How EchelonGraph scores compliance
Every score on this platform comes from a pure-function evaluator run against live cloud state โ never a questionnaire and never a self-assessment. Below is the full mapping: 129 controls across 11 frameworks, each with the exact infrastructure signal it reads and the verdict that signal produces. The platform scores 3,473 controls across 330 frameworks in total; the frameworks documented here are the ones whose control-by-control mapping we publish.
What's Inside Each Control Page
Every control in this encyclopedia goes far beyond documentation. Each page is a complete security reference designed for security engineers, compliance managers, and auditors.
Real-World Attack Scenarios
Detailed narratives of how each control has been exploited in real breaches โ Capital One, SolarWinds, Uber, Anthem, and more. Understand the exact attack chain so you can prioritize remediation.
Cost of Non-Compliance
Dollar-figure consequences with real case studies: GDPR fines (Amazon โฌ746M, British Airways ยฃ20M), HIPAA settlements (Anthem $16M), PCI consequences (card-brand action and forensic costs), and average breach costs per control category.
Terraform & IaC Fixes
Copy-paste Terraform code blocks for every CIS Benchmark control. Includes resource configurations for GCP, AWS, and Azure with security best practices baked in โ not just documentation, but deployable infrastructure.
MITRE ATT&CK Mapping
Every control maps to specific MITRE ATT&CK techniques (T1078, T1190, T1530, etc.) enabling threat-informed defense. Use these mappings to connect compliance requirements to your threat model.
Auditor Questions
The exact questions SOC 2 auditors, ISO 27001 certification bodies, PCI QSAs, and HIPAA OCR investigators will ask. Prepare evidence before the audit, not during it.
Effort Estimates
Side-by-side comparison of manual remediation effort vs. automated detection with EchelonGraph. Typical savings: 40+ hours of manual IAM review reduced to 60-second automated scan.
Control Severity Breakdown
Framework Coverage
| Framework | Controls | Clouds | Key Areas |
|---|---|---|---|
| ๐ท CIS GCP | 24 | GCP | IAM, networking, logging, storage, databases, compute, GKE, Cloud Run, KMS |
| ๐ CIS AWS | 35 | AWS | Root MFA, S3 public access, CloudTrail, Security Groups, RDS, IMDSv2 |
| ๐ต CIS Azure | 10 | Azure | Azure AD MFA, NSG rules, Blob Storage, SQL encryption, AKS RBAC |
| โธ๏ธ CIS Kubernetes | 26 | Kubernetes (any cloud) | 5.1.1 Cluster-admin, 5.1.5 Default SA tokens, 5.2.1 Privileged, 5.2.4 hostNetwork, 5.3.2 NetworkPolicy, 5.7.3 runAsNonRoot |
| ๐ก๏ธ SOC 2 | 33 | AWS ยท GCP ยท Azure | CC6.1 Access, CC6.6 Network, CC7.2 Monitoring, CC7.5 Recovery |
| ๐ ISO 27001 | 36 | AWS ยท GCP ยท Azure | A.5.1 Policies, A.8.2 Privileged Access, A.8.24 Cryptography, A.8.25 Secure SDLC |
| ๐ฅ HIPAA | 21 | AWS ยท GCP ยท Azure | ยง164.312 Access, Encryption, Audit Controls, Authentication, Transmission Security |
| ๐ณ PCI DSS | 27 | AWS ยท GCP ยท Azure | CDE segmentation, Default creds, PAN encryption, TLS, MFA, Audit trails |
| ๐ช๐บ GDPR | 23 | AWS ยท GCP ยท Azure | Art 5 Principles, Art 25 Privacy by Design, Art 32 Security, Art 33 Breach Notification |
| ๐๏ธ NIST 800-53 | 41 | AWS ยท GCP ยท Azure | AC-2 Accounts, AC-6 Least Privilege, CM-6 Configuration, SC-7 Boundary, SI-4 Monitoring |
| ๐ Pod Security Standards | 10 | Kubernetes (any cloud) | Privileged ยท Baseline ยท Restricted profile compliance against live Pod posture flags |
| ๐ค AI Workload Compliance | 9 | AWS ยท GCP ยท Azure ยท Kubernetes | NIST AI-RMF ยท EU AI Act Art 9/15/16/17 ยท ISO 42001 ยท MITRE ATLAS shadow AI detection |
| ๐ฎ๐ณ DPDP Act | 20 | All | India's comprehensive data-protection regulation, enacted August 2023. Applies to processing of digital personal data within India + cross-border processing of data principals in India. Penalty up to โน250 crore per violation. The dominant privacy regulation for the world's most populous market. |
