Automatable GRC Controls Dashboard

Select a category from the left to view controls. Click “Details” to see compact attributes for each control.

Identity & Access Management (IAM)

Control Name Frequency Automation Summary How to Automate Details
MFA Enforcement Daily Ensure MFA enabled for all users. Use IdP/IAM APIs to check MFA and enforce policies.
Dormant Account Detection Daily Identify and disable inactive accounts. Query last login timestamps and disable stale accounts.
Privileged Access Review Weekly Review admin and high-privilege roles. Pull role mappings and send review tasks.
Joiner-Mover-Leaver (JML) Daily Automate provisioning and deprovisioning. Sync HR events to IAM and adjust access.
Password Policy Compliance Weekly Ensure password settings meet standards. Check and enforce password policy via IAM.
Orphaned Account Detection Daily Identify accounts without valid owners. Cross-check IAM accounts with HR and CMDB.
Shared Account Monitoring Daily Detect use of shared credentials. Analyze login patterns and device fingerprints.
SSO Coverage Monitoring Weekly Ensure apps are integrated with SSO. Inventory apps and compare to SSO catalog.
Break-glass Account Monitoring Daily Monitor emergency account usage. Alert on any login to break-glass accounts.
Access Certification Automation Quarterly Automate periodic access reviews. Generate review tasks for managers.

Cloud Security

Control Name Frequency Automation Summary How to Automate Details
Storage Encryption Daily Ensure all storage is encrypted at rest. Use CSP config services to enforce encryption.
Public Bucket Detection Daily Detect publicly exposed storage. Scan ACLs and block public access.
Security Group Open Ports Daily Detect overly permissive security groups. Identify 0.0.0.0/0 on sensitive ports.
Instance Hardening Daily Ensure VMs meet hardening baselines. Check CIS benchmarks via agents.
Monitoring Enabled Daily Ensure metrics and logs are enabled. Verify CloudWatch/Monitor/Log Analytics.
Unused Public IP Detection Weekly Identify unattached or idle public IPs. Scan IP allocations and usage.
KMS Key Rotation Monthly Ensure encryption keys rotate on schedule. Check key age and rotation flags.
Tagging Compliance Daily Ensure resources have mandatory tags. Scan resources and enforce tag policies.
Serverless Function Security Daily Check permissions and configs for functions. Review IAM roles and network settings.
Cloud Config Compliance Continuous Evaluate resources against policies. Use AWS Config/Azure Policy/GCP Config.

Network Security

Control Name Frequency Automation Summary How to Automate Details
Firewall Drift Detection Daily Detect unauthorized firewall changes. Compare configs to golden baseline.
Network Segmentation Validation Weekly Validate segmentation boundaries. Run automated path analysis.
IDS/IPS Alert Monitoring Continuous Monitor intrusion detection alerts. Stream alerts to SIEM and triage.
VPN Account Monitoring Daily Monitor VPN usage and anomalies. Review active users and geolocation.
TLS Certificate Expiry Monitoring Daily Detect certificates nearing expiry. Scan endpoints and notify owners.
Open Port Scanning Weekly Identify unauthorized open ports. Run network scans and compare to baseline.
DNS Sinkhole Monitoring Daily Block malicious domains via DNS. Monitor DNS queries and sinkhole bad domains.
Network Config Backup Daily Backup configs for network devices. Automate config export and storage.
DDoS Protection Monitoring Daily Monitor and tune DDoS protections. Review traffic anomalies and mitigation events.
Wireless Security Compliance Weekly Ensure Wi-Fi uses secure configs. Check WPA2/3, segmentation, and auth.

Endpoint Security

Control Name Frequency Automation Summary How to Automate Details
EDR Agent Presence Daily Ensure EDR installed on all endpoints. Query EDR console and MDM for coverage.
Disk Encryption Daily Ensure full disk encryption enabled. Check BitLocker/FileVault status via MDM.
Patch Compliance Daily Ensure OS patches are applied. Check patch status and push updates.
Application Whitelisting Daily Block unauthorized applications. Enforce allow/deny lists via MDM/EDR.
Local Admin Rights Review Weekly Detect and remove local admin rights. Scan local groups and adjust membership.
USB / Removable Media Control Daily Control use of USB storage. Enforce device control policies.
Endpoint CIS Compliance Weekly Ensure endpoints meet CIS baseline. Scan configs and remediate drift.
Device Last-Seen Monitoring Daily Detect stale or missing devices. Track last check-in time.
Browser Security Enforcement Weekly Enforce secure browser settings. Push policies for extensions and security.
Mobile Device Compliance Daily Ensure mobile devices meet policy. Check MDM compliance status.

Database Security

Control Name Frequency Automation Summary How to Automate Details
DB Encryption Weekly Ensure databases are encrypted at rest. Check TDE/storage encryption settings.
Audit Logging Weekly Ensure DB audit logs are enabled. Check logging settings and destinations.
Privileged DB Accounts Review Monthly Review admin-level DB accounts. List privileged users and validate need.
Default Account Hardening Monthly Disable or secure default DB accounts. Scan for default users and lock them.
DB Network Exposure Weekly Detect publicly exposed DB endpoints. Check network configs and firewall rules.
Backup Verification Daily Ensure DB backups complete successfully. Check backup job status.
DB CIS Benchmarking Monthly Check DB configs against CIS baseline. Run benchmark tools or scripts.
SQL Injection Protection Continuous Protect DBs via WAF/DB firewall rules. Use WAF signatures and DB firewall.
Service Account Monitoring Weekly Monitor DB service account usage. Detect interactive logins or anomalies.
Data Masking in Non-Prod Per Refresh Mask sensitive data in lower environments. Apply masking during data refresh.

