Skip to main content
This category contains 5 automated control definitions and 3 manual checks across the sources named below. Similar controls from different standards are listed separately because names, thresholds or severity can differ. Whether the seeded Alignr Baseline is available depends on how your workspace was provisioned. Library templates are copied as disabled drafts. See Choose a baseline before enabling anything.

Automated controls

Expand a control to see the exact population, expectation and defaults. A pass requires usable evidence for the selected population. A known contrary observation can prove failure; missing observations or an empty population must not become a pass.
The recorded maximum vulnerability severity should not be critical.Part of Alignr Baseline (seeded).Applies toSubjects with a recorded highest vulnerability severity observation.What the result tells youThis excludes the exact value critical. A non-critical value does not mean zero vulnerabilities, and absent severity evidence does not pass.
The recorded open-vulnerability count should be at or below the configured limit.Part of Alignr Baseline (seeded).Applies toSubjects with a recorded open vulnerability count observation.Default settingsClient overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThe limit applies to the source-reported count for a subject. Keep scanner scopes comparable; a low count is not proof of low business risk.
The selected device needs an explicit null observation for missing patches to satisfy this comparison.Part of Alignr Baseline (seeded).Applies toDevices reported as managed by an RMM.What the result tells youImportant limitation: not_exists compares an observed null value. No missing_patch row is unknown, not a clean patch result. An observed missing patch fails; do not use a lack of rows as proof that the endpoint is patched.
The recorded maximum vulnerability severity should not be critical.Part of BIOS Vulnerability and Governance.Applies toSubjects with a recorded highest vulnerability severity observation.What the result tells youThis excludes the exact value critical. A non-critical value does not mean zero vulnerabilities, and absent severity evidence does not pass.
The recorded open-vulnerability count should be at or below the configured limit.Part of BIOS Vulnerability and Governance.Applies toSubjects with a recorded open vulnerability count observation.Default settingsClient overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThe limit applies to the source-reported count for a subject. Keep scanner scopes comparable; a low count is not proof of low business risk.

Manual checks

These are human reviews, not automated evidence. The interval below is the template default; review ownership, evidence and suitability for the client.
Review every 30 days · BIOS Vulnerability and GovernanceReview approved baselines, exception ownership and drift evidence across systems. Current facts do not prove a complete cross-domain baseline.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review every 90 days · BIOS Vulnerability and GovernanceConfirm contacts, roles, escalation paths, communications and exercise evidence are current.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review every 30 days · BIOS Vulnerability and GovernanceReview SPF, DKIM, DMARC, threat protection, forwarding and audit retention in the source consoles. Current emitted mail facts do not prove the full set of expectations.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.

Investigate a result

Confirm the client and the account, device or other item being assessed. Check the source, observation time and effective settings, then compare the recorded evidence with the expectation. Missing evidence needs investigation; a change to the environment requires a separate review.

Next steps

Create a custom control · Parameters and client overrides · Record a manual check