Skip to content

Set Up Service Catalog

Your service catalog is the foundation for LanternOps to map your offerings to compliance controls and identify revenue opportunities.

  1. Navigate to SettingsService Catalog
  2. Click Add Service

Basic Information:

  • Service name
  • Description
  • Service category
  • Pricing (MRR)

Example:

Service: Advanced Email Security
Category: Email Protection
MRR: $18/user/month
Description: Phishing protection, URL rewriting, attachment sandboxing

Map to Controls:

Select which compliance controls this service satisfies:

  • HIPAA 164.312(e)(1) - Transmission Security
  • CIS 7.1-7.7 - Email and Web Browser Protections
  • NIST AC-17 - Remote Access
  • SOC 2 CC6.1 - Logical Access Controls

Assets Covered:

  • User accounts
  • Mailboxes
  • Endpoints
  • Servers

Integration Data:

  • Source: Microsoft 365
  • Evidence: Email security logs
  • Refresh: Real-time

Common Categories:

  • Endpoint Protection
  • Email Security
  • Backup & Disaster Recovery
  • Network Security
  • Access Management
  • Monitoring & Alerting
  • Compliance Management

Per-User:

  • Email security
  • Endpoint protection
  • MFA services

Per-Device:

  • RMM monitoring
  • EDR protection
  • Backup services

Flat-Rate:

  • Network firewall
  • SIEM/logging
  • Compliance reporting

Tiered:

  • Basic vs Advanced packages
  • Bronze/Silver/Gold tiers
  • Feature-based pricing

Create Bundles:

  • Essential Security Stack
  • Compliance Starter Pack
  • Complete Protection Suite

Bundle Benefits:

  • Simplified pricing
  • Better value proposition
  • Easier upsells

Instead of:

  • ❌ “Security Services”
  • ❌ “Monitoring”

Use:

  • ✅ “Advanced Email Security with Phishing Protection”
  • ✅ “24/7 SIEM Monitoring with Automated Response”

Link services to all applicable controls:

  • EDR → 8-12 controls across frameworks
  • Email Security → 6-10 controls
  • Backup → 4-8 controls
  • Review quarterly
  • Add new services
  • Update pricing
  • Refine mappings

Specify data sources:

  • Integration providing evidence
  • Metrics to collect
  • Validation criteria