Summary
The finding-list schema (now including Intune columns and a Filter column) still has no dedicated column for a framework reference, rationale or CVE. Cross-framework mapping (e.g. CIS ID -> ISO 27001 -> NIS2) and the justification of recommended values must be maintained externally.
Affected files
All lists. Header example:
ID,Category,Name,Method,MethodArgument,RegistryPath,RegistryItem,RegistryPathIntune,RegistryPathDCP,RegistryItemIntune,ClassName,Namespace,Property,DefaultValue,DefaultValueIntune,RecommendedValue,RecommendedValueIntune,Operator,OperatorIntune,Severity,Filter
Recommendation
Add an optional Reference/Rationale column so each finding can carry its source (benchmark section, CVE, vendor doc), improving auditability and threat traceability.
Summary
The finding-list schema (now including Intune columns and a
Filtercolumn) still has no dedicated column for a framework reference, rationale or CVE. Cross-framework mapping (e.g. CIS ID -> ISO 27001 -> NIS2) and the justification of recommended values must be maintained externally.Affected files
All lists. Header example:
Recommendation
Add an optional
Reference/Rationalecolumn so each finding can carry its source (benchmark section, CVE, vendor doc), improving auditability and threat traceability.