How EchelonGraph scores compliance

Every score on this platform comes from a pure-function evaluator run against live cloud state โ€” never a questionnaire and never a self-assessment. Below is the full mapping: 129 controls across 11 frameworks, each with the exact infrastructure signal it reads and the verdict that signal produces. The platform scores 3,473 controls across 330 frameworks in total; the frameworks documented here are the ones whose control-by-control mapping we publish.

Jump to a framework

What's Inside Each Control Page

Every control in this encyclopedia goes far beyond documentation. Each page is a complete security reference designed for security engineers, compliance managers, and auditors.

Real-World Attack Scenarios

Detailed narratives of how each control has been exploited in real breaches โ€” Capital One, SolarWinds, Uber, Anthem, and more. Understand the exact attack chain so you can prioritize remediation.

Cost of Non-Compliance

Dollar-figure consequences with real case studies: GDPR fines (Amazon โ‚ฌ746M, British Airways ยฃ20M), HIPAA settlements (Anthem $16M), PCI consequences (card-brand action and forensic costs), and average breach costs per control category.

Terraform & IaC Fixes

Copy-paste Terraform code blocks for every CIS Benchmark control. Includes resource configurations for GCP, AWS, and Azure with security best practices baked in โ€” not just documentation, but deployable infrastructure.

MITRE ATT&CK Mapping

Every control maps to specific MITRE ATT&CK techniques (T1078, T1190, T1530, etc.) enabling threat-informed defense. Use these mappings to connect compliance requirements to your threat model.

Auditor Questions

The exact questions SOC 2 auditors, ISO 27001 certification bodies, PCI QSAs, and HIPAA OCR investigators will ask. Prepare evidence before the audit, not during it.

Effort Estimates

Side-by-side comparison of manual remediation effort vs. automated detection with EchelonGraph. Typical savings: 40+ hours of manual IAM review reduced to 60-second automated scan.

