Framework Mappings
Every Controlio finding is mapped to recognized security frameworks. A single scan produces a compliance score for several of them, so you do not have to audit each one separately.
Supported frameworks
| Framework | Scope |
|---|---|
| CIS Benchmark | Hardening benchmarks for Microsoft 365 |
| NIST | NIST 800-53 control-family references |
| ISO 27001 | Information security management controls |
| Microsoft Security Baseline | Microsoft's recommended security baseline |
How it works
Each control result, whether pass, warning, fail or not evaluated, is tied to the relevant framework items. The report and the portal show a separate compliance percentage for each framework.
MITRE ATT&CK is separate
MITRE ATT&CK is not a compliance framework. It is a threat-mapping layer. See MITRE ATT&CK.