Controls Screen
The Controls screen shows the latest scan result for all 184 security controls in a single list. The heading tells you how many controls were scanned and how many are automatic (e.g. 184 controls · 169 automatic).
On a monitored tenant the scan runs automatically. The banner at the top says so and gives you a button to email the latest scan summary. For more on reports, see Reports.
Categories
Controls are grouped category by category: Identity & Access, Device, Application, Security Operations, Data, Email & Collaboration, and Governance. Each category header shows the number of controls in the group, how many are automatic, the count of open findings, and the compliance percentage. Open a category to see the controls inside it, or use "Expand all" to open them at once.
A control row
Each row shows the control's status as an icon, next to the control code (e.g. IAM-01), its name, and a few badges:
- Level — L1 basic, L2 advanced.
- Automatic / Attestation — Controlio measures automatic controls app-only; you mark attested ones. The distinction is explained on the Control Catalog page.
- Frameworks — the frameworks the control maps to (CIS, NIST, ISO, MS Baseline) and MITRE ATT&CK where it applies.
Statuses
A control is in one of five states:
- ✅ Passed — the setting is as expected.
- ⚠️ Warning — worth attention, but not counted as a failure.
- ❌ Failed — the setting is a clear risk.
- ✔️ Accepted — the finding has been handled with an attestation (risk acceptance, exemption or compensating control).
- — Not evaluated — the control could not be measured on this tenant (e.g. the required license is missing or no data arrived).
Filters and search
"Add filter" narrows the list on three axes: by framework (CIS, NIST 800-53, ISO 27001, MS Baseline), by type (automatic or attestation), and by status (failed, warning, passed, accepted, not evaluated). The search box filters by code and title. To see only the risks you have not handled yet, for example, apply the "Failed" status filter.
Closing a finding
On a failed control there is a close link below the row. From there you close the finding with an attestation: you state that you accept the risk, exempt the control, or have a compensating control in place, with a short rationale and, if you like, an evidence link. A closed finding moves to the "Accepted" state.
These attestations are kept across the tenant. Every administrator sees the same record from any device, and it is retained as an audit trail.
Accepting a finding does not change the underlying setting; it only records your decision with its rationale. If the setting is genuinely corrected later, the control passes again on its own.