← Support

Control Frameworks

Veri-Guard assesses your Microsoft 365 tenant against 582 security controls sourced from 14 independent frameworks across 8 domains.

582

Total Controls

361

Auto-Remediable

8

Assessment Domains

Framework Visual Guide

View all 14 frameworks with color-coded badges, score grids, and comparison cards

Official / Regulatory

619 controls

Community-Based

177 controls

Veri-Tech Recommendations

44 controls

How framework mapping works: Each security control in the Veri-Guard registry is sourced from one primary detection framework (e.g., CISA, CIS, EIDSCA) and cross-referenced to compliance standards (NIST 800-53, NIST CSF, ISO 27001, SOC 2, HIPAA, GDPR). Every cross-framework mapping is sourced from authoritative public data — official NIST crosswalks, CISA CSVs, and AICPA mappings. A single control may satisfy requirements from multiple frameworks simultaneously.

This multi-framework approach means one assessment run provides compliance evidence across all twelve mapped standards — no need to run separate audits for each framework.

Framework Sources

CISA SCuBA M365 Security Configuration Baselines
Official / Regulatory

U.S. federal security baselines for Microsoft 365, developed by CISA as part of the Secure Cloud Business Applications (SCuBA) project.

108 controlsOfficial docs
CIS Microsoft 365 Foundations Benchmarks
Official / Regulatory

Industry-consensus security configuration benchmarks from the Center for Internet Security.

154 controlsOfficial docs
Entra ID Security Config Analyzer
Official / Regulatory

Microsoft Entra ID security configuration checks maintained by the identity security community with Microsoft endorsement.

50 controlsOfficial docs
NIST SP 800-53 Rev 5
Official / Regulatory

U.S. federal security and privacy controls catalog. Includes both NIST-prefixed detection controls and cross-framework tags on all controls.

35 controlsOfficial docs
Maester Community Tests
Community-Based

Community-maintained Pester tests for Microsoft 365 security, contributed by the open-source Maester project.

109 controlsOfficial docs
ORCA (Office 365 ATP Recommended Configuration Analyzer)
Community-Based

Community-developed checks for Defender for Office 365 configuration, originally created by Cam Murray.

68 controlsOfficial docs
Veri-Tech Recommended Controls
Veri-Tech Recommendations

Recommended controls developed by Veri-Tech to fill compliance and operational hygiene gaps not addressed by other frameworks.

44 controls
NIST Cybersecurity Framework
Official / Regulatory

Risk-based cybersecurity framework organized by Identify, Protect, Detect, Respond, and Recover functions. Mapped via official NIST CSF-to-800-53 crosswalk.

106 requirementsOfficial docs
ISO/IEC 27001:2022
Official / Regulatory

International information security management standard with 93 Annex A controls. Mapped via the official NIST OLIR 800-53-to-ISO 27001 crosswalk.

91 requirementsOfficial docs
SOC 2 Trust Services Criteria
Official / Regulatory

AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy. Mapped via the official AICPA TSC-to-NIST 800-53 crosswalk.

49 requirementsOfficial docs
EU General Data Protection Regulation
Official / Regulatory

GDPR-supportive controls mapped via the ISO 27001 Annex A to GDPR article bridge (ISO 27701).

12 requirementsOfficial docs
HHS 405(d) Health Industry Cybersecurity Practices (HICP, 2023 Edition)
Official / Regulatory

HHS-published voluntary cybersecurity practices for the healthcare sector under §405(d) of the Cybersecurity Act of 2015. Implementation can support HITECH safe-harbor benefit (PL 116-321). Mapped from HICP Technical Volumes 1 and 2 sub-practices to M365-observable controls.

0 requirementsOfficial docs
Microsoft 365 Copilot Pre-Deployment Readiness
Veri-Tech Recommendations

Veri-Tech curated readiness lens. Grades a tenant against the data-protection prerequisites Microsoft documents in the Copilot setup guide and the Secure and Governed Data Foundation deployment blueprint. Subset of existing Veri-Guard controls plus Copilot-specific items.

0 requirements
HIPAA Security Rule
Official / Regulatory

U.S. healthcare security standard (45 CFR 164 Subpart C) protecting electronic Protected Health Information. Assessed via the dedicated HIPAA scanner.

14 controlsOfficial docs