Skip to main content

Compliance Center Overview

The Swif.ai Compliance Center is your centralized workspace for managing device security, enforcing policies, and tracking compliance across frameworks like NIS2, NIST, SOC 2, ISO 27001, HIPAA, and CIS.

It provides real-time visibility into your organization’s compliance posture while automating the enforcement of critical security controls across all managed devices.


What is the Compliance Center?

The Compliance Center brings together:

  • Device security controls

  • Compliance frameworks

  • Real-time monitoring

  • Automated enforcement

…into a single, unified dashboard.

Instead of manually tracking compliance requirements, Swif continuously evaluates your devices and ensures they meet security standards—helping you stay audit-ready at all times.


Frameworks Snapshot

The Frameworks Snapshot widget gives you an instant overview of your compliance status across multiple frameworks.

You can track:

  • Overall completion % per framework

  • Current status (On Track / At Risk)

  • Number of issues detected

Supported frameworks include:

  • NIS2

  • NIST 800-53

  • SOC 2

  • ISO/IEC 27001

  • HIPAA

  • CIS Benchmarks (Level 1 & Level 2)

This allows IT and security teams to quickly understand where they stand and prioritize remediation.


Compliance Controls

Compliance is enforced through device-level controls, each mapped to one or more frameworks.

Key Control Categories

Swif organizes controls into logical groups such as:

Access & Authentication

  • ACC-1 – Unique user accounts

  • AUTH-1 – Strong authentication (password + MFA)

  • LOGIN-1 – Login window configuration

Data Protection

  • ENC-1 – Full-disk encryption

  • USB-1 – Removable media restrictions

Endpoint Security

  • MAL-1 – Anti-malware enforcement

  • PATCH-1 – OS updates and patching

Device Management

  • INV-1 – Device inventory and enrollment

Advanced CIS-Based Controls

Additional controls aligned with CIS benchmarks include:

  • AAC-1 / SAC-1 – Account & system access controls

  • BSC-1 / MSC-1 – Baseline system configurations

  • FDC-1 – Firewall configuration

  • LSC-1 – Logging and system monitoring

  • DRC-1 – Data recovery and backup controls

  • SCC-1 / TSC-1 / SSC-1 – System and service protections

  • ICC-1 / CCC-1 – Configuration consistency and change control

  • HCD-1 – Hardening configurations (e.g., disabling risky macOS features)

Each control includes:

  • Description of the requirement

  • Enforcement mechanism (policy/script)

  • Compliance mappings (e.g., NIST, CIS, ISO)

  • Status (Completed, Not Started, Incomplete)

Here’s an updated section you can append into your existing article (or replace the “Advanced CIS-Based Controls” section). It’s structured to match your Help Center style and clearly introduces all the new CIS Level 1 & Level 2 controls.


CIS Benchmark Controls (Level 1 & Level 2)

Swif.ai supports CIS Benchmarks (Level 1 and Level 2) to help organizations enforce secure device configurations aligned with industry best practices.

These controls focus on system hardening, access restrictions, logging, and attack surface reduction across macOS devices.

System Configuration & Hardening

  • MSI-1 – Menu bar system indicators (Wi-Fi, Bluetooth visibility)

  • SIP-1 – System Integrity Protection enforcement

  • PEC-1 – Power and energy security settings (disable network wake features)

  • HCD-1 – Disable hot corners that bypass session lock

  • FDC-1 – File system protections (file extensions visibility, home folder security)

  • CCC-1 – Configuration and certificate controls

  • SCC-1 – Secure system configuration (sudo timeout, privilege restrictions)

  • TSC-1 – Time synchronization for audit consistency

These controls ensure devices are hardened against misconfiguration and local bypass techniques.

Account & Access Controls

  • AAC-1 – Account security (disable guest account, root login restrictions)

  • ASC-1 – Application and system service restrictions (Siri, AirDrop, Handoff)

  • ICC-1 – Interface controls (limit system features like Spotlight or Game Center)

  • SAC-1 – Sharing and remote access controls (screen sharing, SMB, AirPlay)

  • LSC-1 – Lock screen configuration and session security

These controls reduce unauthorized access and enforce least privilege principles.

Network & Data Protection

  • CNC-1 – Cellular and network configuration controls

  • MAC-1 – Managed application data separation

  • AWC-1 – Apple Watch unlock restrictions

  • USB-1 – Removable media control (from core controls)

These policies help prevent data exfiltration and unauthorized device interactions.

Logging, Monitoring & Auditing

  • SSC-1 – Security services (audit logging, firewall logging, Gatekeeper)

  • ALC-1 – Advanced logging configuration and retention

  • MVC-1 – MDM enrollment verification (User Approved MDM)

These controls ensure auditability and support forensic investigations.

