Automatable GRC Controls Dashboard
Select a category from the left to view controls. Click “Details” to see compact attributes for each control.
Identity & Access Management (IAM)
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| MFA Enforcement | Daily | Ensure MFA enabled for all users. | Use IdP/IAM APIs to check MFA and enforce policies. | |
| Dormant Account Detection | Daily | Identify and disable inactive accounts. | Query last login timestamps and disable stale accounts. | |
| Privileged Access Review | Weekly | Review admin and high-privilege roles. | Pull role mappings and send review tasks. | |
| Joiner-Mover-Leaver (JML) | Daily | Automate provisioning and deprovisioning. | Sync HR events to IAM and adjust access. | |
| Password Policy Compliance | Weekly | Ensure password settings meet standards. | Check and enforce password policy via IAM. | |
| Orphaned Account Detection | Daily | Identify accounts without valid owners. | Cross-check IAM accounts with HR and CMDB. | |
| Shared Account Monitoring | Daily | Detect use of shared credentials. | Analyze login patterns and device fingerprints. | |
| SSO Coverage Monitoring | Weekly | Ensure apps are integrated with SSO. | Inventory apps and compare to SSO catalog. | |
| Break-glass Account Monitoring | Daily | Monitor emergency account usage. | Alert on any login to break-glass accounts. | |
| Access Certification Automation | Quarterly | Automate periodic access reviews. | Generate review tasks for managers. |
Cloud Security
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Storage Encryption | Daily | Ensure all storage is encrypted at rest. | Use CSP config services to enforce encryption. | |
| Public Bucket Detection | Daily | Detect publicly exposed storage. | Scan ACLs and block public access. | |
| Security Group Open Ports | Daily | Detect overly permissive security groups. | Identify 0.0.0.0/0 on sensitive ports. | |
| Instance Hardening | Daily | Ensure VMs meet hardening baselines. | Check CIS benchmarks via agents. | |
| Monitoring Enabled | Daily | Ensure metrics and logs are enabled. | Verify CloudWatch/Monitor/Log Analytics. | |
| Unused Public IP Detection | Weekly | Identify unattached or idle public IPs. | Scan IP allocations and usage. | |
| KMS Key Rotation | Monthly | Ensure encryption keys rotate on schedule. | Check key age and rotation flags. | |
| Tagging Compliance | Daily | Ensure resources have mandatory tags. | Scan resources and enforce tag policies. | |
| Serverless Function Security | Daily | Check permissions and configs for functions. | Review IAM roles and network settings. | |
| Cloud Config Compliance | Continuous | Evaluate resources against policies. | Use AWS Config/Azure Policy/GCP Config. |
Network Security
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Firewall Drift Detection | Daily | Detect unauthorized firewall changes. | Compare configs to golden baseline. | |
| Network Segmentation Validation | Weekly | Validate segmentation boundaries. | Run automated path analysis. | |
| IDS/IPS Alert Monitoring | Continuous | Monitor intrusion detection alerts. | Stream alerts to SIEM and triage. | |
| VPN Account Monitoring | Daily | Monitor VPN usage and anomalies. | Review active users and geolocation. | |
| TLS Certificate Expiry Monitoring | Daily | Detect certificates nearing expiry. | Scan endpoints and notify owners. | |
| Open Port Scanning | Weekly | Identify unauthorized open ports. | Run network scans and compare to baseline. | |
| DNS Sinkhole Monitoring | Daily | Block malicious domains via DNS. | Monitor DNS queries and sinkhole bad domains. | |
| Network Config Backup | Daily | Backup configs for network devices. | Automate config export and storage. | |
| DDoS Protection Monitoring | Daily | Monitor and tune DDoS protections. | Review traffic anomalies and mitigation events. | |
| Wireless Security Compliance | Weekly | Ensure Wi-Fi uses secure configs. | Check WPA2/3, segmentation, and auth. |
Endpoint Security
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| EDR Agent Presence | Daily | Ensure EDR installed on all endpoints. | Query EDR console and MDM for coverage. | |
| Disk Encryption | Daily | Ensure full disk encryption enabled. | Check BitLocker/FileVault status via MDM. | |
