-
CIS Google Workspace audit: the benchmark everyone ignores because CIS labels it manual
CIS declares all 89 of its Google Workspace recommendations manual. That single label is why most Workspace domains never get a serious configuration review.
-
One CIS control, five regulatory obligations: the mapping nobody publishes
NIS2, DORA, ISO 27001 and GDPR often ask for the same thing under different names. One observed setting can serve several requirements at once, on one condition.
-
CIS Microsoft 365 v7.0.0: auditing all 160 recommendations without running a single script on the client tenant
The 160 recommendations of CIS Microsoft 365 v7.0.0 can be assessed read-only, with no script run on the client tenant. What that changes for compliance evidence.
Insights
Insights
What we observe in the field, on the configuration of Microsoft 365 and Google Workspace environments and on the frameworks that govern them.