The 173 controls explained: CIS, ANSSI, NIST and ISO 27001
A security control only means something when it is tied to a recognised framework. AdGUARD runs 173 automated controls across eight Microsoft referentials, each mapped to established standards. Here is what that coverage looks like and why it matters.
Why framework alignment matters
Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer, or an ISO assessor — is that every control traces back to an authoritative source. AdGUARD aligns its controls with four widely recognised frameworks so that each finding carries a reference you can justify.
The four frameworks
CIS Active Directory Benchmarks
The Center for Internet Security publishes consensus-based hardening benchmarks for Active Directory. They are prescriptive and practical — exact settings, recommended values, level 1 (essential) and level 2 (defence-in-depth) tiers. They form the backbone of AdGUARD's control set.
ANSSI recommendations
The French national cybersecurity agency publishes hardening guides for Microsoft environments that are especially strong on identity. They inform many of the identity-focused controls.
NIST
NIST's cybersecurity guidance (including SP 800-53 and the Cybersecurity Framework) provides the control-family structure that helps map technical findings to governance categories — useful when reporting to risk and compliance functions.
ISO/IEC 27001
The international standard for information security management. Mapping controls to ISO 27001 annex A helps organisations pursuing or maintaining certification show concrete technical evidence behind their ISMS.
Coverage across eight referentials
The 173 controls are distributed across eight Microsoft referentials:
| Referential | Example controls |
|---|---|
| Active Directory | Conditional access, MFA, legacy auth, privileged roles |
| Exchange Online | Mail flow, external forwarding, authentication |
| SharePoint | External sharing, access controls |
| Teams | Guest access, meeting and messaging policy |
| OneDrive | Sharing, sync restrictions |
| Defender | Threat policies, safe attachments/links |
| Purview | Retention, audit, data governance |
More than three times Secure Score depth
Microsoft Secure Score covers roughly eighty checks. At 173 controls across eight referentials, AdGUARD goes more than three times deeper than Secure Score.
Every finding is traceable
Each control in a report cites its framework reference and, where relevant, a link to Microsoft documentation. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters and where the recommendation comes from.
Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee.