What "mapped to eight frameworks" actually means.
Every SARTUS™ finding is recorded once, in one risk register, against one control taxonomy: NIST SP 800-53 Rev 5, benchmarked to the CIS Benchmarks for Microsoft 365 and Azure. Six technical overlays are applied where the regulatory footprint requires. Four attestation frameworks are crosswalked so an assessor can use the evidence. The register is not a compliance certificate. This page shows the mapping so a CFO, GC, underwriter, or diligence reviewer does not have to take the claim on faith.
As cited in
KrebsOnSecurity · Reuters · ZDNet · CRN · Security Boulevard
One register. Two tiers.
Eight frameworks the register is built on. Four it is crosswalked to.
A control catalog and an attestation are different things. The first tells an engineer what to configure. The second tells a buyer that someone independent checked. SARTUS™ findings carry control IDs from the first tier. They are translated into the language of the second tier so an assessor can use them, and no further.
Tier one: baselines and overlays
Technical control catalogs. Every finding in the register carries an identifier from the two baselines. Overlays are applied where the client’s regulatory footprint requires.
| Framework | Version mapped | Role | What it governs | Where the register lands |
|---|---|---|---|---|
| NIST SP 800-53 | Rev 5 | Baseline | The federal control catalog: twenty families, over a thousand controls, adopted voluntarily across regulated mid-market | Primary taxonomy. Every finding carries a control family and control ID. |
| CIS Benchmarks | M365 Foundations v3.x, Azure Foundations v2.x | Baseline | Configuration hardening for Microsoft 365 and Azure, the baseline cyber insurers and PE technical reviewers ask about first | Every configuration finding carries a Benchmark recommendation number. |
| NIST SP 800-171 | Rev 2 | Overlay | 110 requirements for protecting Controlled Unclassified Information in nonfederal systems | 800-53 to 800-171 crosswalk for defense contractors and their acquirers. |
| CMMC | 2.0 | Overlay | The DoD assessment program built on 800-171; Level 2 assessed by a C3PAO | Practices in scope flagged. The identity, cloud, and compromise findings that most often stall a Level 2 assessment. |
| PCI DSS | 4.0 | Overlay | Twelve requirements on a scoped cardholder data environment | Requirements 7, 8, 10, and 12 where Microsoft 365 or Azure touch the CDE. |
| CISA SCuBA | Secure Cloud Business Applications, M365 baselines | Overlay | Federal secure-configuration baselines for Entra ID, Exchange, SharePoint, Teams, and Defender | Policy-level crosswalk by SCuBA baseline ID. The closest thing to a federal answer key for a Microsoft tenant. |
| MCSB | Microsoft Cloud Security Benchmark v1 | Overlay | Microsoft’s own control framework for Azure and Microsoft 365 | Azure findings carry the MCSB control ID, so the register reads against the same taxonomy Defender for Cloud reports in. |
| NSA hardening guidance | Current cybersecurity information sheets | Overlay | Identity, cloud, and network hardening guidance published by the National Security Agency | Applied where a finding matches published guidance, cited by document. |
Tier two: attestation and governance crosswalks
Frameworks that produce an opinion, a certificate, or a governance profile rather than a control list. The register translates findings into their language. It does not, and cannot, issue the result.
| Framework | Version | Who asks for it | What it certifies | What it does not ask | What the register provides |
|---|---|---|---|---|---|
| SOC 2 | 2017 TSC, 2022 points of focus | Enterprise customers, PE diligence, vendor risk teams | Controls as designed and tested on sample dates, opined by a CPA firm | Whether an attacker was in the tenant between samples | CC6 and CC7 crosswalk. Evidence for the auditor. Not the opinion. |
| ISO/IEC 27001 | 2022 | International enterprise customers | An Information Security Management System exists and operates, certified by an accredited body | Whether the environment the ISMS governs is defensible | Annex A themes 5 and 8 crosswalk. Evidence for the certification audit. Not the certificate. |
| HIPAA Security Rule | 45 CFR 164.308 to 164.312 | Covered entities, business associates, healthcare acquirers | Administrative, physical, and technical safeguards; a documented risk analysis | Whether the risk analysis found the breach already underway | Technical safeguards 164.312(a), (b), (d), (e) crosswalk. The register serves as the technical risk analysis artifact. Administrative and physical safeguards are marked out of scope. |
| NIST CSF | 2.0 | Boards, SEC registrants, PE portfolio reporting | Six functions; a profile of intended posture | Current state, measured | Govern, Identify, Protect, and Detect crosswalk at the category level. A measured current-state profile a board can compare to the target profile. |
Crosswalks are conservative. Where a requirement is only partially satisfied by a control the register measures, the crosswalk says partial. Over-mapping is how compliant organizations end up in the Breach Library.