Control Severity Breakdown

79 critical 248 high 113 medium

Framework Coverage

FrameworkControlsCloudsKey Areas
๐Ÿ”ท CIS GCP24GCPIAM, networking, logging, storage, databases, compute, GKE, Cloud Run, KMS
๐ŸŸ  CIS AWS35AWSRoot MFA, S3 public access, CloudTrail, Security Groups, RDS, IMDSv2
๐Ÿ”ต CIS Azure10AzureAzure AD MFA, NSG rules, Blob Storage, SQL encryption, AKS RBAC
โ˜ธ๏ธ CIS Kubernetes26Kubernetes (any cloud)5.1.1 Cluster-admin, 5.1.5 Default SA tokens, 5.2.1 Privileged, 5.2.4 hostNetwork, 5.3.2 NetworkPolicy, 5.7.3 runAsNonRoot
๐Ÿ›ก๏ธ SOC 233AWS ยท GCP ยท AzureCC6.1 Access, CC6.6 Network, CC7.2 Monitoring, CC7.5 Recovery
๐Ÿ“‹ ISO 2700136AWS ยท GCP ยท AzureA.5.1 Policies, A.8.2 Privileged Access, A.8.24 Cryptography, A.8.25 Secure SDLC
๐Ÿฅ HIPAA21AWS ยท GCP ยท Azureยง164.312 Access, Encryption, Audit Controls, Authentication, Transmission Security
๐Ÿ’ณ PCI DSS27AWS ยท GCP ยท AzureCDE segmentation, Default creds, PAN encryption, TLS, MFA, Audit trails
๐Ÿ‡ช๐Ÿ‡บ GDPR23AWS ยท GCP ยท AzureArt 5 Principles, Art 25 Privacy by Design, Art 32 Security, Art 33 Breach Notification
๐Ÿ›๏ธ NIST 800-5341AWS ยท GCP ยท AzureAC-2 Accounts, AC-6 Least Privilege, CM-6 Configuration, SC-7 Boundary, SI-4 Monitoring
๐Ÿ”’ Pod Security Standards10Kubernetes (any cloud)Privileged ยท Baseline ยท Restricted profile compliance against live Pod posture flags
๐Ÿค– AI Workload Compliance9AWS ยท GCP ยท Azure ยท KubernetesNIST AI-RMF ยท EU AI Act Art 9/15/16/17 ยท ISO 42001 ยท MITRE ATLAS shadow AI detection
๐Ÿ‡ฎ๐Ÿ‡ณ DPDP Act20AllIndia's comprehensive data-protection regulation, enacted August 2023. Applies to processing of digital personal data within India + cross-border processing of data principals in India. Penalty up to โ‚น250 crore per violation. The dominant privacy regulation for the world's most populous market.
๐Ÿ‡ฐ๐Ÿ‡ท ISMS-P22AllKorea's combined information security + privacy certification managed by KISA (Korea Internet & Security Agency). Mandatory for many Korean industries; voluntary for others. Penalty: up to 3% of annual revenue (proposed amendments to 10% to align with GDPR).
๐Ÿค– NIST AI-RMF18AllNational Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI-RMF 1.0). Four functions โ€” Govern, Map, Measure, Manage โ€” providing voluntary guidance for trustworthy AI development and deployment. The de-facto reference standard cited by US federal AI Executive Order 14110 and state-level AI laws.
๐Ÿ‡ช๐Ÿ‡บ EU AI Act18AllThe world's first comprehensive AI regulation. High-risk AI system obligations under Articles 9-17 were extended by Regulation (EU) 2026/1744 (in force 27 July 2026) and now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. The Article 50 transparency obligations have applied since 2 August 2026. High-risk breaches carry penalties up to โ‚ฌ15M or 3% of global annual turnover; the โ‚ฌ35M / 7% maximum is reserved for Article 5 prohibited practices โ€” still more punitive than GDPR. Extraterritorial reach: applies to any provider, deployer, importer, or distributor whose AI output reaches the EU market.
๐Ÿ“ ISO/IEC 4200115AllThe first international management-system standard for artificial intelligence. Provides certifiable framework for organisations developing, providing, or using AI systems. Modelled on ISO/IEC 27001's structure (Clauses 4-10) so organisations with mature ISMS can extend to AI management system with familiar PDCA + continual improvement cadence.
๐ŸŽฏ MITRE ATLAS12AllMITRE ATLAS catalogues adversarial tactics, techniques, and case studies specific to AI/ML systems. The AI counterpart to MITRE ATT&CK, ATLAS provides the structured taxonomy security teams need to threat-model AI workloads. Used by NIST AI-RMF, EU AI Act guidance, and OWASP LLM Top 10 as the canonical adversarial-ML reference.
๐Ÿง  OWASP LLM Top 1012AllOWASP's specialised Top 10 for Large Language Model applications. The de-facto checklist for any product team shipping LLM-backed features. Maps to EU AI Act Article 15 cybersecurity requirements + MITRE ATLAS adversarial techniques + NIST AI-RMF MEASURE controls. Updated quarterly by the OWASP GenAI Project working group.
๐Ÿฆ… FedRAMP Moderate12AllThe FedRAMP Moderate baseline โ€” the NIST 800-53 Rev 5 control set a cloud service must meet to be authorized for U.S. federal use (the most common FedRAMP impact level). EchelonGraph live-scores the technical control set against your actual cloud posture so ConMon is continuous, not annual.
๐Ÿ›ก๏ธ CMMC 2.0 L212AllCybersecurity Maturity Model Certification 2.0 Level 2 โ€” the controls (derived from NIST SP 800-171) that U.S. defense contractors must meet to handle Controlled Unclassified Information (CUI). EchelonGraph live-scores the technical practices against your cloud posture so you enter the assessment with evidence, not spreadsheets.
๐ŸŽฏ CIS Controls v810AllThe CIS Critical Security Controls v8 โ€” 18 prioritized, prescriptive safeguards used worldwide as a pragmatic baseline (and the basis of many regulatory cross-walks). EchelonGraph live-scores the controls that map to cloud posture, so your CIS Controls program is continuously measured, not self-attested.
โš™๏ธ

How We Score Compliance

Every compliance score in EchelonGraph is derived from real infrastructure signals โ€” not questionnaires or self-assessments. Our scoring engine runs pure-function evaluators against your actual cloud state on every scan cycle. Below is the exact mapping of every control to its automated check.