| Patch Compliance | Daily | Ensure OS patches are applied. | Check patch status and push updates. | |
| Application Whitelisting | Daily | Block unauthorized applications. | Enforce allow/deny lists via MDM/EDR. | |
| Local Admin Rights Review | Weekly | Detect and remove local admin rights. | Scan local groups and adjust membership. | |
| USB / Removable Media Control | Daily | Control use of USB storage. | Enforce device control policies. | |
| Endpoint CIS Compliance | Weekly | Ensure endpoints meet CIS baseline. | Scan configs and remediate drift. | |
| Device Last-Seen Monitoring | Daily | Detect stale or missing devices. | Track last check-in time. | |
| Browser Security Enforcement | Weekly | Enforce secure browser settings. | Push policies for extensions and security. | |
| Mobile Device Compliance | Daily | Ensure mobile devices meet policy. | Check MDM compliance status. |
Database Security
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| DB Encryption | Weekly | Ensure databases are encrypted at rest. | Check TDE/storage encryption settings. | |
| Audit Logging | Weekly | Ensure DB audit logs are enabled. | Check logging settings and destinations. | |
| Privileged DB Accounts Review | Monthly | Review admin-level DB accounts. | List privileged users and validate need. | |
| Default Account Hardening | Monthly | Disable or secure default DB accounts. | Scan for default users and lock them. | |
| DB Network Exposure | Weekly | Detect publicly exposed DB endpoints. | Check network configs and firewall rules. | |
| Backup Verification | Daily | Ensure DB backups complete successfully. | Check backup job status. | |
| DB CIS Benchmarking | Monthly | Check DB configs against CIS baseline. | Run benchmark tools or scripts. | |
| SQL Injection Protection | Continuous | Protect DBs via WAF/DB firewall rules. | Use WAF signatures and DB firewall. | |
| Service Account Monitoring | Weekly | Monitor DB service account usage. | Detect interactive logins or anomalies. | |
| Data Masking in Non-Prod | Per Refresh | Mask sensitive data in lower environments. | Apply masking during data refresh. |
CI/CD & DevSecOps
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| SAST Enforcement | Per Pipeline | Ensure static code analysis runs. | Integrate SAST into CI pipelines. | |
| SCA Scanning | Per Build | Scan dependencies for vulnerabilities. | Run SCA tools in CI. | |
| Container Image Scanning | Per Build | Scan container images for vulnerabilities. | Use image scanning tools in registry/CI. | |
| IaC Policy Checks | Per Commit | Validate Terraform/K8s manifests. | Run policy-as-code tools. | |
| Code Review Enforcement | Per PR | Require peer review before merge. | Use branch protection rules. | |
| Secrets Detection | Per Commit | Detect secrets in code repositories. | Run secret scanning tools. | |
| Deployment Approval Gates | Per Deployment | Require approvals before production deploy. | Use pipeline gates and change tickets. | |
| Artifact Signing | Per Build | Sign build artifacts for integrity. | Use signing tools in CI. | |
| Environment Drift Detection | Daily | Detect drift between IaC and runtime. | Compare deployed state to IaC. | |
| Pipeline Access Review | Monthly | Review who can modify pipelines. | Check permissions on CI/CD configs. |
Logging & Monitoring
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Log Collection Coverage | Daily | Ensure all systems send logs to SIEM. | Compare asset inventory to log sources. | |
| Log Retention Compliance | Weekly | Ensure log retention meets policy. | Check retention settings per log type. | |
| Time Sync Monitoring | Daily | Ensure systems are NTP-synchronized. | Check time drift across key systems. | |
| Critical Security Event Alerts | Continuous | Alert on high-risk security events. | Use SIEM correlation rules. | |
| Log Integrity Monitoring | Daily | Detect tampering with logs. | Use hashing or immutable storage. | |
| Schema Compliance | Weekly | Ensure logs follow standard schema. | Validate fields and formats. | |
| Alert Tuning Automation | Monthly | Reduce noise from excessive alerts. | Analyze alert volumes and tune rules. | |
| SIEM Pipeline Health | Daily | Monitor log ingestion pipeline. | Check ingestion rates and errors. | |