CI/CD & DevSecOps

Control Name Frequency Automation Summary How to Automate Details
SAST Enforcement Per Pipeline Ensure static code analysis runs. Integrate SAST into CI pipelines.
SCA Scanning Per Build Scan dependencies for vulnerabilities. Run SCA tools in CI.
Container Image Scanning Per Build Scan container images for vulnerabilities. Use image scanning tools in registry/CI.
IaC Policy Checks Per Commit Validate Terraform/K8s manifests. Run policy-as-code tools.
Code Review Enforcement Per PR Require peer review before merge. Use branch protection rules.
Secrets Detection Per Commit Detect secrets in code repositories. Run secret scanning tools.
Deployment Approval Gates Per Deployment Require approvals before production deploy. Use pipeline gates and change tickets.
Artifact Signing Per Build Sign build artifacts for integrity. Use signing tools in CI.
Environment Drift Detection Daily Detect drift between IaC and runtime. Compare deployed state to IaC.
Pipeline Access Review Monthly Review who can modify pipelines. Check permissions on CI/CD configs.

Logging & Monitoring

Control Name Frequency Automation Summary How to Automate Details
Log Collection Coverage Daily Ensure all systems send logs to SIEM. Compare asset inventory to log sources.
Log Retention Compliance Weekly Ensure log retention meets policy. Check retention settings per log type.
Time Sync Monitoring Daily Ensure systems are NTP-synchronized. Check time drift across key systems.
Critical Security Event Alerts Continuous Alert on high-risk security events. Use SIEM correlation rules.
Log Integrity Monitoring Daily Detect tampering with logs. Use hashing or immutable storage.
Schema Compliance Weekly Ensure logs follow standard schema. Validate fields and formats.
Alert Tuning Automation Monthly Reduce noise from excessive alerts. Analyze alert volumes and tune rules.
SIEM Pipeline Health Daily Monitor log ingestion pipeline. Check ingestion rates and errors.
User Behavior Analytics (UBA) Continuous Detect anomalous user behavior. Apply ML/behavioral analytics.
Service Account Log Coverage Weekly Ensure service accounts generate logs. Check logging for critical service accounts.

Vulnerability Management

Control Name Frequency Automation Summary How to Automate Details
Network & Host Vulnerability Scans Weekly Scan infrastructure for vulnerabilities. Schedule scans via vuln scanner.
Patch SLA Tracking Daily Track remediation against SLAs. Monitor age of open vulnerabilities.
Risk-Based Prioritization Daily Prioritize vulns by risk. Combine CVSS, exploit data, and asset value.
Exception & Risk Acceptance Workflow Weekly Manage exceptions to remediation. Automate approvals and expiry.
Web Application Scanning Weekly Scan web apps for vulnerabilities. Run DAST tools on web endpoints.
Cloud Configuration Vulnerability Scans Daily Scan cloud configs for misconfigurations. Use CSPM tools.
Third-Party / Vendor Vulnerability Intake Weekly Ingest vendor advisories. Map advisories to internal assets.
Zero-Day Exposure Assessment Ad-hoc Assess exposure to new zero-days. Search for affected software/versions.
Credential Exposure Monitoring Daily Monitor for leaked credentials. Use breach data and dark web monitoring.
Remediation Verification Scans After Fix Verify vulnerabilities are resolved. Re-scan assets after patching.

Backup & Recovery

Control Name Frequency Automation Summary How to Automate Details
Backup Job Monitoring Daily Monitor backup job success/failure. Check backup logs and statuses.
Backup Coverage Validation Weekly Ensure all critical systems are backed up. Compare CMDB to backup jobs.
Immutable Backup Enforcement Daily Ensure backups are immutable where required. Check storage policies for immutability.
Periodic Restore Testing Monthly Test restore of critical systems. Automate restore to sandbox.
Backup Encryption Verification Weekly Ensure backups are encrypted. Check encryption settings on backup storage.
Ransomware-Aware Backup Monitoring Daily Detect abnormal backup patterns. Monitor for mass deletions or encryption.
Backup Retention Policy Compliance Weekly Ensure retention meets policy. Check retention periods per backup set.
Offsite / Cross-Region Replication Daily Monitor replication to secondary sites. Check replication job status.
Backup Access Control Review Monthly Review who can modify/delete backups. Check IAM/ACLs on backup systems.
Automated DR Runbook Execution Quarterly Test DR procedures automatically. Script DR steps and run in test mode.

Compliance Automation

Control Name Frequency Automation Summary How to Automate Details
Policy-as-Code Enforcement Continuous Encode and enforce policies as code. Use OPA/Kyverno/Checkov in pipelines.
Automated Evidence Collection Continuous Collect evidence from systems automatically. Use scripts/APIs to pull configs and logs.
Control Health Dashboards Daily Visualize status of key controls. Aggregate metrics into dashboards.
Regulatory Mapping & Gap Checks Monthly Map controls to frameworks and find gaps. Use control-library mapping.
Exception Lifecycle Management Weekly Manage control exceptions end-to-end. Automate approvals and expiry reminders.
Automated Control Testing (Sampling) Monthly Test controls using automated sampling. Sample transactions/configs programmatically.
Third-Party Control Evidence Intake Quarterly Collect SOC reports and attestations. Automate reminders and uploads.
Training & Awareness Completion Tracking Monthly Track completion of mandatory training. Pull data from LMS and notify managers.
Data Classification & Labeling Checks Weekly Ensure data is classified and labeled. Scan repositories for labels and content.
Audit-Ready Evidence Packaging Before Audit Package evidence by control and framework. Auto-compile evidence into exportable sets.