Automated controls
Expand a control to see the exact population, expectation and defaults. A pass requires usable evidence for the selected population. A known contrary observation can prove failure; missing observations or an empty population must not become a pass.No open critical vulnerabilities
No open critical vulnerabilities
- Explanation
- Definition
The recorded maximum vulnerability severity should not be critical.Part of Alignr Baseline (seeded).Applies toSubjects with a recorded highest vulnerability severity observation.What the result tells youThis excludes the exact value critical. A non-critical value does not mean zero vulnerabilities, and absent severity evidence does not pass.
Open vulnerability count stays within limits
Open vulnerability count stays within limits
- Explanation
- Definition
The recorded open-vulnerability count should be at or below the configured limit.Part of Alignr Baseline (seeded).Applies toSubjects with a recorded open vulnerability count observation.Default settings
Client overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThe limit applies to the source-reported count for a subject. Keep scanner scopes comparable; a low count is not proof of low business risk.
Managed endpoints have no missing patches
Managed endpoints have no missing patches
- Explanation
- Definition
The selected device needs an explicit null observation for missing patches to satisfy this comparison.Part of Alignr Baseline (seeded).Applies toDevices reported as managed by an RMM.What the result tells youImportant limitation: not_exists compares an observed null value. No missing_patch row is unknown, not a clean patch result. An observed missing patch fails; do not use a lack of rows as proof that the endpoint is patched.
No critical vulnerabilities remain open
No critical vulnerabilities remain open
- Explanation
- Definition
The recorded maximum vulnerability severity should not be critical.Part of BIOS Vulnerability and Governance.Applies toSubjects with a recorded highest vulnerability severity observation.What the result tells youThis excludes the exact value critical. A non-critical value does not mean zero vulnerabilities, and absent severity evidence does not pass.
Open vulnerabilities stay below threshold
Open vulnerabilities stay below threshold
- Explanation
- Definition
The recorded open-vulnerability count should be at or below the configured limit.Part of BIOS Vulnerability and Governance.Applies toSubjects with a recorded open vulnerability count observation.Default settings
Client overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThe limit applies to the source-reported count for a subject. Keep scanner scopes comparable; a low count is not proof of low business risk.
Manual checks
These are human reviews, not automated evidence. The interval below is the template default; review ownership, evidence and suitability for the client.Review configuration drift governance
Review configuration drift governance
Review every 30 days · BIOS Vulnerability and GovernanceReview approved baselines, exception ownership and drift evidence across systems. Current facts do not prove a complete cross-domain baseline.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review incident response readiness
Review incident response readiness
Review every 90 days · BIOS Vulnerability and GovernanceConfirm contacts, roles, escalation paths, communications and exercise evidence are current.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review email security posture
Review email security posture
Review every 30 days · BIOS Vulnerability and GovernanceReview SPF, DKIM, DMARC, threat protection, forwarding and audit retention in the source consoles. Current emitted mail facts do not prove the full set of expectations.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.