SEC — Security Operations
Audit, monitoring and security operations controls. 19 controls in total — 17 automatic, 2 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
SEC-01 Microsoft Secure Score L1 | Checks the overall security score Microsoft gives your environment. A low score points to security gaps. | ✅ 70% or higher · ⚠️ 50–69% · ❌ Below 50% | Auto N/A if data is unavailable |
SEC-02 Open security alerts L1 | Checks open security alerts that have not been handled. Unhandled alerts signal an active threat. | ✅ None (0) · ⚠️ 1–3 · ❌ More than 3 | Auto Requires Defender for Office 365 P2; N/A otherwise |
SEC-03 High-priority security alerts L1 | Checks high- and critical-priority security alerts. They show priority threats are present. | ✅ None (0) · ❌ One or more | Auto Requires Defender for Office 365 P2; N/A otherwise |
SEC-04 Risk detections in the last 30 days L1 | Checks identity risks detected in the last 30 days. Unwatched risks signal an attack. | ✅ None (0) · ⚠️ 1–5 · ❌ More than 5 | Auto Requires Entra ID P2; N/A otherwise |
SEC-05 Failed sign-in count L1 | Checks the number of failed sign-in attempts. A high count signals a brute-force attack. | ✅ 20 or fewer · ⚠️ 21–50 · ❌ More than 50 | Auto |
SEC-06 Account with repeated failed sign-ins L2 | Checks repeated failed sign-ins against the same account. It shows a sustained attack on one account. | ✅ 5 or fewer · ⚠️ 6–15 · ❌ More than 15 | Auto |
SEC-07 Risk event types L1 | Checks the distinct types of risk events seen in your environment. Variety points to different attack methods. | ✅ None (0) · ⚠️ 1–2 · ❌ More than 2 | Auto Requires Entra ID P2; N/A otherwise |
SEC-08 Exposure Score L1 | Checks how exposed your environment is to threats. A high value means a wide attack surface. | ✅ 30 or lower · ⚠️ 31–50 · ❌ More than 50 | Auto N/A if data is unavailable |
SEC-09 Open security incidents L1 | Checks security incidents that have not been closed. Unhandled incidents signal an active threat. | ✅ None (0) · ⚠️ 1–2 · ❌ More than 2 | Auto Requires Defender for Office 365 P2; N/A otherwise |
SEC-10 Impossible travel detection L1 | Checks sign-ins from distant locations within a short time. It signals account takeover. | ✅ None (0) · ❌ One or more | Auto Requires Entra ID P2; N/A otherwise |
SEC-11 Password spray attack L1 | Checks for signs of a password spray attack. It shows an ongoing brute-force attack. | ✅ None (0) · ❌ One or more | Auto Requires Entra ID P2; N/A otherwise |
SEC-12 Security score decline trend L1 | Checks whether the security score dropped over the last 30 days. A drop shows your security posture is getting worse. | ✅ No drop (same or higher) · ❌ Dropped | Auto N/A if data is unavailable |
SEC-13 MFA fraud alert L1 | Checks whether an alert is raised for unexpected MFA approval requests. These can signal an attack. | ✅ Alert on · ❌ Off | Auto N/A if no data |
SEC-16 Zero-hour Auto Purge (ZAP) L1 | Checks whether malicious email detected after delivery is purged automatically. When off, malicious mail stays in the mailbox. | ✅ Enabled · ❌ Off | Auto N/A if no data |
SEC-17 Alert policy notifications L1 | Checks whether notifications for security events are configured. Without them, events go unnoticed. | ✅ Notifications configured · ❌ Not configured | Auto N/A if no data |
SEC-18 Admin approval for quarantine release L2 | Checks whether releasing quarantined items requires admin approval. Without it, users can open malicious content themselves. | ✅ Admin approval required · ❌ Users can release themselves | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
SEC-19 Phishing simulation L1 | Checks whether a phishing simulation was run in the last 12 months. Without one, user awareness goes untested. | ✅ Run in the last 12 months · ⚠️ Run but older than 12 months · ❌ Never run | Auto Requires Defender for Office 365 P2; N/A otherwise |
SEC-20 Incident response plan test L1 | Checks whether the security incident response plan is tested at least once a year. If untested, it fails during a real incident. | Attested Customer attestation (not measured automatically) | |
SEC-21 Device isolation authority (Defender for Endpoint) L2 | Checks whether the authority and scope to isolate a compromised device from the network are defined. Without them, a threat spreads laterally. | Attested Customer attestation (not measured automatically) |