๐Ÿ”งInfrastructure Check
๐Ÿ”‘IAM & Access Check
๐Ÿ“‹Procedural / Maturity
โšกCustom Logic

Scoring Formula

Score % = (Pass + Partial ร— 0.5) รท Total Controls ร— 100

Each control produces one of four verdicts: Pass (1.0), Fail (0.0), Partial (0.5), or N/A (excluded from denominator). Scores are computed independently per cloud provider.

๐Ÿ›ก๏ธ

SOC 2 Type II

17 controls ยท 7 infra checks ยท 9 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
CC1.1
Ethics & Code of Conduct
๐Ÿ“‹ MaturityOrganisational governance control
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC1.2
Board Independence
๐Ÿ“‹ MaturityOrganisational governance control
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC2.1
Security Policy Library
๐Ÿ“‹ MaturityOrganisational governance control
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC3.1
Risk Assessment
๐Ÿ”ง InfrastructureChecks total asset count > 0
Assets under scanNo cloud accounts connected
CC4.1
Continuous Monitoring
๐Ÿ”ง InfrastructureChecks total asset count > 0
Assets under scanNo cloud accounts connected
CC5.1
Network Segmentation
๐Ÿ”ง InfrastructureVPC count + firewall rule count
VPC + firewall both presentMissing VPC or firewall
CC5.2
Segregation of Duties
๐Ÿ“‹ MaturityIaC + PR review workflow
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC6.1
MFA & Authentication
๐Ÿ”‘ IAM & AccessIAM user + service account count
IAM users found โ€” verify MFANo IAM identities
CC6.2
Access Provisioning
๐Ÿ“‹ MaturityOnboarding workflow
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC6.3
Access Removal
๐Ÿ“‹ MaturityOffboarding workflow
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC6.6
Firewall Posture
๐Ÿ”ง InfrastructureScans for 0.0.0.0/0 ingress rules
No broad rulesOver-permissive rules detected
CC6.7
TLS Enforcement
๐Ÿ”ง InfrastructureLB, DB, compute TLS posture
TLS enforced across servicesTLS not verified
CC6.8
Threat Detection
๐Ÿ”ง InfrastructureGuardDuty / SCC / Defender presence
Threat detection activeNot detected
CC7.1
Audit Logging
๐Ÿ”ง InfrastructureCloudTrail / Audit Logs / Activity Log
Audit logging enabledAudit logging not verified
CC7.2
Incident Response
๐Ÿ“‹ MaturityIR runbook existence
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC8.1
Change Management
๐Ÿ“‹ MaturityCI/CD + PR review pipeline
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
CC9.1
Vendor Risk
๐Ÿ“‹ MaturityVendor risk register
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
๐Ÿ‡ช๐Ÿ‡บ

GDPR

12 controls ยท 2 infra checks ยท 9 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
Art5
Lawful Basis
๐Ÿ“‹ MaturityRecords of Processing Activities (RoPA)
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art6
Lawful Basis Mapping
๐Ÿ“‹ MaturityArticle 6 legal basis per processing activity
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art7
Consent Management
๐Ÿ“‹ MaturityConsent UI + withdrawal records
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art12
Privacy Notice
๐Ÿ“‹ MaturityPublic privacy notice + DSAR procedure
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art15
DSAR Procedure
๐Ÿ“‹ MaturitySubject access request portal, 30-day SLA
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art17
Right to Erasure
๐Ÿ“‹ MaturityCascading delete + backup retention policy
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art25
Privacy by Design
๐Ÿ”ง InfrastructureHas object_storage or managed_database with encryption
Encryption at rest verifiedNo storage resources
Art30
Records of Processing
๐Ÿ“‹ MaturityRoPA register maintained
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art32
Security of Processing
๐Ÿ”ง InfrastructureHas object_storage or managed_database with encryption
Encryption at rest verifiedNo storage resources
Art33
Breach Notification
๐Ÿ“‹ Maturity72-hour notification runbook
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art35
DPIA Template
๐Ÿ“‹ MaturityData Protection Impact Assessment template
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Art44
Cross-Border Transfers
โšก Custom LogicCloud region metadata
Region known โ€” verify adequacyRegion info unavailable
๐Ÿ›๏ธ