Backup, Recovery & Diagnostics

  • BSC-1 – Backup security (e.g., encrypted Time Machine backups)

  • DRC-1 – Diagnostic reporting controls

These controls protect sensitive data and reduce unintended data exposure.

Performance & Optimization Controls

  • CCD-1 – Content caching configuration

While not directly security-critical, these controls help reduce unnecessary services that may introduce risk.

CIS Level 1 vs Level 2

  • CIS Level 1
    Designed for usability and security balance. Recommended for most organizations.

  • CIS Level 2
    More restrictive and security-focused. Intended for high-risk or regulated environments.

Swif.ai automatically maps controls to the appropriate level and allows you to track compliance across both.

How CIS Controls Work in Swif

Each CIS control:

  • Is mapped to CIS Level 1 and/or Level 2

  • Contributes to your Frameworks Snapshot score

  • Can be enforced via Swif policy templates

  • Is continuously monitored for compliance drift

This allows your team to:

  • Identify gaps instantly

  • Apply recommended policies with one click

  • Maintain continuous compliance without manual audits


Control Status & Lifecycle

Each control progresses through a lifecycle:

  • Not Started – Control not yet enforced

  • In Progress – Policy applied but not fully compliant

  • Completed – Fully enforced across devices

  • Incomplete – Devices are out of compliance

Swif continuously monitors device state and updates status in real time.

Smart Policy Enforcement

All controls are powered by Swif’s policy engine, which allows you to:

  • Automatically apply controls to device groups

  • Enforce configurations across Mac, Windows, Linux, iOS/iPadOS, and Android

  • Remediate non-compliant devices instantly

  • Customize policies for your organization

This ensures a consistent security posture without manual intervention.

Filtering & Organization

The Compliance Center includes powerful tools to manage controls:

  • Filter by framework, status, or category

  • Sort controls by priority or completion

  • Search for specific controls

  • Toggle between:

    • Organization Controls

    • Device Group Controls


Custom Controls

You can create your own compliance controls using:

This is useful for:

  • Internal security requirements

  • Industry-specific policies

  • Advanced configurations beyond standard frameworks

Custom Controls in Framework Scoring

Custom controls can now be included in framework scoring, allowing your organization-specific controls to contribute directly to your compliance percentages in the Frameworks Snapshot.

This means custom controls aren't just documentation—they actively count toward your compliance posture alongside system default controls.

Adding a Framework Target

To include a custom control in framework scoring:

  1. Navigate to Organization Settings → Compliance tab.

  2. Expand a custom control card (or create one via "+ Create Compliance Control").

  3. In the Framework scoring section, click "+ Add Framework Target".

  4. Select a framework from the dropdown:

    • NIS 2

    • NIST 800-53

    • SOC 2

    • ISO/IEC 27001:2022

    • HIPAA

    • CIS Level 2

  5. Once added, select one or more categories specific to that framework (e.g., "System Protection Integrity" for CIS, or "Identity Authentication" for CIS Level 1).

Selected categories appear as removable tags. You can add multiple categories per framework.

Mapping to Multiple Frameworks

A single custom control can be mapped to multiple frameworks simultaneously. Each framework row has its own independent category selection and can be removed without affecting the others.

Example: A custom encryption control could be mapped to both SOC 2 (under Data Protection) and ISO 27001 (under Cryptography) at the same time.

Removing a Framework Target

Hover over the 🗑 icon on any framework row to see the "Remove framework target" tooltip. Clicking it removes the entire mapping—the framework will return to the dropdown and the custom control will no longer contribute to that framework's scoring.

How It Appears in Framework Snapshot

Once mapped, custom controls appear in the Framework Snapshot under their assigned category with:

  • A "Custom" badge in the new Source column (system default controls show a "System Default" badge)

  • Their compliance percentage contributing to the category's overall score

  • An updated control count in the category header

Column order in Framework Snapshot:

Control ID → Control Benchmark → Source → Compliance

This gives you full visibility into which controls are built-in and which are organization-specific, while ensuring both contribute equally to your compliance posture.

This covers all the functionality from ST-8255 in a customer-friendly format. You can paste it directly after the existing custom controls paragraph, or create a new H2 section wherever it fits best in your article layout.

Continuous Compliance & Audit Readiness

Swif.ai ensures that compliance is not a one-time effort but an ongoing process:

  • Continuous monitoring of device posture

  • Automatic drift detection

  • Real-time reporting for audits

  • Integration with tools like Vanta, Drata, and Secureframe

This eliminates manual evidence collection and simplifies audits.


Summary

The Compliance Center helps you:

  • ✅ Monitor compliance across frameworks

  • ✅ Enforce security policies automatically

  • ✅ Track device-level compliance in real time

  • ✅ Stay audit-ready without manual effort


Did this answer your question?