Step 1 · The requirement
—
—
—
Source requirement vs. local implementation choice
—
Evidence-driven cybersecurity assurance
Choose the role and technologies you actually operate. Then select a control pack to see what evidence to provide, which platform-specific query applies, how it is monitored, and what the result means.
Queries run in your own authorized environment. This project has no ingestion endpoint and never receives credentials, tenant data, or production evidence. Every generated query still requires validation in your own tenant before operational use.
Environment profile
Your cloud and monitoring choices control which working-platform buttons appear below. The profile also changes recommendations and flags technology mismatches.
These packs only ever run a query in Microsoft Sentinel, AWS, or Splunk. Everything else you select is either a source those queries read, or a system you export evidence from. The badge tells you which, so you can see whether your stack is covered before choosing a pack.
directory:users, privileged:assignments, backup:jobs, config:snapshot, network:rules — rather than any vendor's tables. Forward the product into Splunk with that sourcetype and the documented fields, and the existing query covers it with no new query written. This is how Okta, Veeam, Rubrik, Commvault, VMware, and Google Cloud are covered.Open How this connects under any option for the exact index, sourcetype, fields, or contract file involved.
Implementation pack library
Start with the area you are reviewing. Packs are filtered to your selected operating profile unless you choose to view the full library.
Implementation guide
Five steps, from the control objective to a reviewed result. The objective stays fixed — the platform can change at any point without it changing.
Step 1 · The requirement
—
—
—
Step 2 · What you must supply
—
Step 3 · How it is monitored
The query below follows the working platform selected above and updates automatically.
Adjust the available settings. The query updates automatically as you type or change platforms.
—
Step 4 · How it runs continuously
—
—
Step 5 · What the analyst sees
Open this workspace when you are ready to generate a synthetic console preview and review the possible implications.
—
Send feedback here without leaving the page. Submissions are recorded with the selected pack and platform. Do not include identifiers, query results, or production evidence.
Did this pack run in your environment?
Implementation snapshot
A compact view of platform data, supplied evidence, permissions, and the monitoring destination for the selected control.
The JSON profile carries the objective, organization-defined parameters, evidence contract, platform implementation, monitoring configuration, outcome vocabulary, human-review boundary, and validation status as one structured artifact. It is OSCAL-informed and is not an OSCAL document. It contains no credentials, tenant data, query results, or evidence values.