How the register is built
One finding, one row, one control ID.
Recorded once
A finding is written once. The row carries the observed condition, the affected asset or identity, the NIST SP 800-53 control family and control ID, the CIS Benchmark recommendation where applicable, the crosswalk to the other six frameworks, and a severity rating.
Closure status is the column assessors read first
Most third-party assessment findings remain open beyond ninety days without a closure engagement. The register separates closed inside SARTUS™, closed with a documented path and separate quote, and accepted by leadership. That is the difference between a finding and an attestation gap.
Dated and defensible
Every row carries the date it was observed and the date it was closed. A QSA, C3PAO, SOC 2 auditor, or diligence reviewer can trace each control claim to evidence without a follow-up request.
What the register is not
Mapped is not the same as compliant.
- It is not a certification. No document Cloudskope produces satisfies a PCI Report on Compliance, a C3PAO assessment, a SOC 2 opinion, or an ISO certificate. Those remain the work of independent assessors, and independence rules prevent the assessor from fixing what they find. SARTUS™ is the engagement that fixes it first.
- It is not continuous monitoring. It is a six-day measurement and a six-day remediation, dated. Organizations that need the state held between assessments pair it with continuous controls monitoring. The register is the baseline that program starts from.
- It is not a substitute for reading the frameworks. The explainers below are written for the CFO, GC, and board member who has to sign the attestation.
Read the frameworks
Plain-English explainers for the people who sign the attestation.
- What is NIST SP 800-53?
- What is the NIST Cybersecurity Framework?
- What is CMMC? · CMMC Compliance Roadmap
- What is PCI DSS? · Report on Compliance · QSA
- What is SOC 2 Compliance?
- What is ISO 27001?
- What is HIPAA Security?
- What is a Compliance Risk Assessment?
- Cloudskope SARTUS™: the six-day engagement
- What are the CIS Benchmarks?
- What is NIST SP 800-171? · 800-53 vs 800-171
- What is CISA SCuBA? · Microsoft Cloud Security Benchmark
- What is NSA Cybersecurity Guidance?
- FTC Safeguards Rule · NYDFS Part 500 · Cyber Insurance Attestation
Questions assessors and buyers ask
Frequently asked questions.
Is the SARTUS™ risk register accepted by auditors?
Assessors accept evidence, not registers. Each row is structured as evidence: control ID, observed state, remediation record, date. QSAs, C3PAOs, and SOC 2 auditors have used Cloudskope registers as the starting point for scoping and evidence requests. The register does not replace their opinion.
Which framework is the primary mapping?
NIST SP 800-53 Rev 5, benchmarked to the CIS Benchmarks for Microsoft 365 and Azure. Six technical overlays (NIST SP 800-171, CMMC, PCI DSS, CISA SCuBA, MCSB, and NSA hardening guidance) are applied where the regulatory footprint requires. SOC 2, ISO 27001, HIPAA, and NIST CSF are crosswalked from 800-53 as attestation and governance frameworks.
Does SARTUS™ cover all of PCI DSS or all of CMMC?
No. SARTUS™ measures the Microsoft 365, Azure, endpoint, and identity surface plus dark web and active-compromise exposure. Where those surfaces are in scope for PCI DSS or CMMC, the register crosswalks the requirements. Physical controls, policy documentation, and out-of-scope systems are not measured.
Can the register serve as the HIPAA Security Rule risk analysis?
For the technical safeguards on the measured surface, yes, and it is dated and signed. Administrative and physical safeguards are documented as out of scope so the gap is visible rather than implied.
How is "eight frameworks mapped" different from "eight frameworks compliant"?
Mapped means each finding is expressed in the language of each framework. Compliant is a determination only an independent assessor can make. Cloudskope does not claim the second.
No risk to start. If we don’t find it, the engagement is free.
Book a Strategy SessionAssessment. Closure. Evidence. In six days.
If your organization has never formally answered where are we exposed, are we already compromised, and who is going to fix it — SARTUS™ answers all three in one engagement, in one week, at one fixed fee.
Contact us for current availability
.png)