Horizon governance, risk, and compliance

Kestrel for Horizon

Framework-mapped cloud benchmarks, applied directly to Horizon.

Kestrel for Horizon dashboard showing framework-mapped cloud benchmark results

Map cloud posture into the compliance workflow

  • Horizon GRC
  • Microsoft 365
  • AWS
  • Azure
  • Google Cloud

The benchmark and assessment already speak the same language.

Kestrel for Horizon runs cloud benchmarks that are directly mapped to framework requirements, then applies the results where compliance teams score requirements and manage risk.

Challenge01

Generic findings do not map cleanly

A cloud configuration finding may support a framework requirement, but generic scanner output rarely carries the direct provider and requirement mapping an assessment needs.

Challenge02

Assessment results are re-entered

Teams often review scan results separately, then manually update requirement scores, compliance statuses, and notes inside the assessment.

Challenge03

Negative results stop at the scan

Failed benchmark checks can remain technical findings instead of becoming governed risks with ownership, treatment, and review in Horizon GRC.

From mapped scan to completed requirement.

Use Kestrel infrastructure to run the right benchmark, import its results into the matching Horizon assessment nodes, and decide how those results affect compliance and risk.

01

Run directly mapped benchmarks

Use benchmark definitions directly mapped to a specific frameworks and cloud providers.

Start with the requirement map

02

Execute with Kestrel infrastructure

Run the mapped checks through Kestrel across supported Microsoft Azure, Microsoft 365, AWS, and Google Cloud environments.

Use one cloud scan foundation

03

Pull results into requirement nodes

Select a Horizon project and Compliance Assessment, preview the mapping, and apply Kestrel results directly to the framework requirements they evaluate.

Skip manual result entry

04

Optionally update score and compliance

Choose whether imported results should set the requirement node score and compliance status, including whether existing statuses should be updated.

Accelerate assessment completion

05

Move negative results into risk

Bring failed Kestrel results directly into the Horizon GRC Risk Registry for ownership, analysis, acceptance, treatment, and ongoing review.

Turn failures into governed risk

Run the scan. Apply the result. Govern the risk.

Replace manual assessment updates with a direct path from a framework-mapped Kestrel benchmark to Horizon requirement nodes and the Risk Registry.

01

Select

Choose a benchmark already mapped to the target compliance framework and cloud provider combination.

02

Scan

Run the benchmark against the connected environment using the existing Kestrel scan infrastructure.

03

Apply

Preview the direct mapping and pull results into the matching Compliance Assessment requirement nodes, with optional score and status updates.

04

Escalate

Send negative results to the Horizon GRC Risk Registry when a failed requirement needs formal risk ownership and treatment.

Kestrel for Horizon dialog for applying mapped cloud findings to compliance assessment requirements

Complete cloud-backed assessments faster.

Pull mapped results into an assessment, optionally update requirement scoring and compliance, and move failed results into risk without rebuilding the work by hand.

  • Run cloud checks already mapped to framework requirements
  • Pull scan results directly into assessment requirement nodes
  • Optionally update node scores and compliance status
  • Complete cloud-backed assessments with less manual work
  • Bring negative findings into the Horizon Risk Registry

Apply cloud results where compliance work happens.

See how Kestrel for Horizon runs mapped benchmarks, updates assessment requirements, and routes negative results into risk.

Request a demo