| ๐ฐ๐ท ISMS-P | 22 | All | Korea's combined information security + privacy certification managed by KISA (Korea Internet & Security Agency). Mandatory for many Korean industries; voluntary for others. Penalty: up to 3% of annual revenue (proposed amendments to 10% to align with GDPR). |
| ๐ค NIST AI-RMF | 18 | All | National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI-RMF 1.0). Four functions โ Govern, Map, Measure, Manage โ providing voluntary guidance for trustworthy AI development and deployment. The de-facto reference standard cited by US federal AI Executive Order 14110 and state-level AI laws. |
| ๐ช๐บ EU AI Act | 18 | All | The world's first comprehensive AI regulation. High-risk AI system obligations under Articles 9-17 were extended by Regulation (EU) 2026/1744 (in force 27 July 2026) and now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. The Article 50 transparency obligations have applied since 2 August 2026. High-risk breaches carry penalties up to โฌ15M or 3% of global annual turnover; the โฌ35M / 7% maximum is reserved for Article 5 prohibited practices โ still more punitive than GDPR. Extraterritorial reach: applies to any provider, deployer, importer, or distributor whose AI output reaches the EU market. |
| ๐ ISO/IEC 42001 | 15 | All | The first international management-system standard for artificial intelligence. Provides certifiable framework for organisations developing, providing, or using AI systems. Modelled on ISO/IEC 27001's structure (Clauses 4-10) so organisations with mature ISMS can extend to AI management system with familiar PDCA + continual improvement cadence. |
| ๐ฏ MITRE ATLAS | 12 | All | MITRE ATLAS catalogues adversarial tactics, techniques, and case studies specific to AI/ML systems. The AI counterpart to MITRE ATT&CK, ATLAS provides the structured taxonomy security teams need to threat-model AI workloads. Used by NIST AI-RMF, EU AI Act guidance, and OWASP LLM Top 10 as the canonical adversarial-ML reference. |
| ๐ง OWASP LLM Top 10 | 12 | All | OWASP's specialised Top 10 for Large Language Model applications. The de-facto checklist for any product team shipping LLM-backed features. Maps to EU AI Act Article 15 cybersecurity requirements + MITRE ATLAS adversarial techniques + NIST AI-RMF MEASURE controls. Updated quarterly by the OWASP GenAI Project working group. |
| ๐ฆ FedRAMP Moderate | 12 | All | The FedRAMP Moderate baseline โ the NIST 800-53 Rev 5 control set a cloud service must meet to be authorized for U.S. federal use (the most common FedRAMP impact level). EchelonGraph live-scores the technical control set against your actual cloud posture so ConMon is continuous, not annual. |
| ๐ก๏ธ CMMC 2.0 L2 | 12 | All | Cybersecurity Maturity Model Certification 2.0 Level 2 โ the controls (derived from NIST SP 800-171) that U.S. defense contractors must meet to handle Controlled Unclassified Information (CUI). EchelonGraph live-scores the technical practices against your cloud posture so you enter the assessment with evidence, not spreadsheets. |
| ๐ฏ CIS Controls v8 | 10 | All | The CIS Critical Security Controls v8 โ 18 prioritized, prescriptive safeguards used worldwide as a pragmatic baseline (and the basis of many regulatory cross-walks). EchelonGraph live-scores the controls that map to cloud posture, so your CIS Controls program is continuously measured, not self-attested. |
How We Score Compliance
Every compliance score in EchelonGraph is derived from real infrastructure signals โ not questionnaires or self-assessments. Our scoring engine runs pure-function evaluators against your actual cloud state on every scan cycle. Below is the exact mapping of every control to its automated check.
Scoring Formula
Score % = (Pass + Partial ร 0.5) รท Total Controls ร 100Each control produces one of four verdicts: Pass (1.0), Fail (0.0), Partial (0.5), or N/A (excluded from denominator). Scores are computed independently per cloud provider.
