Blog

Home / Blog / Methodology
Methodology

The 318 controls explained: CIS, ANSSI, NIST and ISO 27001

EntraGUARD·2026-02-24·9 min

A security control only means something when it is tied to a recognised framework. EntraGUARD runs 318 automated controls across eight Microsoft referentials, each mapped to established standards. Here is what that coverage looks like and why it matters.

Why framework alignment matters

Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer, or an ISO assessor — is that every control traces back to an authoritative source. EntraGUARD aligns its controls with four widely recognised frameworks so that each finding carries a reference you can justify.

The four frameworks

CIS Microsoft 365 & Entra ID Benchmarks

The Center for Internet Security publishes consensus-based hardening benchmarks for Microsoft 365 and Entra ID. They are prescriptive and practical — exact settings, recommended values, level 1 (essential) and level 2 (defence-in-depth) tiers. They form the backbone of EntraGUARD's control set.

ANSSI recommendations

The French national cybersecurity agency publishes hardening guides for Microsoft environments that are especially strong on identity. They inform many of the identity-focused controls.

NIST

NIST's cybersecurity guidance (including SP 800-53 and the Cybersecurity Framework) provides the control-family structure that helps map technical findings to governance categories — useful when reporting to risk and compliance functions.

ISO/IEC 27001

The international standard for information security management. Mapping controls to ISO 27001 annex A helps organisations pursuing or maintaining certification show concrete technical evidence behind their ISMS.

Coverage across eight referentials

The 318 controls are distributed across eight Microsoft referentials:

ReferentialExample controls
Entra IDConditional access, MFA, legacy auth, privileged roles
Exchange OnlineMail flow, external forwarding, authentication
SharePointExternal sharing, access controls
TeamsGuest access, meeting and messaging policy
OneDriveSharing, sync restrictions
DefenderThreat policies, safe attachments/links
PurviewRetention, audit, data governance

More than three times Secure Score depth

Microsoft Secure Score covers roughly eighty checks. At 318 controls across eight referentials, EntraGUARD goes more than three times deeper than Secure Score.

Every finding is traceable

Each control in a report cites its framework reference and, where relevant, a link to Microsoft documentation. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters and where the recommendation comes from.

Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee.

How the mapping is maintained

Framework mappings are not set-and-forget. CIS publishes new benchmark versions, NIST revises 800-53, ISO reorganises Annex A, regulators issue new articles. A control's value is only as current as its references, so the catalog is maintained against those changes — which is why keeping the application updated matters as much for accuracy as for features.

Reading a control's evidence

Each control is more than a pass or fail. Expanded, it shows the actual finding with the values observed in the tenant, what the control checks, the remediation path in the Microsoft portals, the framework clauses it answers, and a link to the Microsoft documentation. That is what makes a result defensible to an auditor: not "control X failed", but the observed configuration, the requirement it violates and the fix — all in one place.