ISO 27001:2022

14 controls ยท 3 infra checks ยท 7 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
A5.1
Info Security Policy
๐Ÿ“‹ MaturityOrganisational governance
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A5.2
Roles & Responsibilities
๐Ÿ“‹ MaturityDocumented security roles
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A6.1
Background Checks
๐Ÿ“‹ MaturityHR security control
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A6.2
Employment Terms
๐Ÿ“‹ MaturityHR security control
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A7.1
Physical Security
๐Ÿ“‹ MaturityInherited from cloud provider attestations
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A7.2
Physical Entry Controls
๐Ÿ“‹ MaturityInherited from cloud provider attestations
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A8.1
Endpoint Management
โšก Custom Logiccompute_instance + serverless_function count
Managed compute inventoriedNo managed compute
A8.2
Privileged Access
๐Ÿ”‘ IAM & AccessIAM principal analysis for over-privilege
No broad IAMOver-privileged accountsNo IAM
A8.3
Access Restriction
๐Ÿ”‘ IAM & AccessIAM principal analysis
No broad IAMOver-privileged accountsNo IAM
A8.4
Source Code Access
๐Ÿ“‹ MaturityIdP-federated git host
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
A8.5
Secure Authentication
๐Ÿ”‘ IAM & AccessIAM user + service account count
IAM users found โ€” verify MFANo IAM identities
A8.9
Configuration Mgmt
๐Ÿ”ง InfrastructureChecks for default/unhardened firewall rules
No default rules remainDefault vendor configs detectedNo firewall rules
A8.20
Network Security
๐Ÿ”ง InfrastructureVPC + firewall rule presence
Network segmentedSegmentation gap
A8.24
Cryptography
๐Ÿ”ง InfrastructureKMS keys, encryption + TLS posture
KMS or default encryption activeManual review needed
๐Ÿฅ

HIPAA Security Rule

5 controls ยท 1 infra checks ยท 1 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
164.312(a)
ePHI Access Control
โšก Custom Logicmanaged_database behind VPC + firewall
DB isolated in VPCDB without network isolationNo databases
164.312(c)
ePHI Integrity
โšก Custom Logicmanaged_database with point-in-time recovery
Integrity controls presentNo databases
164.312(d)
Person Authentication
๐Ÿ”‘ IAM & AccessIAM user + service account count
IAM users found โ€” verify MFANo IAM identities
164.312(e)
Transmission Security
๐Ÿ”ง InfrastructureLB, DB, compute TLS enforcement
TLS enforcedTLS not verified
164.308(a)(1)
Risk Analysis
๐Ÿ“‹ MaturityAnnual ePHI risk analysis
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
๐Ÿ’ณ

PCI DSS 4.0

12 controls ยท 6 infra checks ยท 4 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
Req1
Network Segmentation
๐Ÿ”ง InfrastructureVPC + firewall rule presence
CDE segmentedSegmentation gap
Req2
Default Configs
๐Ÿ”ง InfrastructureChecks for unhardened default firewall rules
No defaults remainDefault vendor configsNo firewall rules
Req3
Stored Data Protection
๐Ÿ”ง InfrastructureStorage/DB encryption-at-rest posture
Encryption verifiedNo storage
Req4
Transit Encryption
๐Ÿ”ง InfrastructureLB, DB, compute TLS enforcement
TLS enforcedTLS not verified
Req5
Malware Protection
๐Ÿ”ง InfrastructureGuardDuty / SCC / Defender presence
ActiveNot detected
Req6
Secure Development
๐Ÿ“‹ MaturitySAST + dependency scanning pipeline
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Req7
Access Restriction
๐Ÿ”‘ IAM & AccessIAM privilege analysis
No broad IAMOver-privilegedNo IAM
Req8
Authentication
๐Ÿ”‘ IAM & AccessIAM user + service account count
Verify MFANo IAM
Req9
Physical Access
๐Ÿ“‹ MaturityInherited from cloud provider
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Req10
Audit Trails
๐Ÿ”ง InfrastructureCloudTrail / Audit Logs / Activity Log
Logging enabledLogging not verified
Req11
Vulnerability Testing
๐Ÿ“‹ MaturityQuarterly ASV + annual pen-test
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
Req12
Security Policy
๐Ÿ“‹ MaturityInformation security policy document
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
๐Ÿ›๏ธ