SOC 2 Type II
17 controls ยท 7 infra checks ยท 9 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| CC1.1 Ethics & Code of Conduct | ๐ Maturity | Organisational governance control | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC1.2 Board Independence | ๐ Maturity | Organisational governance control | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC2.1 Security Policy Library | ๐ Maturity | Organisational governance control | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC3.1 Risk Assessment | ๐ง Infrastructure | Checks total asset count > 0 | Assets under scanNo cloud accounts connected |
| CC4.1 Continuous Monitoring | ๐ง Infrastructure | Checks total asset count > 0 | Assets under scanNo cloud accounts connected |
| CC5.1 Network Segmentation | ๐ง Infrastructure | VPC count + firewall rule count | VPC + firewall both presentMissing VPC or firewall |
| CC5.2 Segregation of Duties | ๐ Maturity | IaC + PR review workflow | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC6.1 MFA & Authentication | ๐ IAM & Access | IAM user + service account count | IAM users found โ verify MFANo IAM identities |
| CC6.2 Access Provisioning | ๐ Maturity | Onboarding workflow | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC6.3 Access Removal | ๐ Maturity | Offboarding workflow | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC6.6 Firewall Posture | ๐ง Infrastructure | Scans for 0.0.0.0/0 ingress rules | No broad rulesOver-permissive rules detected |
| CC6.7 TLS Enforcement | ๐ง Infrastructure | LB, DB, compute TLS posture | TLS enforced across servicesTLS not verified |
| CC6.8 Threat Detection | ๐ง Infrastructure | GuardDuty / SCC / Defender presence | Threat detection activeNot detected |
| CC7.1 Audit Logging | ๐ง Infrastructure | CloudTrail / Audit Logs / Activity Log | Audit logging enabledAudit logging not verified |
| CC7.2 Incident Response | ๐ Maturity | IR runbook existence | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC8.1 Change Management | ๐ Maturity | CI/CD + PR review pipeline | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| CC9.1 Vendor Risk | ๐ Maturity | Vendor risk register | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
GDPR
12 controls ยท 2 infra checks ยท 9 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| Art5 Lawful Basis | ๐ Maturity | Records of Processing Activities (RoPA) | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art6 Lawful Basis Mapping | ๐ Maturity | Article 6 legal basis per processing activity | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art7 Consent Management | ๐ Maturity | Consent UI + withdrawal records | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art12 Privacy Notice | ๐ Maturity | Public privacy notice + DSAR procedure | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art15 DSAR Procedure | ๐ Maturity | Subject access request portal, 30-day SLA | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art17 Right to Erasure | ๐ Maturity | Cascading delete + backup retention policy | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art25 Privacy by Design | ๐ง Infrastructure | Has object_storage or managed_database with encryption | Encryption at rest verifiedNo storage resources |
| Art30 Records of Processing | ๐ Maturity | RoPA register maintained | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art32 Security of Processing | ๐ง Infrastructure | Has object_storage or managed_database with encryption | Encryption at rest verifiedNo storage resources |
| Art33 Breach Notification | ๐ Maturity | 72-hour notification runbook | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art35 DPIA Template | ๐ Maturity | Data Protection Impact Assessment template | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Art44 Cross-Border Transfers | โก Custom Logic | Cloud region metadata | Region known โ verify adequacyRegion info unavailable |
ISO 27001:2022
14 controls ยท 3 infra checks ยท 7 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| A5.1 Info Security Policy | ๐ Maturity | Organisational governance | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A5.2 Roles & Responsibilities | ๐ Maturity | Documented security roles | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A6.1 Background Checks | ๐ Maturity | HR security control | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A6.2 Employment Terms | ๐ Maturity | HR security control | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A7.1 Physical Security | ๐ Maturity | Inherited from cloud provider attestations | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A7.2 Physical Entry Controls | ๐ Maturity | Inherited from cloud provider attestations | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A8.1 Endpoint Management | โก Custom Logic | compute_instance + serverless_function count | Managed compute inventoriedNo managed compute |
