Skip to main content

SEC — Security Operations

Audit, monitoring and security operations controls. 19 controls in total — 17 automatic, 2 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
SEC-01 Microsoft Secure Score
L1
Checks the overall security score Microsoft gives your environment. A low score points to security gaps.✅ 70% or higher · ⚠️ 50–69% · ❌ Below 50%Auto
N/A if data is unavailable
SEC-02 Open security alerts
L1
Checks open security alerts that have not been handled. Unhandled alerts signal an active threat.✅ None (0) · ⚠️ 1–3 · ❌ More than 3Auto
Requires Defender for Office 365 P2; N/A otherwise
SEC-03 High-priority security alerts
L1
Checks high- and critical-priority security alerts. They show priority threats are present.✅ None (0) · ❌ One or moreAuto
Requires Defender for Office 365 P2; N/A otherwise
SEC-04 Risk detections in the last 30 days
L1
Checks identity risks detected in the last 30 days. Unwatched risks signal an attack.✅ None (0) · ⚠️ 1–5 · ❌ More than 5Auto
Requires Entra ID P2; N/A otherwise
SEC-05 Failed sign-in count
L1
Checks the number of failed sign-in attempts. A high count signals a brute-force attack.✅ 20 or fewer · ⚠️ 21–50 · ❌ More than 50Auto
SEC-06 Account with repeated failed sign-ins
L2
Checks repeated failed sign-ins against the same account. It shows a sustained attack on one account.✅ 5 or fewer · ⚠️ 6–15 · ❌ More than 15Auto
SEC-07 Risk event types
L1
Checks the distinct types of risk events seen in your environment. Variety points to different attack methods.✅ None (0) · ⚠️ 1–2 · ❌ More than 2Auto
Requires Entra ID P2; N/A otherwise
SEC-08 Exposure Score
L1
Checks how exposed your environment is to threats. A high value means a wide attack surface.✅ 30 or lower · ⚠️ 31–50 · ❌ More than 50Auto
N/A if data is unavailable
SEC-09 Open security incidents
L1
Checks security incidents that have not been closed. Unhandled incidents signal an active threat.✅ None (0) · ⚠️ 1–2 · ❌ More than 2Auto
Requires Defender for Office 365 P2; N/A otherwise
SEC-10 Impossible travel detection
L1
Checks sign-ins from distant locations within a short time. It signals account takeover.✅ None (0) · ❌ One or moreAuto
Requires Entra ID P2; N/A otherwise
SEC-11 Password spray attack
L1
Checks for signs of a password spray attack. It shows an ongoing brute-force attack.✅ None (0) · ❌ One or moreAuto
Requires Entra ID P2; N/A otherwise
SEC-12 Security score decline trend
L1
Checks whether the security score dropped over the last 30 days. A drop shows your security posture is getting worse.✅ No drop (same or higher) · ❌ DroppedAuto
N/A if data is unavailable
SEC-13 MFA fraud alert
L1
Checks whether an alert is raised for unexpected MFA approval requests. These can signal an attack.✅ Alert on · ❌ OffAuto
N/A if no data
SEC-16 Zero-hour Auto Purge (ZAP)
L1
Checks whether malicious email detected after delivery is purged automatically. When off, malicious mail stays in the mailbox.✅ Enabled · ❌ OffAuto
N/A if no data
SEC-17 Alert policy notifications
L1
Checks whether notifications for security events are configured. Without them, events go unnoticed.✅ Notifications configured · ❌ Not configuredAuto
N/A if no data
SEC-18 Admin approval for quarantine release
L2
Checks whether releasing quarantined items requires admin approval. Without it, users can open malicious content themselves.✅ Admin approval required · ❌ Users can release themselvesAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
SEC-19 Phishing simulation
L1
Checks whether a phishing simulation was run in the last 12 months. Without one, user awareness goes untested.✅ Run in the last 12 months · ⚠️ Run but older than 12 months · ❌ Never runAuto
Requires Defender for Office 365 P2; N/A otherwise
SEC-20 Incident response plan test
L1
Checks whether the security incident response plan is tested at least once a year. If untested, it fails during a real incident.Attested
Customer attestation (not measured automatically)
SEC-21 Device isolation authority (Defender for Endpoint)
L2
Checks whether the authority and scope to isolate a compromised device from the network are defined. Without them, a threat spreads laterally.Attested
Customer attestation (not measured automatically)