Assessment domain
Framework mapping
Framework mapping is what turns a technical finding into evidence a board, an auditor, or an insurer can act on. Every issue we raise is traced to the specific controls it touches across the frameworks your organization is measured against — and, where it applies, the regional privacy law that governs the data involved. It is the layer that makes the other five domains legible to the people who fund and sign off on the work, without inventing a control or a status the assessment did not observe.
Why it matters
Where the risk lives
A finding nobody can tie to a requirement is hard to fund, hard to prioritize, and hard to prove closed. When the same misconfiguration maps to a CIS benchmark, a SOC 2 criterion, and a PCI requirement at once, one remediation can close several control gaps — and the evidence you produce serves the audit, the cyber-insurance questionnaire, and the board update from a single body of work. Mapping is also where accuracy matters most: we describe which controls a finding relates to and what evidence it produces, not whether you are certified, because certification is an auditor's determination and not something a read-only assessment can grant.

What we assess
The checks inside framework mapping
Each area below is a focused review with its own findings, per-cloud detail, and remediation.
From finding to evidence
Each finding carries the context an auditor or reviewer needs to act on it: the affected resource, the observed condition, the control it relates to, and the remediation that would close it. We frame this as evidence of a gap or a satisfied control, not as a pass/fail certification, because the assessment is read-only and does not change your environment or your compliance status. The goal is a report you can hand to an auditor, an insurer, or leadership without translating it first.
What we look forDomain-to-framework crosswalk
The five technical domains — identity, data, network, logging, and configuration — rarely map one-to-one onto a single framework. A single identity gap can touch access-control requirements in CIS, SOC 2, HIPAA, and PCI at the same time. The crosswalk shows, for each finding, every framework and control it produces evidence for, so you can plan remediation by impact instead of fixing the same issue once per audit.
What we look forRegional privacy overlays
On top of the security frameworks, most organizations answer to privacy law that depends on where they and their customers operate — US state privacy statutes, sector rules like GLBA and HIPAA, and cross-border regimes for organizations handling Canadian or EU data. The report surfaces where a finding intersects data-residency and privacy obligations so those requirements are visible alongside the security controls. This is practical guidance for planning, not legal advice, and it is framed as current to 2026 without asserting a compliance determination.
What we look forAcross your clouds
AWS, Azure & Google Cloud
AWS
Findings are mapped from AWS controls — IAM, S3, CloudTrail, Config, Security Hub standards — to the specific framework requirements they satisfy, correlated where useful with Security Hub's CIS/PCI standards and Audit Manager control sets rather than replacing them.
Azure
Findings are mapped from Azure controls — Entra ID, Storage, Defender for Cloud, Activity and Diagnostic logs — to framework requirements, cross-referenced with the Defender for Cloud regulatory compliance dashboard so the report speaks the same language as your native tooling.
Google Cloud
Findings are mapped from Google Cloud controls — Cloud IAM, Cloud Storage, Cloud Audit Logs, org policy — to framework requirements, correlated with Security Command Center's compliance findings so evidence lines up with what GCP already reports.
Example finding
One over-privileged IAM role mapped to CIS IAM, SOC 2 CC6, and PCI-DSS Req. 7
Risk: Left unmapped, the same finding gets remediated separately for each audit — or falls through the cracks because no single framework owner claims it.
Fix: Map the finding once to every control it touches, then remediate once — a single least-privilege change produces evidence for all three requirements at the same time.
Questions
Does a mapped report mean we are compliant or certified?
No. The report shows how each finding relates to framework controls and what evidence it produces, so you can prepare for an audit and prioritize work. Certification is a determination your auditor makes — a read-only assessment cannot grant it, and we do not claim it.
Which frameworks and privacy laws do you map to?
CIS Benchmarks, NIST CSF, SOC 2, ISO 27001, HIPAA, PCI-DSS, GLBA, HITRUST, CMMC, FedRAMP, and FFIEC, plus regional privacy overlays such as US state privacy laws and Canadian and EU regimes. We map to the frameworks your industry answers to rather than every catalog at once.
Is the regional privacy guidance legal advice?
No. We surface where findings intersect data-residency and privacy obligations as practical guidance for planning and for your counsel to review. It is framed as current to 2026 and is not a substitute for legal review.
See where you stand on framework mapping
A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.
Related domains
The rest of the health check
One read-only assessment covers all six domains — here's where else exposure tends to hide.




