Risk is not only CVEs and patches. Misconfigurations, identity gaps, and missing controls each map to the frameworks auditors hold you to. This page rolls security findings up into risk by framework, so you can see where you are most exposed against the standard you report on.
It is part of the Security Center rollup, alongside the patch, CVE, and configuration trackers. Start from the frameworks hub for the per-framework crosswalks.
Illustrative. For your own tenant the numbers come from a scan: each failed check is weighted by Severity and mapped to the controls it evidences, then summed per framework.
We use Google Analytics cookies to understand site traffic. No findings, scan data, or tenant data are sent. Privacy policy.