NIST CSF 2.0

21 controls ยท 5 infra checks ยท 11 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
GV.OC-01
Organisational Context
๐Ÿ“‹ MaturityGovernance framework
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
GV.RM-01
Risk Strategy
๐Ÿ“‹ MaturityRisk management programme
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
GV.SC-01
Supply Chain Risk
๐Ÿ“‹ MaturityThird-party risk programme
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ID.AM-01
Hardware Inventory
โšก Custom LogicTotal asset count across all types
Assets inventoriedNo assets connected
ID.AM-02
Software Inventory
โšก Custom Logiccompute + serverless + k8s count
Software platforms inventoriedNo platforms detected
ID.RA-01
Vulnerability Scanning
โšก Custom LogicTotal asset count under CVE matching
Under continuous scanNo assets to scan
ID.RA-02
Threat Intelligence
๐Ÿ“‹ MaturityNVD + MITRE ATT&CK feed subscription
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
PR.AA-01
Identity Management
๐Ÿ”‘ IAM & AccessIAM privilege analysis
No broad IAMOver-privilegedNo IAM
PR.AA-03
MFA
๐Ÿ”‘ IAM & AccessIAM user + service account count
Verify MFANo IAM
PR.DS-01
Data-at-Rest
๐Ÿ”ง InfrastructureStorage/DB encryption posture
EncryptedNo storage
PR.DS-02
Data-in-Transit
๐Ÿ”ง InfrastructureTLS enforcement across services
TLS enforcedTLS not verified
PR.PS-01
Config Management
๐Ÿ”ง InfrastructureDefault firewall rule detection
HardenedDefault configsNo rules
PR.IR-01
Incident Response Plan
๐Ÿ“‹ MaturityIR plan document
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DE.CM-01
Network Monitoring
๐Ÿ”ง InfrastructureAudit logging posture
Logging onNot verified
DE.CM-06
Activity Monitoring
๐Ÿ”ง InfrastructureAudit logging posture
Logging onNot verified
DE.AE-02
Anomaly Analysis
๐Ÿ“‹ MaturityAnomaly playbooks
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
RS.MA-01
Incident Management
๐Ÿ“‹ MaturityIncident workflow
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
RS.CO-02
Regulatory Notification
๐Ÿ“‹ MaturityNotification templates
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
RS.MI-01
Containment
๐Ÿ“‹ MaturityContainment playbooks
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
RC.RP-01
Recovery Planning
๐Ÿ“‹ MaturityBackup + restore drill cadence
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
RC.CO-01
Recovery Comms
๐Ÿ“‹ MaturityRecovery communication templates
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
๐Ÿ‡ฎ๐Ÿ‡ณ

DPDP Act (India)

10 controls ยท 0 infra checks ยท 8 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
DPDP-1
Lawful Purpose
๐Ÿ“‹ MaturityRecords of Processing Activities
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-2
Privacy Notice
๐Ÿ“‹ MaturityPublic privacy notice
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-3
Consent Management
๐Ÿ“‹ MaturityConsent platform
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-4
Data Accuracy
๐Ÿ“‹ MaturityReconciliation jobs
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-5
Data Retention
๐Ÿ“‹ MaturityLifecycle + retention policy
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-6
Security Safeguards
โšก Custom LogicEncryption-at-rest + TLS-in-transit posture
Both verifiedIncomplete safeguards
DPDP-7
Breach Response
๐Ÿ“‹ MaturityDPB notification runbook
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-8
Data Principal Rights
๐Ÿ“‹ MaturitySelf-service rights portal
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
DPDP-9
Cross-Border Transfer
โšก Custom LogicCloud region metadata
Region knownRegion unavailable
DPDP-10
Children's Data
๐Ÿ“‹ MaturityAge-gating + parental consent
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
โ˜ธ๏ธ

