The Swif.ai Compliance Center is your centralized workspace for managing device security, enforcing policies, and tracking compliance across frameworks like NIS2, NIST, SOC 2, ISO 27001, HIPAA, and CIS.
It provides real-time visibility into your organization’s compliance posture while automating the enforcement of critical security controls across all managed devices.
What is the Compliance Center?
The Compliance Center brings together:
Device security controls
Compliance frameworks
Real-time monitoring
Automated enforcement
…into a single, unified dashboard.
Instead of manually tracking compliance requirements, Swif continuously evaluates your devices and ensures they meet security standards—helping you stay audit-ready at all times.
Frameworks Snapshot
The Frameworks Snapshot widget gives you an instant overview of your compliance status across multiple frameworks.
You can track:
Overall completion % per framework
Current status (On Track / At Risk)
Number of issues detected
Supported frameworks include:
This allows IT and security teams to quickly understand where they stand and prioritize remediation.
Compliance Controls
Compliance is enforced through device-level controls, each mapped to one or more frameworks.
Key Control Categories
Swif organizes controls into logical groups such as:
Access & Authentication
ACC-1 – Unique user accounts
AUTH-1 – Strong authentication (password + MFA)
LOGIN-1 – Login window configuration
Data Protection
ENC-1 – Full-disk encryption
USB-1 – Removable media restrictions
Endpoint Security
MAL-1 – Anti-malware enforcement
PATCH-1 – OS updates and patching
Device Management
INV-1 – Device inventory and enrollment
Advanced CIS-Based Controls
Additional controls aligned with CIS benchmarks include:
AAC-1 / SAC-1 – Account & system access controls
BSC-1 / MSC-1 – Baseline system configurations
FDC-1 – Firewall configuration
LSC-1 – Logging and system monitoring
DRC-1 – Data recovery and backup controls
SCC-1 / TSC-1 / SSC-1 – System and service protections
ICC-1 / CCC-1 – Configuration consistency and change control
HCD-1 – Hardening configurations (e.g., disabling risky macOS features)
Each control includes:
Description of the requirement
Enforcement mechanism (policy/script)
Compliance mappings (e.g., NIST, CIS, ISO)
Status (Completed, Not Started, Incomplete)
Here’s an updated section you can append into your existing article (or replace the “Advanced CIS-Based Controls” section). It’s structured to match your Help Center style and clearly introduces all the new CIS Level 1 & Level 2 controls.
CIS Benchmark Controls (Level 1 & Level 2)
Swif.ai supports CIS Benchmarks (Level 1 and Level 2) to help organizations enforce secure device configurations aligned with industry best practices.
These controls focus on system hardening, access restrictions, logging, and attack surface reduction across macOS devices.
System Configuration & Hardening
MSI-1 – Menu bar system indicators (Wi-Fi, Bluetooth visibility)
SIP-1 – System Integrity Protection enforcement
PEC-1 – Power and energy security settings (disable network wake features)
HCD-1 – Disable hot corners that bypass session lock
FDC-1 – File system protections (file extensions visibility, home folder security)
CCC-1 – Configuration and certificate controls
SCC-1 – Secure system configuration (sudo timeout, privilege restrictions)
TSC-1 – Time synchronization for audit consistency
These controls ensure devices are hardened against misconfiguration and local bypass techniques.
Account & Access Controls
AAC-1 – Account security (disable guest account, root login restrictions)
ASC-1 – Application and system service restrictions (Siri, AirDrop, Handoff)
ICC-1 – Interface controls (limit system features like Spotlight or Game Center)
SAC-1 – Sharing and remote access controls (screen sharing, SMB, AirPlay)
LSC-1 – Lock screen configuration and session security
These controls reduce unauthorized access and enforce least privilege principles.
Network & Data Protection
CNC-1 – Cellular and network configuration controls
MAC-1 – Managed application data separation
AWC-1 – Apple Watch unlock restrictions
USB-1 – Removable media control (from core controls)
These policies help prevent data exfiltration and unauthorized device interactions.
Logging, Monitoring & Auditing
SSC-1 – Security services (audit logging, firewall logging, Gatekeeper)
ALC-1 – Advanced logging configuration and retention
MVC-1 – MDM enrollment verification (User Approved MDM)
These controls ensure auditability and support forensic investigations.
