Documentation
Frameworks and control coverage
How TenantVigil maps technical findings into benchmark and compliance frameworks.
Need a hands-on starting point?
Run a free assessment or talk to the team if you want help evaluating fit, permissions, or rollout approach.
Supported framework families
TenantVigil maintains a control catalog that maps Microsoft 365 technical findings into multiple frameworks and reporting views. The goal is to help technical teams remediate a real control once and then understand the overlap across frameworks.
- CIS Microsoft 365 Foundations Benchmark
- CISA SCuBA guidance
- SOC 2 oriented control mapping
- NIST CSF oriented reporting
- GDPR, NIS2, HIPAA, and ISO 27001 reporting mappings
How scoring differs from raw counts
A TenantVigil score is a normalized health index, not a raw control count. Pass, fail, warning, and non-applicable states are treated differently so the score reflects the weighted condition of the tenant rather than just the number of controls in the library.
This means the total controls scanned and the weighted score are related but not identical metrics. The purpose of the control pages and history views is to let technical users inspect the specific evidence behind those higher-level report values.
How control relevance is maintained
TenantVigil curates controls around current Microsoft 365 threat areas such as privileged access, phishing resistance, collaboration exposure, device hygiene, data protection, and audit readiness.
Controls are benchmark-driven but also described in plain operational language so teams can connect the technical check to a modern attack or governance failure mode.