Home / Blog / Methodology
Methodology

The 283 controls explained: CIS, ANSSI, NIST and ISO 27001

EntraGUARD·2026-02-24·9 min

A security control only means something when it is tied to a recognised framework. EntraGUARD runs 283 automated controls across nine Microsoft referentials, each mapped to established standards. Here is what that coverage looks like and why it matters.

Why framework alignment matters

Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer, or an ISO assessor — is that every control traces back to an authoritative source. EntraGUARD aligns its controls with four widely recognised frameworks so that each finding carries a reference you can justify.

The four frameworks

CIS Microsoft 365 & Azure Benchmarks

The Center for Internet Security publishes consensus-based hardening benchmarks for Microsoft 365 and Azure. They are prescriptive and practical — exact settings, recommended values, level 1 (essential) and level 2 (defence-in-depth) tiers. They form the backbone of EntraGUARD's control set.

ANSSI recommendations

The French national cybersecurity agency publishes hardening guides for Active Directory and Microsoft environments that are especially strong on on-premises and hybrid identity. They inform many of the AD-focused controls.

NIST

NIST's cybersecurity guidance (including SP 800-53 and the Cybersecurity Framework) provides the control-family structure that helps map technical findings to governance categories — useful when reporting to risk and compliance functions.

ISO/IEC 27001

The international standard for information security management. Mapping controls to ISO 27001 annex A helps organisations pursuing or maintaining certification show concrete technical evidence behind their ISMS.

Coverage across nine referentials

The 283 controls are distributed across nine Microsoft referentials:

ReferentialExample controls
Entra IDConditional access, MFA, legacy auth, privileged roles
Active DirectoryPrivileged groups, delegation, password policy, Kerberos
AzureRBAC, network exposure, Defender for Cloud, key vaults
Exchange OnlineMail flow, external forwarding, authentication
SharePointExternal sharing, access controls
TeamsGuest access, meeting and messaging policy
OneDriveSharing, sync restrictions
DefenderThreat policies, safe attachments/links
PurviewRetention, audit, data governance

More than three times Secure Score depth

Microsoft Secure Score covers roughly eighty checks. At 283 controls across nine referentials, EntraGUARD goes more than three times deeper — and crucially, it covers on-premises Active Directory, which Secure Score does not touch at all.

Every finding is traceable

Each control in a report cites its framework reference and, where relevant, a link to Microsoft documentation. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters and where the recommendation comes from.

Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee.

Audit your Microsoft environment

Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.

Download the free demo