Backup, Recovery & Diagnostics
BSC-1 – Backup security (e.g., encrypted Time Machine backups)
DRC-1 – Diagnostic reporting controls
These controls protect sensitive data and reduce unintended data exposure.
Performance & Optimization Controls
CCD-1 – Content caching configuration
While not directly security-critical, these controls help reduce unnecessary services that may introduce risk.
CIS Level 1 vs Level 2
CIS Level 1
Designed for usability and security balance. Recommended for most organizations.CIS Level 2
More restrictive and security-focused. Intended for high-risk or regulated environments.
Swif.ai automatically maps controls to the appropriate level and allows you to track compliance across both.
How CIS Controls Work in Swif
Each CIS control:
Is mapped to CIS Level 1 and/or Level 2
Contributes to your Frameworks Snapshot score
Can be enforced via Swif policy templates
Is continuously monitored for compliance drift
This allows your team to:
Identify gaps instantly
Apply recommended policies with one click
Maintain continuous compliance without manual audits
Control Status & Lifecycle
Each control progresses through a lifecycle:
Not Started – Control not yet enforced
In Progress – Policy applied but not fully compliant
Completed – Fully enforced across devices
Incomplete – Devices are out of compliance
Swif continuously monitors device state and updates status in real time.
Smart Policy Enforcement
All controls are powered by Swif’s policy engine, which allows you to:
Automatically apply controls to device groups
Enforce configurations across Mac, Windows, Linux, iOS/iPadOS, and Android
Remediate non-compliant devices instantly
Customize policies for your organization
This ensures a consistent security posture without manual intervention.
Filtering & Organization
The Compliance Center includes powerful tools to manage controls:
Filter by framework, status, or category
Sort controls by priority or completion
Search for specific controls
Toggle between:
Organization Controls
Device Group Controls
Custom Controls
You can create your own compliance controls using:
This is useful for:
Internal security requirements
Industry-specific policies
Advanced configurations beyond standard frameworks
Custom Controls in Framework Scoring
Custom controls can now be included in framework scoring, allowing your organization-specific controls to contribute directly to your compliance percentages in the Frameworks Snapshot.
This means custom controls aren't just documentation—they actively count toward your compliance posture alongside system default controls.
Adding a Framework Target
To include a custom control in framework scoring:
Navigate to Organization Settings → Compliance tab.
Expand a custom control card (or create one via "+ Create Compliance Control").
In the Framework scoring section, click "+ Add Framework Target".
Select a framework from the dropdown:
NIS 2
NIST 800-53
SOC 2
ISO/IEC 27001:2022
HIPAA
CIS Level 2
Once added, select one or more categories specific to that framework (e.g., "System Protection Integrity" for CIS, or "Identity Authentication" for CIS Level 1).
Selected categories appear as removable tags. You can add multiple categories per framework.
Mapping to Multiple Frameworks
A single custom control can be mapped to multiple frameworks simultaneously. Each framework row has its own independent category selection and can be removed without affecting the others.
Example: A custom encryption control could be mapped to both SOC 2 (under Data Protection) and ISO 27001 (under Cryptography) at the same time.
Removing a Framework Target
Hover over the 🗑 icon on any framework row to see the "Remove framework target" tooltip. Clicking it removes the entire mapping—the framework will return to the dropdown and the custom control will no longer contribute to that framework's scoring.
How It Appears in Framework Snapshot
Once mapped, custom controls appear in the Framework Snapshot under their assigned category with:
A "Custom" badge in the new Source column (system default controls show a "System Default" badge)
Their compliance percentage contributing to the category's overall score
An updated control count in the category header
Column order in Framework Snapshot:
Control ID → Control Benchmark → Source → Compliance
This gives you full visibility into which controls are built-in and which are organization-specific, while ensuring both contribute equally to your compliance posture.
This covers all the functionality from ST-8255 in a customer-friendly format. You can paste it directly after the existing custom controls paragraph, or create a new H2 section wherever it fits best in your article layout.
Continuous Compliance & Audit Readiness
Swif.ai ensures that compliance is not a one-time effort but an ongoing process:
Continuous monitoring of device posture
Automatic drift detection
Real-time reporting for audits
Integration with tools like Vanta, Drata, and Secureframe
This eliminates manual evidence collection and simplifies audits.
Summary
The Compliance Center helps you:
✅ Monitor compliance across frameworks
✅ Enforce security policies automatically
✅ Track device-level compliance in real time
✅ Stay audit-ready without manual effort