| A8.2 Privileged Access | ๐ IAM & Access | IAM principal analysis for over-privilege | No broad IAMOver-privileged accountsNo IAM |
| A8.3 Access Restriction | ๐ IAM & Access | IAM principal analysis | No broad IAMOver-privileged accountsNo IAM |
| A8.4 Source Code Access | ๐ Maturity | IdP-federated git host | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| A8.5 Secure Authentication | ๐ IAM & Access | IAM user + service account count | IAM users found โ verify MFANo IAM identities |
| A8.9 Configuration Mgmt | ๐ง Infrastructure | Checks for default/unhardened firewall rules | No default rules remainDefault vendor configs detectedNo firewall rules |
| A8.20 Network Security | ๐ง Infrastructure | VPC + firewall rule presence | Network segmentedSegmentation gap |
| A8.24 Cryptography | ๐ง Infrastructure | KMS keys, encryption + TLS posture | KMS or default encryption activeManual review needed |
HIPAA Security Rule
5 controls ยท 1 infra checks ยท 1 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| 164.312(a) ePHI Access Control | โก Custom Logic | managed_database behind VPC + firewall | DB isolated in VPCDB without network isolationNo databases |
| 164.312(c) ePHI Integrity | โก Custom Logic | managed_database with point-in-time recovery | Integrity controls presentNo databases |
| 164.312(d) Person Authentication | ๐ IAM & Access | IAM user + service account count | IAM users found โ verify MFANo IAM identities |
| 164.312(e) Transmission Security | ๐ง Infrastructure | LB, DB, compute TLS enforcement | TLS enforcedTLS not verified |
| 164.308(a)(1) Risk Analysis | ๐ Maturity | Annual ePHI risk analysis | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
PCI DSS 4.0
12 controls ยท 6 infra checks ยท 4 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| Req1 Network Segmentation | ๐ง Infrastructure | VPC + firewall rule presence | CDE segmentedSegmentation gap |
| Req2 Default Configs | ๐ง Infrastructure | Checks for unhardened default firewall rules | No defaults remainDefault vendor configsNo firewall rules |
| Req3 Stored Data Protection | ๐ง Infrastructure | Storage/DB encryption-at-rest posture | Encryption verifiedNo storage |
| Req4 Transit Encryption | ๐ง Infrastructure | LB, DB, compute TLS enforcement | TLS enforcedTLS not verified |
| Req5 Malware Protection | ๐ง Infrastructure | GuardDuty / SCC / Defender presence | ActiveNot detected |
| Req6 Secure Development | ๐ Maturity | SAST + dependency scanning pipeline | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Req7 Access Restriction | ๐ IAM & Access | IAM privilege analysis | No broad IAMOver-privilegedNo IAM |
| Req8 Authentication | ๐ IAM & Access | IAM user + service account count | Verify MFANo IAM |
| Req9 Physical Access | ๐ Maturity | Inherited from cloud provider | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Req10 Audit Trails | ๐ง Infrastructure | CloudTrail / Audit Logs / Activity Log | Logging enabledLogging not verified |
| Req11 Vulnerability Testing | ๐ Maturity | Quarterly ASV + annual pen-test | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| Req12 Security Policy | ๐ Maturity | Information security policy document | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
NIST CSF 2.0
21 controls ยท 5 infra checks ยท 11 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| GV.OC-01 Organisational Context | ๐ Maturity | Governance framework | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| GV.RM-01 Risk Strategy | ๐ Maturity | Risk management programme | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| GV.SC-01 Supply Chain Risk | ๐ Maturity | Third-party risk programme | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ID.AM-01 Hardware Inventory | โก Custom Logic | Total asset count across all types | Assets inventoriedNo assets connected |
| ID.AM-02 Software Inventory | โก Custom Logic | compute + serverless + k8s count | Software platforms inventoriedNo platforms detected |
| ID.RA-01 Vulnerability Scanning | โก Custom Logic | Total asset count under CVE matching | Under continuous scanNo assets to scan |
| ID.RA-02 Threat Intelligence | ๐ Maturity | NVD + MITRE ATT&CK feed subscription | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| PR.AA-01 Identity Management | ๐ IAM & Access | IAM privilege analysis | No broad IAMOver-privilegedNo IAM |
| PR.AA-03 MFA | ๐ IAM & Access | IAM user + service account count | Verify MFANo IAM |
