Tasks

Adopt a framework,
the worklist writes itself

A task is a unit of work with an owner, a due date and a status. Adopt a framework and its tasks seed themselves, linked to the controls they serve; add your own alongside. Filter the list by framework, status or owner, and nothing falls through the cracks between adoption and the audit.

Start for freeBook a conversation
++++
app.devguard.ch / tasks
7 open
Worklist
Tasks done
68%
of all tasks
Done34
In progress03
To do13
Everything that moves you toward audit-ready
TSK-012
Document backup procedure
ISO 27001
TSK-013
Quarterly access review
SOC 2
TSK-014
Write the scope statement
ISO 27001
TSK-015
Approve supplier policy
ISO 27001
Seeded from the framework you adopt — each task linked to its control
Every framework
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • Swiss nFADP
How it works

Seeded, owned, done

Adopting a framework writes the worklist, roles and people own the items, and statuses carry each one from to-do to done.

01

Adopt a framework, get the worklist

Each framework ships task templates for the work it actually requires. When you adopt it, those clone into your worklist linked to the relevant controls — so instead of staring at 93 controls, you start with a concrete list of things to do.

02

Give every task an owner and a date

Assign to a business role so ownership survives people changes, or to a person for one-off work. Set priority and deadline, and overdue work flags itself in red on the list and the dashboard.

Attached to the thing it’s about

A task can link one record — a control, risk, policy, evidence item, asset, vendor or audit. Open the task and jump straight to the thing the work is on, or add a task from the record’s own Tasks tab and the link fills itself in.

03

Statuses that mean something

To do, in progress, in review, done, cancelled — the worklist reads at a glance, per framework and per owner. The same tasks feed the Roadmap, where their deadlines are laid out on a timeline toward your audit-ready date.

Why it’s built this way

A worklist that knows what a control is

Four choices behind how tasks work here — each one something you can check, not an adjective.

01

Seeded when you adopt, not typed in

Adopt a framework and its task templates clone into your worklist, each linked to the control it serves — the “what do we actually have to do?” list writes itself on day one.

02

Owned by a role, not trapped with a person

Assign a task to a business role and ownership survives every personnel change; assign to a person when it’s genuinely one-off. Either way, everyone’s own tasks show on their profile.

03

Attached to the thing it’s about

A task can link one record (a control, risk, policy, evidence item, asset, vendor or audit), so you jump from the work item straight to the thing the work is on.

04

One list across every framework

ISO 27001, SOC 2 and GDPR work sit in the same filterable worklist with stable TSK IDs, so each owner sees their open work without hopping between framework silos.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where tasks fit in

Tasks are the human work of the program — seeded by the frameworks you adopt, planned on the roadmap, due alongside everything else on the calendar.

ISO 27001audit-ready · Oct 24
W1W2W3W4W5

Roadmap

Your open tasks on a timeline, planned toward a target.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Adopting a framework seeds its tasks, linked to controls.

EventPR merged
ActionEvidence captured

Actions

Automated runs on a schedule — tasks are the human work.

JUN
ISO review
in 3 days

Deadlines

Reviews and renewals, alongside your task due dates.

FAQ

The questions evaluators ask.

Where do tasks come from — do I create them all?

Both. Adopting a framework seeds tasks automatically from that framework’s templates, each linked to the relevant control. And you can create tasks manually at any time — from the worklist, or directly from the record the work is about.

How are tasks different from actions and treatment actions?

A task is a unit of human work with an owner, a due date and a status. An action is an automated run devguard executes on a schedule or a trigger. A treatment action is a remediation tied to specific risks. Three different things, kept apart on purpose so none of them turns into a junk drawer.

Who can own a task?

A business role or an individual member. Role ownership keeps tasks stable as people change positions; personal assignment fits one-off work. A person’s tasks, direct or via their roles, are listed on their profile, so “what’s on my plate?” has one answer.

How is this different from a spreadsheet or a generic to-do app?

A generic list doesn’t know what a control is. A devguard task is linked to the control, risk or policy it serves, carries framework context, shows up on the Roadmap timeline, and was seeded from the framework you adopted — so the list is the compliance program, not a copy of it.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your worklist is yours and exportable in full at any time, with no lock-in.

Know exactly what’s left between you and the audit

Adopt a framework and start from a seeded worklist instead of a blank page — every task owned, dated and linked to the control it serves.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free