Prepared for
Security coverage report — what your licences already cover
Requirements in our crosswalk reachable from the tiers you selected. Open each list to see them by name.
ISO 27001 2022 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
ISO 27002 2022 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
CIS CSC 8.1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
CIS CSC 8.1 IG1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
CIS CSC 8.1 IG2 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
CIS CSC 8.1 IG3 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
AICPA TSC 2017:2022 (used for SOC 2) appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
PCI DSS 4.0.1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.
Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory
Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
Backup Modification and/or Destruction via Backup access control
Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.
Unprivileged user accounts are prevented from modifying and deleting backups.
Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy
Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.
Application control is implemented on workstations.
Data Backups via Backup job status
Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
Backups of data, applications and settings are retained in a secure and resilient manner.
Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting
Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.
Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state
Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership
Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
Privileged users use separate privileged and unprivileged operating environments.
Requests for privileged access to systems and their resources are validated when first requested.
Unprivileged user accounts cannot logon to privileged operating environments.
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
Software & Firmware Patching via Patch deployment state
Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Testing for Reliability & Integrity via Backup integrity check
Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
Vulnerability Scanning via Vulnerability findings
Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
Anomalous Behavior via Endpoint detection and response
Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.
Allowed and blocked application control events are centrally logged.
Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory
Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
Backup Modification and/or Destruction via Backup access control
Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.
Unprivileged user accounts are prevented from modifying and deleting backups.
Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy
Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.
Application control is implemented on workstations.
Application control is implemented on internet-facing servers.
Microsoft’s recommended application blocklist is implemented.
Application control rulesets are validated on an annual or more frequent basis.
Content of Event Logs via Authentication events, Endpoint logging policy
Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.
Data Backups via Backup job status
Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
Backups of data, applications and settings are retained in a secure and resilient manner.
Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting
Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.
Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state
Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.
Multi-factor authentication is used to authenticate unprivileged users of systems.
Multi-factor authentication is used to authenticate privileged users of systems.
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Successful and unsuccessful multi-factor authentication events are centrally logged.
Multi-factor authentication used for authenticating users of online services is phishing-resistant.
Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting
Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.
Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership
Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
Privileged users use separate privileged and unprivileged operating environments.
Requests for privileged access to systems and their resources are validated when first requested.
Privileged access events are centrally logged.
Privileged access to systems and their resources are disabled after 45 days of inactivity.
Privileged user account and security group management events are centrally logged.
Privileged operating environments are not virtualised within unprivileged operating environments.
Unprivileged user accounts cannot logon to privileged operating environments.
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
Software & Firmware Patching via Patch deployment state
Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Testing for Reliability & Integrity via Backup integrity check
Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
Vulnerability Scanning via Vulnerability findings
Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
Anomalous Behavior via Endpoint detection and response
Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.
Allowed and blocked application control events are centrally logged.
Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory
Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
Backup Modification and/or Destruction via Backup access control
Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.
Unprivileged user accounts are prevented from modifying and deleting backups.
Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy
Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.
Application control is implemented on workstations.
Application control is implemented on internet-facing servers.
Microsoft’s recommended application blocklist is implemented.
Application control rulesets are validated on an annual or more frequent basis.
Content of Event Logs via Authentication events, Endpoint logging policy
Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.
Data Backups via Backup job status
Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
Backups of data, applications and settings are retained in a secure and resilient manner.
Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting
Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.
Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state
Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.
Multi-factor authentication is used to authenticate unprivileged users of systems.
Multi-factor authentication is used to authenticate privileged users of systems.
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication is used to authenticate users of data repositories.
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Successful and unsuccessful multi-factor authentication events are centrally logged.
Multi-factor authentication used for authenticating users of online services is phishing-resistant.
Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting
Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.
Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership
Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
Privileged users use separate privileged and unprivileged operating environments.
Requests for privileged access to systems and their resources are validated when first requested.
Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
Privileged access events are centrally logged.
Privileged access to systems and their resources are disabled after 45 days of inactivity.
Just-in-time administration is used for the administration of systems and their resources.
Privileged user account and security group management events are centrally logged.
Privileged operating environments are not virtualised within unprivileged operating environments.
Unprivileged user accounts cannot logon to privileged operating environments.