| PR.DS-01 Data-at-Rest | ๐ง Infrastructure | Storage/DB encryption posture | EncryptedNo storage |
| PR.DS-02 Data-in-Transit | ๐ง Infrastructure | TLS enforcement across services | TLS enforcedTLS not verified |
| PR.PS-01 Config Management | ๐ง Infrastructure | Default firewall rule detection | HardenedDefault configsNo rules |
| PR.IR-01 Incident Response Plan | ๐ Maturity | IR plan document | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DE.CM-01 Network Monitoring | ๐ง Infrastructure | Audit logging posture | Logging onNot verified |
| DE.CM-06 Activity Monitoring | ๐ง Infrastructure | Audit logging posture | Logging onNot verified |
| DE.AE-02 Anomaly Analysis | ๐ Maturity | Anomaly playbooks | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| RS.MA-01 Incident Management | ๐ Maturity | Incident workflow | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| RS.CO-02 Regulatory Notification | ๐ Maturity | Notification templates | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| RS.MI-01 Containment | ๐ Maturity | Containment playbooks | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| RC.RP-01 Recovery Planning | ๐ Maturity | Backup + restore drill cadence | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| RC.CO-01 Recovery Comms | ๐ Maturity | Recovery communication templates | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
DPDP Act (India)
10 controls ยท 0 infra checks ยท 8 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| DPDP-1 Lawful Purpose | ๐ Maturity | Records of Processing Activities | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-2 Privacy Notice | ๐ Maturity | Public privacy notice | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-3 Consent Management | ๐ Maturity | Consent platform | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-4 Data Accuracy | ๐ Maturity | Reconciliation jobs | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-5 Data Retention | ๐ Maturity | Lifecycle + retention policy | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-6 Security Safeguards | โก Custom Logic | Encryption-at-rest + TLS-in-transit posture | Both verifiedIncomplete safeguards |
| DPDP-7 Breach Response | ๐ Maturity | DPB notification runbook | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-8 Data Principal Rights | ๐ Maturity | Self-service rights portal | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| DPDP-9 Cross-Border Transfer | โก Custom Logic | Cloud region metadata | Region knownRegion unavailable |
| DPDP-10 Children's Data | ๐ Maturity | Age-gating + parental consent | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
CIS Kubernetes Benchmark v1.9
7 controls ยท 5 infra checks ยท 0 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| CIS-K8S-5.1.1 Cluster-admin minimised | ๐ IAM & Access | ClusterRoleBinding subjects + non_system_subject_count attributes from live watcher | No non-system subject bound to cluster-adminBroad CRBs detectedNo K8s cluster |
| CIS-K8S-5.1.5 Default SA tokens not auto-mounted | ๐ IAM & Access | ServiceAccount.AutomountServiceAccountToken posture attribute | default SA tokens disabledDefault SAs auto-mount tokensNo K8s cluster |
| CIS-K8S-5.2.1 Privileged containers minimised | ๐ง Infrastructure | Pod priv_count attribute (containers[].securityContext.privileged) | No privileged PodsPrivileged Pods detectedNo K8s cluster |
| CIS-K8S-5.2.4 hostNetwork minimised | ๐ง Infrastructure | Pod host_network posture attribute | No hostNetwork PodshostNetwork Pods detectedNo K8s cluster |
| CIS-K8S-5.2.5 hostPID minimised | ๐ง Infrastructure | Pod host_pid posture attribute | No hostPID PodshostPID Pods detectedNo K8s cluster |
| CIS-K8S-5.3.2 NetworkPolicy on every namespace | ๐ง Infrastructure | Live correlation of K8S_NAMESPACE ร K8S_NETWORKPOLICY assets | Every namespace coveredNamespaces without NetPol detectedNo K8s cluster |
| CIS-K8S-5.7.3 runAsNonRoot enforced | ๐ง Infrastructure | Pod runasnonroot_count vs container_count posture | runAsNonRoot on every containerContainers running as rootNo K8s cluster |
Pod Security Standards
3 controls ยท 0 infra checks ยท 0 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| PSS-Privileged Privileged tier | โก Custom Logic | Always informational โ unrestricted policy in effect | Privileged tier acknowledged (low severity)No K8s cluster |
| PSS-Baseline Baseline tier | โก Custom Logic | Aggregate priv_count + host_network + host_pid violations | Baseline policies satisfiedBaseline violations: priv/hostNet/hostPIDNo K8s cluster |
| PSS-Restricted Restricted tier | โก Custom Logic | Aggregate Baseline checks + runasnonroot + default-SA automount | Restricted policies satisfiedRestricted violations detectedNo K8s cluster |
