Where the community decides what sits above the line — and what sits below it.
A repository of sanitized implementation patterns — mapped to assessment objectives and rated by people who make adequacy calls. One example rarely covers a whole practice; you assemble the pieces. Every verdict carries written justification, because the reasoning is the part you need.
- Controls
- 110
- Assessment objectives
- 320
- Published examples
- 110
- Verdicts cast
- 28
Implementing a control?
Find patterns that need more eyes, or publish the one you actually used.
Needs more eyesAssessing implementations?
See where the community disagrees, then read how verdicts work.
Contested examplesReading is open. Contributing needs an account.
Anyone can read controls, examples, verdicts and discussion. Posting an example, casting a verdict, or replying requires a signed-in account — that is how attribution and abuse controls work. Start with the quick tour, or sign in with an email link.
Needs more eyes
See all- AC.L2-3.1.3Not enough signal0 verdictsCUI only in labeled libraries; DLP blocks unlabeled egress
- IA.L2-3.5.4Not enough signal0 verdictsNetwork access requires FIDO2 or certificate; OTP not accepted for VPN or SSO
- MP.L2-3.8.3Not enough signal0 verdictsFull-disk encryption plus cryptographic erase; destroy when CE cannot be verified
- CM.L2-3.4.2Not enough signal0 verdictsCIS-aligned Windows baseline assigned by compliance; drift becomes a ticket
- SC.L2-3.13.11Not enough signal0 verdictsOrg-approved crypto module list; BitLocker and TLS configured to approved modes
Contested
See all- AC.L2-3.1.5Contested3 verdictsJust-in-time admin roles; standing privilege only for break-glass
- IA.L2-3.5.3Above the line3 verdictsSmart card at the rack, RADIUS-gated MFA for VDI and VPN
- AC.L2-3.1.1Contested3 verdictsEnclave allow-list: users, service principals, and compliant devices only
Recent examples
All examplesActive discussion
Forum- How should we argue partial AO coverage on one example?
Assessment Practice1 postAug 2, 2026
- Quarterly access review theater vs real removal evidence
Above or Below the Line2 postsAug 2, 2026
- When is a shared scanner identity an identification failure?
IA.L2-3.5.12 postsAug 2, 2026
- Intune vs GPO for least functionality on a hybrid shop floor
Tooling & Implementation2 postsAug 2, 2026
- What evidence actually moves an assessor on Conditional Access?
Evidence & Artifacts2 postsAug 2, 2026
- FIDO2 for admins + TOTP for everyone else — enough for IA.L2-3.5.3?
Assessment Practice2 postsAug 2, 2026