by your regulator. What ShadowMap produces is evidence that an external monitoring control was operating: dated, scoped, and attributable to specific assets. What that evidence is worth against a particular obligation is an assessment, and assessment is a Security Brigade engagement rather than a product feature.

Can you map ShadowMap to specific paragraphs of the Directions?

Not on this page, and the omission is deliberate. A published mapping is a claim about what a regulator requires; it goes stale the moment an amendment lands, and the governing instrument for commercial banks itself moved on 31 July 2026. It is also advisory work rather than product documentation. In an engagement, an adviser does that mapping against the instrument that actually binds you and against your own control set — which is the only version of it worth having.

Our auditor wants proof the monitoring ran, not a dashboard tour. What do we hand over?

The scan window records covering the period under review, the attributed inventory as it stood on those dates, the findings each run produced with the state each one was given, and the workflow history showing what was done next. Where a finding was validated, the session identifier and the scope that session was bounded to. It is the ordinary operating record of the platform, exported — nothing is assembled specially for the audit, which is precisely what makes it worth reading.

Does this cover third-party and outsourced technology providers?

Yes, using the same outside-in methodology — the identical categories, the same maths and the same bands applied to your own estate. That symmetry is the point: a vendor file and an internal file produced by different methods cannot be set beside each other, and the questions asked about your own external posture tend to be asked again about the providers you depend on.

Is any of this legal advice?

No. It is programme context. Every artefact described here is a record of something the platform did, and a record is an input to a regulatory decision rather than the decision itself. Whether a control was adequate, whether an obligation applies to you, and what follows if it does are questions for your adviser, your auditor and your regulator.

See what the evidence file would actually contain

One apex domain, two business days, a written snapshot of what is already reachable from outside your estate — produced by the same runs that produce the records above. No call required.