Skip to main content
The supplied catalogue has two sources. Keep them distinct when choosing a starting point. Similar controls appear in both sources. The category pages identify each source separately and show its actual population, expected values, parameter defaults and limits.

Browse by topic

Identity and access

Accounts, MFA, policies and privileged access.

Endpoints and servers

Reporting, patching, EDR and encryption.

Backup and recovery

Protection, job status, recency and restores.

Vulnerabilities and governance

Findings, missing patches and security reviews.

Licensing

Licence presence and renewal evidence.

Networks and firewalls

Firmware, availability and configuration recovery.

Email and domains

SPF, DMARC, MX, DKIM and domain reviews.

External exposure

DNS resilience and internet-facing asset reviews.

Copyable templates

What a baseline does and does not establish

A baseline supplies expectations, not evidence that the client meets them. Check source coverage and subject identity before interpreting the results. Some templates combine automated observations with manual reviews precisely because the broader outcome cannot be established from one fact. Titles can summarise more than the actual comparison proves. For example, the backup “retention window” control measures the time since a successful backup; it does not inspect the retention policy. The category reference calls out these limits alongside each definition. Default severities, thresholds and review intervals are starting settings. Review client requirements and parameters and overrides, then follow testing and rollout. The references are generated from the application’s built-in declarations. They describe the supplied catalogue, not the custom controls or effective overrides in your workspace.