AI Workload Compliance
12 controls ยท 1 infra checks ยท 3 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| AIRMF-MAP-1.1 AI System Inventory | โก Custom Logic | Live CRD watch on KServe / Kubeflow / Argo / Ray / Seldon / Run:ai | AI workloads inventoriedNo AI/ML workloads detected |
| AIRMF-MEASURE-2.7 AI Continuous Monitoring | โก Custom Logic | Same inventory signal + notify-webhook re-scoring (30s SLA per pass) | Continuous monitoring activeNo AI/ML workloads detected |
| AIRMF-MANAGE-1.4 AI Cybersecurity Controls | โก Custom Logic | Strict-ZK Secret inventory + customer-managed encryption posture | Strict-ZK Secret scan + BYOK activeNo K8s cluster |
| AIRMF-GOVERN-1.4 AI Acceptable Use Policy | ๐ Maturity | AI usage policy + guardrails (organisational) | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| EU-AIACT-ART9 AI Risk Management | โก Custom Logic | Live AI workload inventory + risk classification | AI risk-mgmt evidence capturedNo AI/ML workloads detected |
| EU-AIACT-ART15 AI Cybersecurity Resilience | โก Custom Logic | Strict-ZK Secret inventory + secret rotation evidence | Cybersecurity controls verifiedNo K8s cluster |
| EU-AIACT-ART15 AI Access Control | ๐ IAM & Access | K8s broad-CRB detection scoped to AI namespaces | Least-privilege RBAC verifiedBroad CRBs on AI namespaceNo K8s cluster |
| EU-AIACT-ART12 AI Audit Logging | ๐ง Infrastructure | Cloud audit-log presence on AI workload's host cloud | Audit logging enabledAudit logging gapsNo AI workloads or no cloud audit_log asset |
| ISO42001-7.4 AI Management System Documentation | ๐ Maturity | Documented AI management system per ISO/IEC 42001:2023 | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISO42001-8.2 AI Workload RBAC | ๐ IAM & Access | Same K8s broad-RBAC signal โ adds ISO 42001 framework dimension | Least-privilege RBACBroad CRBsNo K8s cluster |
| ISO42001-8.4 AI Image Registry Policy | ๐ Maturity | AI workload container images sourced from approved registries | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| MITRE-ATLAS-AML.T0011 Shadow AI Detection | โก Custom Logic | Live CRD watch flags unauthorised KServe / Kubeflow / Ray / Seldon CRDs | AI workloads detected and auditedNo AI/ML workloads detected |
ISMS-P (Korea)
16 controls ยท 2 infra checks ยท 11 maturity-based| Control | What It Checks | Infrastructure Signal | Verdict Logic |
|---|---|---|---|
| ISMS-1.1 ISMS Scope & Policy | ๐ Maturity | ISMS scope definition | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-1.2 Risk Assessment | ๐ Maturity | Annual risk assessment | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.1 Security Policy | ๐ Maturity | Information security policy | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.2 Security Org | ๐ Maturity | Security organisation chart | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.3 HR Security | ๐ Maturity | Background checks + training | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.4 Asset Management | โก Custom Logic | Total asset count + type diversity | Assets classifiedNo assets identified |
| ISMS-2.5 Access Control | ๐ IAM & Access | IAM user + service account count | Verify MFANo IAM |
| ISMS-2.6 Cryptography | ๐ง Infrastructure | KMS, encryption, TLS posture | Crypto controls activeManual review needed |
| ISMS-2.7 Physical Security | ๐ Maturity | Inherited from cloud provider | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.8 Operations | ๐ Maturity | Operations runbooks | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-2.9 Network Security | ๐ง Infrastructure | VPC + firewall rule presence | SegmentedGap detected |
| ISMS-2.10 Secure SDLC | ๐ Maturity | Secure development lifecycle | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-P.1 PI Protection Policy | ๐ Maturity | Personal information protection | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-P.2 Consent Mgmt | ๐ Maturity | Consent platform | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-P.3 Data Lifecycle | ๐ Maturity | Retention + disposal | โฅ50 assets + โฅ6 types<50 assets or <6 types0 assets |
| ISMS-P.4 Cross-Border Transfer | โก Custom Logic | Cloud region metadata | Region knownRegion unavailable |
๐ How Procedural / Maturity Scoring Works
Organisational controls (code of conduct, incident response, consent management) cannot be fully validated by infrastructure scans alone. Instead, we use your cloud infrastructure footprint as a maturity proxy:
Looking for which frameworks apply to you rather than how they are scored?
โ Back to the compliance encyclopedia