VISTASecurity
  • Vista Platform
  • How it works
  • Insights
  • Docs
  • Release status
  • Mailing list
Try Core
Vista Documentation
  • Editions
  • Vista Platform Platform Overview
  • Cbom
    • CBOM Artifacts
  • Features
    • Algorithm Reference
    • AI Assistant Integration (MCP)
    • Asset Approval Workflow
    • Asset Lifecycle Management
    • AWS Cloud Resource Discovery
    • Azure Cloud Resource Discovery
    • Certificate Chain Management
    • CMDB Integrations
    • CMDB Terminology Glossary
    • Compliance Framework Management
    • Crypto Risks Dashboard
    • Cryptographic Keys
    • Device Interrogation Feature
    • Discovery Feature
    • Fortinet Device Interrogation
    • Viewing Frameworks, Controls & Measurements
    • GCP Cloud Resource Discovery
    • Getting Started checklist
    • Global search (⌘K)
    • Inventory and Lenses
    • Measurement Templates
    • Inviting Members
    • Infrastructure Assets and Crypto Configurations
    • Network Spaces Feature
    • Operational Context
    • Page-local Export
    • PCAP File Ingestion
    • Remediation
    • Scopes
    • Enhanced Sensor Registration & Management Guide
    • Spreadsheet Import
    • Third-Party Systems and External Connections
    • Unified Crypto Inventory
  • Guides
    • Audit Logging User Guide
    • Cloud and Device Management Separation – Migration Guide
    • Device Auto-Discovery Troubleshooting Guide
    • Device Interrogation User Guide
    • Tenant Administrator Guide
    • Tenant User Guide
  • Operating VistaPlatform
    • Container runtime images (source of truth)
    • Platform Administrator Guide
    • Releases & Versioning
    • Service Startup and Shutdown Procedures
    • Configuration
      • Platform Integrations Configuration Guide
    • Deployment Documentation
      • Database Deployment Readiness – Sensor Management Enhancements
      • Database Migration Guide
      • Device Agent Deployment Guide
      • Managed vs In-Cluster Data Services (EKS)
      • Deployment Migration Checklist
      • Production Deployment Checklist
      • Deployment Propagation Guide
      • Vista RKE2 v1 — Customer Documentation
        • Vista — RKE2 Cluster Provisioning Guide
        • Vista Deployment Guide — RKE2 v1
        • Vista RKE2 Deployment — Pre-Flight Checklist
        • Vista Security Overview — RKE2 v1
        • Vista Support Bundle
    • Monitoring
      • Compliance Engine Event Processing Alerts
      • Compliance Log Management & Retention
      • Production Monitoring & Alerting Setup
      • System Monitoring & Alerting Guide
    • Operations
      • Notification Provider Integration Guide
    • Security
      • 🔒 Security Architecture for Cloud-Hosted Control Plane
      • Bootstrap Certificate Management
      • Certificate Management Operations Guide
      • Secrets Management Guide
    • Troubleshooting
      • Asset Approval Workflow Issues – Resolution Documentation
      • Troubleshooting Guide
      • Runbooks
        • Gateway Runbook
        • Recovery and Resume After Reboot
Vista/Docs

Viewing Frameworks, Controls & Measurements

Your compliance score comes from evaluating your inventory against frameworks — each a set of controls, and each control backed by one or more measurements (the actual rules). The Frameworks browser lets you open any published framework and read its controls and exactly what each one measures, in plain language. Nothing is marked failing without a rule you can see here.

This is the companion to the Algorithm Reference: one explains the cryptographic verdicts, the other explains the compliance verdicts.

Where to find it

Risk & Compliance → Posture → Frameworks tab.

Anyone who can view the Posture page can browse it — no special permission, and you do not need to have activated a framework to read its controls and measurements.

What you can do

My frameworks vs. all published

The browser opens on My frameworks — the frameworks you've activated, which are the ones producing your posture score. Each card shows the framework's score, control count, and how many controls are failing.

Switch to All published to explore the entire catalogue. Frameworks you haven't activated still show a preview score — what you would score against them today, given your current inventory — so you can see where you'd stand before deciding to activate.

Open a framework to read its controls

Click any framework to open its control list. Each control shows its identifier, title, and baseline severity, and is flagged when it's cryptography-related.

Expand a control to see how it's measured

Expand a control to read:

  • its description, and
  • how it's measured — each rule written as a sentence, for example:
    • "Passes when RSA key size is at least 2,048 bits."
    • "Flags any certificate signature algorithm matching the pattern sha1."
    • "Passes when certificate validity is at most 398 days."

If a control has no rule configured, it says so (and passes by default).

Why this matters

A compliance score is only trustworthy if you can see what's behind it. The Frameworks browser turns "you're at 72%" into "here are the controls, and here is the exact rule each one applies" — so you can judge a finding, prioritize remediation, and explain your posture to an auditor.

Frameworks, controls, and measurements are authored centrally by platform administrators (or, for your own internal standards, via Settings → Policies → Custom Policies in the Enterprise edition). The Frameworks browser is read-only — it's for understanding what you're measured against.

← Fortinet Device Interrogation GCP Cloud Resource Discovery →

View source on GitHub · Published from 470d8ee

On this page
  • Where to find it
  • What you can do
  • My frameworks vs. all published
  • Open a framework to read its controls
  • Expand a control to see how it's measured
  • Why this matters
VISTASecurity

Vista Platform is a self-hosted cryptographic system of record for continuous discovery, evaluation, action, and proof.

Vista Platform

How it works
Governance
Post-Quantum
Core, Enterprise & MSP
Try Core

Resources

About
Insights
Documentation
Release status
GitHub ↗
info@vistasecurity.io
Join the mailing list

© 2026 Lakeshore Labs LLC. Vista Security is a brand of Lakeshore Labs LLC. All rights reserved.