CIS Kubernetes Benchmark v1.9

7 controls ยท 5 infra checks ยท 0 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
CIS-K8S-5.1.1
Cluster-admin minimised
๐Ÿ”‘ IAM & AccessClusterRoleBinding subjects + non_system_subject_count attributes from live watcher
No non-system subject bound to cluster-adminBroad CRBs detectedNo K8s cluster
CIS-K8S-5.1.5
Default SA tokens not auto-mounted
๐Ÿ”‘ IAM & AccessServiceAccount.AutomountServiceAccountToken posture attribute
default SA tokens disabledDefault SAs auto-mount tokensNo K8s cluster
CIS-K8S-5.2.1
Privileged containers minimised
๐Ÿ”ง InfrastructurePod priv_count attribute (containers[].securityContext.privileged)
No privileged PodsPrivileged Pods detectedNo K8s cluster
CIS-K8S-5.2.4
hostNetwork minimised
๐Ÿ”ง InfrastructurePod host_network posture attribute
No hostNetwork PodshostNetwork Pods detectedNo K8s cluster
CIS-K8S-5.2.5
hostPID minimised
๐Ÿ”ง InfrastructurePod host_pid posture attribute
No hostPID PodshostPID Pods detectedNo K8s cluster
CIS-K8S-5.3.2
NetworkPolicy on every namespace
๐Ÿ”ง InfrastructureLive correlation of K8S_NAMESPACE ร— K8S_NETWORKPOLICY assets
Every namespace coveredNamespaces without NetPol detectedNo K8s cluster
CIS-K8S-5.7.3
runAsNonRoot enforced
๐Ÿ”ง InfrastructurePod runasnonroot_count vs container_count posture
runAsNonRoot on every containerContainers running as rootNo K8s cluster
๐Ÿ”’

Pod Security Standards

3 controls ยท 0 infra checks ยท 0 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
PSS-Privileged
Privileged tier
โšก Custom LogicAlways informational โ€” unrestricted policy in effect
Privileged tier acknowledged (low severity)No K8s cluster
PSS-Baseline
Baseline tier
โšก Custom LogicAggregate priv_count + host_network + host_pid violations
Baseline policies satisfiedBaseline violations: priv/hostNet/hostPIDNo K8s cluster
PSS-Restricted
Restricted tier
โšก Custom LogicAggregate Baseline checks + runasnonroot + default-SA automount
Restricted policies satisfiedRestricted violations detectedNo K8s cluster
๐Ÿค–

