Compliance Engine
Assess your Microsoft 365 security posture against industry frameworks
Compliance Engine
Securtea's compliance engine evaluates your Microsoft 365 configuration against industry-standard security frameworks. Identify gaps, track remediation, and demonstrate compliance to auditors.
What Is Compliance Assessment?
A compliance assessment analyzes your Microsoft 365 configuration against a set of security controls defined by a compliance framework. The engine:
- Collects data from your M365 tenant via Microsoft Graph API
- Evaluates controls by comparing configurations to expected values
- Generates results showing which controls pass, fail, or need manual review
- Calculates scores to measure your overall compliance level
Supported Frameworks
Securtea supports multiple industry-standard frameworks:
CIS Microsoft 365 Foundations Benchmark
The Center for Internet Security (CIS) benchmark provides prescriptive guidance for securing Microsoft 365:
- Scope: M365-specific security configurations
- Controls: 100+ security recommendations
- Updates: Aligned with CIS benchmark versions
- Best for: Organizations wanting detailed M365 security guidance
NIST 800-53
The National Institute of Standards and Technology framework covers comprehensive security controls:
- Scope: Broad security control families
- Controls: Selected controls applicable to M365
- Updates: Aligned with NIST revision 5
- Best for: U.S. government contractors, regulated industries
SOC 2
Service Organization Control 2 focuses on security, availability, and confidentiality:
- Scope: Trust Services Criteria
- Controls: Mapped from M365 configurations
- Updates: Aligned with AICPA standards
- Best for: SaaS companies, service providers
ISO 27001
International standard for information security management:
- Scope: Information security controls
- Controls: Annex A controls mapped to M365
- Updates: Aligned with ISO 27001:2022
- Best for: Organizations seeking ISO certification
Framework coverage depends on your subscription plan. Contact sales for enterprise frameworks.
How It Works
Framework Structure
Each framework is organized hierarchically:
Framework (e.g., CIS Microsoft 365)
└── Themes (e.g., Identity & Access Management)
└── Controls (e.g., Enable MFA for all users)
└── Signals (e.g., Check Conditional Access policies)
Control Evaluation
For each control, the engine:
- Executes signals - Queries Microsoft Graph for relevant data
- Evaluates conditions - Compares data against expected values
- Determines status - Pass, fail, or manual review
- Records evidence - Stores the data for audit purposes
Assessment Run
When you run an assessment:
- Select framework(s) to evaluate
- Engine queries your M365 tenant
- Controls are evaluated in parallel
- Results are compiled and scored
- Assessment completes and results are available
Understanding Results
Control Statuses
| Status | Meaning |
|---|---|
| Pass | Control requirements are met |
| Fail | Control requirements are not met |
| Manual Review | Requires human verification |
| Not Applicable | Control doesn't apply to your environment |
| Error | Evaluation encountered an issue |
Scoring
Your compliance score represents the percentage of applicable controls that pass:
Score = (Passing Controls / Applicable Controls) × 100
Example: If 80 of 100 applicable controls pass, your score is 80%.
Severity Levels
Controls have assigned severity levels:
| Severity | Impact of Non-Compliance |
|---|---|
| Critical | Immediate security risk |
| High | Significant security gap |
| Medium | Moderate security concern |
| Low | Minor security improvement |
Getting Started
Run Your First Assessment
- Navigate to Compliance in the sidebar
- Click Run Assessment
- Select framework(s) to evaluate
- Click Start Assessment
- Wait for completion (typically 2-5 minutes)
- Review your results
Schedule Recurring Assessments
For continuous compliance monitoring:
- Go to Compliance > Settings
- Click Configure Schedule
- Select frequency (daily, weekly, monthly)
- Choose frameworks to include
- Click Save Schedule
Key Features
Multi-Framework Assessment
Assess against multiple frameworks simultaneously:
- Run combined assessments
- See cross-framework control mapping
- Identify controls that satisfy multiple frameworks
Evidence Collection
Automatically collect evidence for each control:
- Configuration snapshots
- API response data
- Timestamps and metadata
Historical Tracking
Track compliance over time:
- View assessment history
- Compare results between runs
- Identify trends and patterns
Remediation Guidance
Get actionable steps to address failures:
- Step-by-step remediation instructions
- Links to relevant Microsoft documentation
- Priority recommendations
What's Next?
- Running Assessments - Detailed guide to running assessments
- Understanding Results - Interpret your compliance data
- Supported Frameworks - Deep dive into each framework
- Assessment History - Track your compliance journey