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
Security Event Monitoring via Endpoint detection and response
Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Software & Firmware Patching via Patch deployment state
Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Testing for Reliability & Integrity via Backup integrity check
Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
Vulnerability Scanning via Vulnerability findings
Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.
Anomalous Behavior via Endpoint detection and response
Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.
Allowed and blocked application control events are centrally logged.
Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory
Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.
A networked IT equipment register is developed, implemented, maintained and verified on a regular basis.
Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
The CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.
Backup Modification and/or Destruction via Backup access control
Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.
Unprivileged user accounts are prevented from modifying and deleting backups.
Centralized Management of Flaw Remediation Processes via Patch deployment state
Mechanisms exist to centrally-manage the flaw remediation process.
A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.
Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.
Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy
Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.
Application control is implemented on workstations.
All users (with the exception of local administrator accounts and break glass accounts) cannot disable, bypass or be exempted from application control.
Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.
When implementing application control using path rules, only approved users can modify approved files and write to approved folders.
When implementing application control using publisher certificate rules, publisher names and product names are used.
Application control is implemented on internet-facing servers.
Microsoft’s recommended application blocklist is implemented.
Application control rulesets are validated on an annual or more frequent basis.
Content of Event Logs via Authentication events, Endpoint logging policy
Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.
Security-relevant events for Microsoft Windows operating systems are centrally logged.
For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.
All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.
Security-relevant events for databases are centrally logged, including:
- access or modification of particularly important content
- addition of new users, especially privileged users
- changes to user roles or privileges
- attempts to elevate user privileges
- queries containing comments
- queries containing multiple embedded queries
- database and query alerts or failures
- database structure changes
- database administrator actions
- use of executable commands
- database logons and logoffs.
Successful and unsuccessful single-factor authentication events are centrally logged.
Software generates sufficient event logs to support the detection of cyber security events.
Data & Asset Classification via Data classification and labelling
Mechanisms exist to ensure data and assets are categorized in accordance with applicable statutory, regulatory and contractual requirements.
Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.
Protective marking tools do not automatically insert protective markings into emails.
Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.
IT equipment, with the exception of high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.
ASD’s approval is sought before applying labels to external surfaces of high assurance IT equipment.
Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.
Databases and their contents are classified based on the sensitivity or classification of data that they contain.
Data Backups via Backup job status
Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.
Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
Backups of data, applications and settings are retained in a secure and resilient manner.
Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting
Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.
Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clients, PDF applications and security products are restricted to an organisation-approved set.
Heuristic / Nonsignature-Based Detection via Anti-malware protection
Mechanisms exist to utilize heuristic / nonsignature-based antimalware detection capabilities.
Files imported or exported via gateways or CDSs undergo content validation.
Files imported or exported via gateways or CDSs undergo content conversion.
Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.
Archive files imported or exported via gateways or CDSs are unpacked in order to undergo content filtering checks.
Encrypted files imported or exported via gateways or CDSs are decrypted in order to undergo content filtering checks.
An antivirus application is implemented on workstations and servers with:
- signature-based detection functionality enabled and set to a high level
- heuristic-based detection functionality enabled and set to a high level
- reputation rating functionality enabled
- ransomware protection functionality enabled
- detection signatures configured to update on at least a daily basis
- regular scanning configured for all fixed disks and removable media.
SOEs provided by third parties are scanned for malicious code and configurations.
A protective DNS service is used to block access to known malicious domain names.
Host Intrusion Detection and Prevention Systems (HIDS / HIPS) via Endpoint detection and response
Mechanisms exist to utilize Host-based Intrusion Detection / Prevention Systems (HIDS / HIPS), or similar technologies, to monitor for and protect against anomalous host activity, including lateral movement across the network.
A HIPS or EDR solution is implemented on critical servers and high-value servers.
A HIPS or EDR solution is implemented on workstations.
If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
Malicious Code Protection (Anti-Malware) via Anti-malware protection
Mechanisms exist to utilize antimalware technologies to detect and eradicate malicious code.
Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.
Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
Media Marking via Data classification and labelling
Mechanisms exist to mark media in accordance with data protection requirements so that personnel are alerted to distribution limitations, handling caveats and applicable security requirements.
Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre intervals and marked as ‘TS RUN’.
Media, with the exception of internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.
Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its classification.
Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains its classification.
Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its classification.
Media Use via Removable media control
Mechanisms exist to restrict the use of types of digital media on systems or system components.
Automatic execution features for removable media are disabled.
If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
Monitoring for Indicators of Compromise (IOC) via Endpoint detection and response
Automated mechanisms exist to identify and alert on Indicators of Compromise (IoC).
Cyber security personnel have access to sufficient data sources and tools to ensure that systems can be monitored for key indicators of compromise.
Keying material is changed when compromised or suspected of being compromised.
Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state
Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.
Multi-factor authentication is used to authenticate unprivileged users of systems.
Multi-factor authentication is used to authenticate privileged users of systems.
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication is used to authenticate users of data repositories.
Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.
Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Successful and unsuccessful multi-factor authentication events are centrally logged.
Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
Multi-factor authentication used for authenticating users of online services is phishing-resistant.
Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.
Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership
Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
Foreign nationals, including seconded foreign nationals, do not have privileged access to systems that process, store or communicate AUSTEO or REL data.
Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
Privileged users use separate privileged and unprivileged operating environments.
Requests for privileged access to systems and their resources are validated when first requested.
Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
Privileged access events are centrally logged.
Privileged user accounts are members of the Protected Users security group.
Privileged access to systems and their resources are disabled after 45 days of inactivity.
Just-in-time administration is used for the administration of systems and their resources.
Privileged user account and security group management events are centrally logged.
Privileged operating environments are not virtualised within unprivileged operating environments.
Unprivileged user accounts cannot logon to privileged operating environments.
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
Privileged user accounts are configured as sensitive and cannot be delegated.
The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.
Removable Media Security via Removable media control
Mechanisms exist to restrict removable media in accordance with data handling and acceptable usage parameters.
A removable media usage policy is developed, implemented and maintained.
A removable media register is developed, implemented, maintained and verified on a regular basis.
Security Event Monitoring via Endpoint detection and response
Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Software & Firmware Patching via Patch deployment state
Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.
Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.
Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and verified on a regular basis.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
Software Firewall via Host firewall management
Mechanisms exist to utilize host-based firewall software, or a similar technology, on all endpoint devices, where technically feasible.
A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.
Testing for Reliability & Integrity via Backup integrity check
Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
Vulnerability Scanning via Vulnerability findings
Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.
Systems have a continuous monitoring plan that includes:
- conducting vulnerability scans for systems at least fortnightly
- conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter
- analysing identified vulnerabilities to determine their potential impact
- implementing mitigations based on risk, effectiveness and cost.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.
Networks are scanned at least monthly to identify any credentials that are being stored in the clear.
Anomalous Behavior via Endpoint detection and response
Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.
Personnel activity and technology usage are monitored to find potentially adverse events
Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory
Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.
Inventories of hardware managed by the organization are maintained
Inventories of software, services, and systems managed by the organization are maintained
Content of Event Logs via Authentication events, Endpoint logging policy
Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.
Log records are generated and made available for continuous monitoring
Data & Asset Classification via Data classification and labelling
Mechanisms exist to ensure data and assets are categorized in accordance with applicable statutory, regulatory and contractual requirements.
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Data Backups via Backup job status
Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Backups of data are created, protected, maintained, and tested
Malicious Code Protection (Anti-Malware) via Anti-malware protection
Mechanisms exist to utilize antimalware technologies to detect and eradicate malicious code.
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Monitoring for Indicators of Compromise (IOC) via Endpoint detection and response
Automated mechanisms exist to identify and alert on Indicators of Compromise (IoC).
Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting
Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.
Installation and execution of unauthorized software are prevented
Security Event Monitoring via Endpoint detection and response
Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.
Information on adverse events is provided to authorized staff and tools
Networks and network services are monitored to find potentially adverse events
Software & Firmware Patching via Patch deployment state
Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.
Software is maintained, replaced, and removed commensurate with risk
Testing for Reliability & Integrity via Backup integrity check
Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.
Vulnerability Scanning via Vulnerability findings
Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.