AI Workload Compliance

12 controls ยท 1 infra checks ยท 3 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
AIRMF-MAP-1.1
AI System Inventory
โšก Custom LogicLive CRD watch on KServe / Kubeflow / Argo / Ray / Seldon / Run:ai
AI workloads inventoriedNo AI/ML workloads detected
AIRMF-MEASURE-2.7
AI Continuous Monitoring
โšก Custom LogicSame inventory signal + notify-webhook re-scoring (30s SLA per pass)
Continuous monitoring activeNo AI/ML workloads detected
AIRMF-MANAGE-1.4
AI Cybersecurity Controls
โšก Custom LogicStrict-ZK Secret inventory + customer-managed encryption posture
Strict-ZK Secret scan + BYOK activeNo K8s cluster
AIRMF-GOVERN-1.4
AI Acceptable Use Policy
๐Ÿ“‹ MaturityAI usage policy + guardrails (organisational)
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
EU-AIACT-ART9
AI Risk Management
โšก Custom LogicLive AI workload inventory + risk classification
AI risk-mgmt evidence capturedNo AI/ML workloads detected
EU-AIACT-ART15
AI Cybersecurity Resilience
โšก Custom LogicStrict-ZK Secret inventory + secret rotation evidence
Cybersecurity controls verifiedNo K8s cluster
EU-AIACT-ART15
AI Access Control
๐Ÿ”‘ IAM & AccessK8s broad-CRB detection scoped to AI namespaces
Least-privilege RBAC verifiedBroad CRBs on AI namespaceNo K8s cluster
EU-AIACT-ART12
AI Audit Logging
๐Ÿ”ง InfrastructureCloud audit-log presence on AI workload's host cloud
Audit logging enabledAudit logging gapsNo AI workloads or no cloud audit_log asset
ISO42001-7.4
AI Management System Documentation
๐Ÿ“‹ MaturityDocumented AI management system per ISO/IEC 42001:2023
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISO42001-8.2
AI Workload RBAC
๐Ÿ”‘ IAM & AccessSame K8s broad-RBAC signal โ€” adds ISO 42001 framework dimension
Least-privilege RBACBroad CRBsNo K8s cluster
ISO42001-8.4
AI Image Registry Policy
๐Ÿ“‹ MaturityAI workload container images sourced from approved registries
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
MITRE-ATLAS-AML.T0011
Shadow AI Detection
โšก Custom LogicLive CRD watch flags unauthorised KServe / Kubeflow / Ray / Seldon CRDs
AI workloads detected and auditedNo AI/ML workloads detected
๐Ÿ‡ฐ๐Ÿ‡ท

ISMS-P (Korea)

16 controls ยท 2 infra checks ยท 11 maturity-based
ControlWhat It ChecksInfrastructure SignalVerdict Logic
ISMS-1.1
ISMS Scope & Policy
๐Ÿ“‹ MaturityISMS scope definition
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-1.2
Risk Assessment
๐Ÿ“‹ MaturityAnnual risk assessment
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.1
Security Policy
๐Ÿ“‹ MaturityInformation security policy
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.2
Security Org
๐Ÿ“‹ MaturitySecurity organisation chart
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.3
HR Security
๐Ÿ“‹ MaturityBackground checks + training
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.4
Asset Management
โšก Custom LogicTotal asset count + type diversity
Assets classifiedNo assets identified
ISMS-2.5
Access Control
๐Ÿ”‘ IAM & AccessIAM user + service account count
Verify MFANo IAM
ISMS-2.6
Cryptography
๐Ÿ”ง InfrastructureKMS, encryption, TLS posture
Crypto controls activeManual review needed
ISMS-2.7
Physical Security
๐Ÿ“‹ MaturityInherited from cloud provider
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.8
Operations
๐Ÿ“‹ MaturityOperations runbooks
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-2.9
Network Security
๐Ÿ”ง InfrastructureVPC + firewall rule presence
SegmentedGap detected
ISMS-2.10
Secure SDLC
๐Ÿ“‹ MaturitySecure development lifecycle
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-P.1
PI Protection Policy
๐Ÿ“‹ MaturityPersonal information protection
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-P.2
Consent Mgmt
๐Ÿ“‹ MaturityConsent platform
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-P.3
Data Lifecycle
๐Ÿ“‹ MaturityRetention + disposal
โ‰ฅ50 assets + โ‰ฅ6 types<50 assets or <6 types0 assets
ISMS-P.4
Cross-Border Transfer
โšก Custom LogicCloud region metadata
Region knownRegion unavailable

๐Ÿ“‹ How Procedural / Maturity Scoring Works

Organisational controls (code of conduct, incident response, consent management) cannot be fully validated by infrastructure scans alone. Instead, we use your cloud infrastructure footprint as a maturity proxy:

N/A
0 assets
No cloud infrastructure to evaluate
Partial
< 50 assets or < 6 types
Early-stage infrastructure, document processes manually
Pass
โ‰ฅ 50 assets + โ‰ฅ 6 types
Production-grade deployment implies mature processes

Looking for which frameworks apply to you rather than how they are scored?

โ† Back to the compliance encyclopedia