| User Behavior Analytics (UBA) | Continuous | Detect anomalous user behavior. | Apply ML/behavioral analytics. | |
| Service Account Log Coverage | Weekly | Ensure service accounts generate logs. | Check logging for critical service accounts. |
Vulnerability Management
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Network & Host Vulnerability Scans | Weekly | Scan infrastructure for vulnerabilities. | Schedule scans via vuln scanner. | |
| Patch SLA Tracking | Daily | Track remediation against SLAs. | Monitor age of open vulnerabilities. | |
| Risk-Based Prioritization | Daily | Prioritize vulns by risk. | Combine CVSS, exploit data, and asset value. | |
| Exception & Risk Acceptance Workflow | Weekly | Manage exceptions to remediation. | Automate approvals and expiry. | |
| Web Application Scanning | Weekly | Scan web apps for vulnerabilities. | Run DAST tools on web endpoints. | |
| Cloud Configuration Vulnerability Scans | Daily | Scan cloud configs for misconfigurations. | Use CSPM tools. | |
| Third-Party / Vendor Vulnerability Intake | Weekly | Ingest vendor advisories. | Map advisories to internal assets. | |
| Zero-Day Exposure Assessment | Ad-hoc | Assess exposure to new zero-days. | Search for affected software/versions. | |
| Credential Exposure Monitoring | Daily | Monitor for leaked credentials. | Use breach data and dark web monitoring. | |
| Remediation Verification Scans | After Fix | Verify vulnerabilities are resolved. | Re-scan assets after patching. |
Backup & Recovery
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Backup Job Monitoring | Daily | Monitor backup job success/failure. | Check backup logs and statuses. | |
| Backup Coverage Validation | Weekly | Ensure all critical systems are backed up. | Compare CMDB to backup jobs. | |
| Immutable Backup Enforcement | Daily | Ensure backups are immutable where required. | Check storage policies for immutability. | |
| Periodic Restore Testing | Monthly | Test restore of critical systems. | Automate restore to sandbox. | |
| Backup Encryption Verification | Weekly | Ensure backups are encrypted. | Check encryption settings on backup storage. | |
| Ransomware-Aware Backup Monitoring | Daily | Detect abnormal backup patterns. | Monitor for mass deletions or encryption. | |
| Backup Retention Policy Compliance | Weekly | Ensure retention meets policy. | Check retention periods per backup set. | |
| Offsite / Cross-Region Replication | Daily | Monitor replication to secondary sites. | Check replication job status. | |
| Backup Access Control Review | Monthly | Review who can modify/delete backups. | Check IAM/ACLs on backup systems. | |
| Automated DR Runbook Execution | Quarterly | Test DR procedures automatically. | Script DR steps and run in test mode. |
Compliance Automation
| Control Name | Frequency | Automation Summary | How to Automate | Details |
|---|---|---|---|---|
| Policy-as-Code Enforcement | Continuous | Encode and enforce policies as code. | Use OPA/Kyverno/Checkov in pipelines. | |
| Automated Evidence Collection | Continuous | Collect evidence from systems automatically. | Use scripts/APIs to pull configs and logs. | |
| Control Health Dashboards | Daily | Visualize status of key controls. | Aggregate metrics into dashboards. | |
| Regulatory Mapping & Gap Checks | Monthly | Map controls to frameworks and find gaps. | Use control-library mapping. | |
| Exception Lifecycle Management | Weekly | Manage control exceptions end-to-end. | Automate approvals and expiry reminders. | |
| Automated Control Testing (Sampling) | Monthly | Test controls using automated sampling. | Sample transactions/configs programmatically. | |
| Third-Party Control Evidence Intake | Quarterly | Collect SOC reports and attestations. | Automate reminders and uploads. | |
| Training & Awareness Completion Tracking | Monthly | Track completion of mandatory training. | Pull data from LMS and notify managers. | |
| Data Classification & Labeling Checks | Weekly | Ensure data is classified and labeled. | Scan repositories for labels and content. | |
| Audit-Ready Evidence Packaging | Before Audit | Package evidence by control and framework. | Auto-compile evidence into exportable sets. |