Vulnerabilities in assets are identified, validated, and recorded
You are paying more than once for this evidence. Overlap is not automatically waste, but it should be a decision rather than an accident.
Asset last seen — NinjaOne Endpoint Management and Microsoft Defender for Endpoint Plan 1
Both NinjaOne Endpoint Management and Microsoft Defender for Endpoint Plan 1 provide this. Overlap is not automatically waste — a second independent source raises confidence — but it is worth knowing you are paying for it twice.
https://www.ninjaone.com/endpoint-management/ · checked 2026-08-18
https://learn.microsoft.com/en-us/defender-endpoint/api/machine · checked 2026-08-20
Operating system fingerprint — NinjaOne Endpoint Management and Microsoft Defender for Endpoint Plan 1
Both NinjaOne Endpoint Management and Microsoft Defender for Endpoint Plan 1 provide this. Overlap is not automatically waste — a second independent source raises confidence — but it is worth knowing you are paying for it twice.
https://www.ninjaone.com/endpoint-management/ · checked 2026-08-18
https://learn.microsoft.com/en-us/defender-endpoint/api/machine · checked 2026-08-20
Software inventory — NinjaOne Endpoint Management and Microsoft Defender for Business Standalone or Business Premium
Both NinjaOne Endpoint Management and Microsoft Defender for Business Standalone or Business Premium provide this. Overlap is not automatically waste — a second independent source raises confidence — but it is worth knowing you are paying for it twice.
https://www.ninjaone.com/endpoint-management/ · checked 2026-08-18
https://learn.microsoft.com/en-us/defender-business/mdb-overview · checked 2026-08-20
Attack surface reduction rules — Microsoft Defender for Endpoint Plan 1 and Microsoft Intune Plan 1
Both Microsoft Defender for Endpoint Plan 1 and Microsoft Intune Plan 1 provide this. Overlap is not automatically waste — a second independent source raises confidence — but it is worth knowing you are paying for it twice.
https://learn.microsoft.com/en-us/defender-business/mdb-overview · checked 2026-08-20
https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/licenses · checked 2026-08-17
For the products you selected: requirements in our crosswalk that no capability in our catalogue reaches.
APAC Australia Essential 8 2024
For the products you selected, no capability in our catalogue is mapped to 167 of the APAC Australia Essential 8 2024 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
19of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
APAC Australia ISM March 2026
For the products you selected, no capability in our catalogue is mapped to 931 of the APAC Australia ISM March 2026 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
47of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
NIST CSF 2.0
For the products you selected, no capability in our catalogue is mapped to 94 of the NIST CSF 2.0 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
5of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
ISO 27001 2022
For the products you selected, no capability in our catalogue is mapped to 122 of the ISO 27001 2022 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
ISO 27002 2022
For the products you selected, no capability in our catalogue is mapped to 81 of the ISO 27002 2022 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
4of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
CIS CSC 8.1
For the products you selected, no capability in our catalogue is mapped to 114 of the CIS CSC 8.1 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
18of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
CIS CSC 8.1 IG1
For the products you selected, no capability in our catalogue is mapped to 36 of the CIS CSC 8.1 IG1 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
5of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
CIS CSC 8.1 IG2
For the products you selected, no capability in our catalogue is mapped to 95 of the CIS CSC 8.1 IG2 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
15of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
CIS CSC 8.1 IG3
For the products you selected, no capability in our catalogue is mapped to 114 of the CIS CSC 8.1 IG3 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
18of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
AICPA TSC 2017:2022 (used for SOC 2)
For the products you selected, no capability in our catalogue is mapped to 58 of the AICPA TSC 2017:2022 (used for SOC 2) requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
3of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
PCI DSS 4.0.1
For the products you selected, no capability in our catalogue is mapped to 205 of the PCI DSS 4.0.1 requirements in our crosswalk. Some of those are met by policy and process rather than by any tool; others we may not have researched yet.
8of these requirements are reachable today with capabilities already mapped in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and the technical requirements we have not yet mapped are what we work through with you in a consultation.
This count reflects our catalogue as it stands today. We research and map products and capabilities continuously, so it will change as that work progresses.
See where your own products stand — free, about 3 minutes.
Check your coverage →