Blog

Written by the people who built it.Audits, compliance, and what breaks in practice.

Home / Blog / Methodology
Methodology

The 173 controls explained: CIS, ANSSI, NIST and ISO 27001

AdGUARD·2026-02-24·9 min

A security control only means something when it is tied to a recognised framework. AdGUARD runs 173 automated controls across eight Microsoft referentials, each mapped to established standards. Here is what that coverage looks like and why it matters.

Why framework alignment matters

Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer, or an ISO assessor — is that every control traces back to an authoritative source. AdGUARD aligns its controls with four widely recognised frameworks so that each finding carries a reference you can justify.

The four frameworks

CIS Active Directory Benchmarks

The Center for Internet Security publishes consensus-based hardening benchmarks for Active Directory. They are prescriptive and practical — exact settings, recommended values, level 1 (essential) and level 2 (defence-in-depth) tiers. They form the backbone of AdGUARD's control set.

ANSSI recommendations

The French national cybersecurity agency publishes hardening guides for Microsoft environments that are especially strong on identity. They inform many of the identity-focused controls.

NIST

NIST's cybersecurity guidance (including SP 800-53 and the Cybersecurity Framework) provides the control-family structure that helps map technical findings to governance categories — useful when reporting to risk and compliance functions.

ISO/IEC 27001

The international standard for information security management. Mapping controls to ISO 27001 annex A helps organisations pursuing or maintaining certification show concrete technical evidence behind their ISMS.

Coverage across eight referentials

The 173 controls are distributed across eight Microsoft referentials:

ReferentialExample controls
Active DirectoryConditional access, MFA, legacy auth, privileged roles
Exchange OnlineMail flow, external forwarding, authentication
SharePointExternal sharing, access controls
TeamsGuest access, meeting and messaging policy
OneDriveSharing, sync restrictions
DefenderThreat policies, safe attachments/links
PurviewRetention, audit, data governance

More than three times Secure Score depth

Microsoft Secure Score covers roughly eighty checks. At 173 controls across eight referentials, AdGUARD goes more than three times deeper than Secure Score.

Every finding is traceable

Each control in a report cites its framework reference and, where relevant, a link to Microsoft documentation. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters and where the recommendation comes from.

Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee.