Skip to content

Library ListΒΆ

Category Metric Type
Access Control Access Control - Account Deactivation Timeliness control
Asset Management Asset Management - Asset Discovery Coverage control
Data Protection Data Protection - Volume Encryption Coverage risk
Disaster Recovery Disaster Recovery - Backup Configuration Coverage control
Disaster Recovery - Backup Success Rate performance
Identity Management Identity Management - Multi-Factor Authentication Coverage risk
Identity Management - Password Rotation Compliance control
Identity Management - Inactive Account Detection control
Identity Management - Privileged Account Control risk
Malware Protection Malware Protection - Agent Deployment Coverage control
Network Security Network Security - DNS Domains Expiring Within the Next Month risk
Network Security - DNS Domains with SPF configured risk
Network Security - DNS Domains with DMARC Configured risk
Network Security - External endpoints with insecure ports exposed risk
Network Security - External endpoints protected by a WAF control
Software Development SDLC - Repositories with SAST / DAST scanning enabled control
SDLC - Repositories without exploitable vulnerabilities risk
SDLC - Repositories without exploitable vulnerabilities remediated within SLO performance
User Security User Security - Awareness Training Completion control
Vulnerability Management Vulnerability Management - Agent Deployment Coverage control
Systems with an up-to-date vulnerability database deployed control
End-of-life - Systems running vendor-supported software risk
Vulnerabilities not remediated within SLO - exploitable patchable critical and high performance
Application vulnerabilities not mitigated within SLO - non-patchable exploitable performance
OS vulnerabilities not mitigated within SLO - non-patchable exploitable performance
Vulnerabilities not remediated within SLO - patchable performance
Application vulnerabilities not remediated within SLO - patchable exploitable performance
OS vulnerabilities not remediated within SLO - patchable exploitable performance
OS vulnerabilities not remediated within SLO - patchable non-exploitable performance
Systems without non-patchable exploitable application vulnerabilities risk
Systems without non-patchable exploitable OS vulnerabilities risk
Systems without non-patchable non-exploitable application vulnerabilities risk
Systems without non-patchable non-exploitable OS vulnerabilities risk
Systems without patchable exploitable application vulnerabilities risk
Systems without patchable exploitable OS vulnerabilities risk
Systems without patchable non-exploitable application vulnerabilities risk
Systems without patchable non-exploitable OS vulnerabilities risk