13 Security Control Areas. Assessed.

We are transparent about what we assess and what falls outside automated endpoint auditing.

1
2
3
4
5
6
7
8
9
10
11
12
13

Thirteen areas assessed from the endpoint. Five categories, listed below, need processes, people or external tools instead.

Coverage Matrix

Area Name Endpoint Agent Azure AD M365 FortiGate SonicWall
1 Device Inventory
2 Software Inventory
3 Data Protection
4 Secure Configuration
5 Account Management
6 Access Control
7 Patch and Vulnerability Management
8 Audit Logging
9 Email and Browser Protection
10 Malware Defense
11 Backup and Recovery
12 Network Configuration
13 Network Monitoring

Area Details

1 Device Inventory partial +
Local device details (hostname, serial, hardware, OS, network adapters). Agent self-reports installed asset. Does NOT include network-wide discovery or DHCP logging.
2 Software Inventory full +
Installed programs (MSI + registry), Windows Store apps, running services, startup programs, browser versions, .NET/Java/Office versions. Supports allowlisting comparison.
3 Data Protection partial +
BitLocker encryption status (TPM, drive encryption, key protectors), NTFS permissions on shares, removable media encryption. Does NOT cover data classification, data flows, or DLP deployment.
4 Secure Configuration full +
Windows Firewall profiles & rules, risky rule detection, session lock/screen saver settings, default account status, unnecessary services, DNS configuration, UAC settings, SMBv1/LLMNR/NetBIOS status, Remote Desktop configuration.
5 Account Management full +
Local user & admin account inventory, service accounts, admin group membership, default Administrator (SID-500) status, dormant account detection, password policy (complexity, age, lockout).
6 Access Control partial +
MFA status for external apps, remote access, and admin accounts via Entra ID Conditional Access policies. Local security policy audit (user rights assignments, logon restrictions). Domain join and Group Policy application status. Does NOT cover documented access granting/revoking processes or RBAC policy definitions.
7 Patch and Vulnerability Management full +
Windows Update service status, installed/pending updates (critical, security), days since last update, auto-update settings, WSUS configuration. Application patch status for known software.
8 Audit Logging full +
Event log configuration (max sizes, retention, overwrite policy), audit policy settings, PowerShell logging status, command-line auditing, Security/System/Application log status, NTP time synchronization.
9 Email and Browser Protection partial +
Installed browser versions and currency, browser extensions inventory, email client versions. Does NOT cover DNS filtering, DMARC, URL filtering, or email server protections.
10 Malware Defense full +
Windows Defender + third-party AV detection, real-time protection, signature age/version, behavior monitoring, scan history, autorun/autoplay settings, exploit protection (ASLR/DEP), Attack Surface Reduction rules.
11 Backup and Recovery partial +
Veeam Backup services, job status/success rates, last run times, repository health. Windows Backup status, System Restore status, VSS service. Does NOT verify isolated recovery instances or test recovery.
12 Network Configuration partial +
VPN connection status, secure protocol configuration (from endpoint), network adapter driver versions. Does NOT assess network device firmware, architecture, or AAA centralization.
13 Network Monitoring partial +
Host-based IDS/IPS agent presence, Windows Firewall logging, remote access settings, connection security rules. Does NOT cover network IDS/IPS, traffic flow logs, port-level access control, or SIEM centralization.

What We Don't Assess

These categories require organizational processes, human testing, or external tools that fall outside automated endpoint auditing.

Security Awareness Training

Organizational process — requires training program records, completion tracking, and phishing simulation results.

Vendor and Service Provider Management

Organizational process — requires vendor inventory, contract review, and third-party assessment documentation.

Application Security

Development process — requires secure development documentation, code review processes, and application penetration testing. The agent can inventory installed third-party components, but not the development process behind them.

Incident Response

Organizational process — requires documented response plans, role assignments, communication plans, and exercise records.

Penetration Testing

Human testing activity — requires professional penetration testers, documented programs, and remediation verification.

Coverage Depth Key

Full Most checks in this area run through automated endpoint auditing.
Partial Some checks run from the endpoint; others require network infrastructure, organizational processes, or external tools.

See how your fleet scores

Deploy the agent and get your ANCHOR Grade within minutes.