The 494 controls explained: CIS, ANSSI, NIST and ISO 27001
A security control only means something when it is tied to a recognised framework. The two GUARD tools run 494 automated controls — across Entra ID & Microsoft 365 and Active Directory — each mapped to established standards. Here is what that coverage looks like and why it matters.
Why framework alignment matters
Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer or an ISO assessor — is that every control traces back to an authoritative source. The two GUARD tools align their controls with recognised public frameworks so that each finding carries a reference you can justify, whether it concerns a Conditional Access policy or an Active Directory delegation.
494 controls across two referentials
The catalogue is not one list but two, each built for the perimeter it audits.
| Referential | Controls | What it covers |
|---|---|---|
| Entra ID & Microsoft 365 | 318 | Eight sources: Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, Intune |
| Active Directory | 176 | Thirty-two categories: privileged accounts, Kerberos, ACL delegation, trusts, AD CS, GPOs, LAPS, attack paths |
Splitting them is deliberate. A domain controller and a storage account do not fail in the same way, and pretending one checklist covers both produces controls that are true of nothing in particular.
The frameworks behind the controls
CIS Benchmarks
The Center for Internet Security publishes consensus-based hardening benchmarks — CIS Microsoft 365 Foundations and CIS Microsoft Windows Server. They are prescriptive and practical: exact settings, recommended values, and level 1 (essential) versus level 2 (defence-in-depth) tiers. They form the backbone of the catalogue.
ANSSI recommendations
The French national cybersecurity agency publishes hardening guides that are especially strong on identity and on Active Directory. They inform the identity controls of both tools, and they supply the five-tier maturity model used on Active Directory.
NIST SP 800-53 and ISO/IEC 27001
NIST's control families give the structure that maps a technical finding to a governance category — useful when reporting to risk and compliance functions. ISO 27001 Annex A does the same for organisations pursuing or maintaining certification, by putting concrete technical evidence behind an ISMS clause.
Microsoft Cloud Security Benchmark
Microsoft's own cloud security framework, organised by domain — network security, data protection, privileged access, identity management, logging and detection, backup and recovery. It is the framework a client already aligned with Defender for Cloud will recognise immediately.
MITRE ATT&CK
The other frameworks answer “which requirement does this control satisfy?”. MITRE answers a different question: which attack technique does this control take away? Every Active Directory control carries that mapping — which is what lets an audit finding speak to a SOC team.
CISA SCuBA, NIS2 and DORA
SCuBA supplies the US agency baselines for Microsoft 365. NIS2 and DORA are not technical frameworks but regulatory ones: the mapping exists so that a finding can be attached directly to an article 21 measure or an ICT risk requirement.
One control, several frameworks
A single control usually answers several frameworks at once — that is the whole point of the mapping. Removing an unconstrained delegation satisfies an ANSSI recommendation, a NIST access-control measure, an ISO 27001 Annex A clause, a NIS2 measure and a DORA article, and it removes MITRE technique T1558. You check it once; it reports in five languages.
Every finding is traceable
Each control in a report cites its framework references and a link to the Microsoft documentation, plus the PowerShell command that verifies it. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters, where the recommendation comes from, and how the client can confirm it themselves.
Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee, on both perimeters rather than only on the cloud one.