Onam Security

Compliance Coverage

Compliance coverage answers a question a framework score cannot: how much of this framework can Onam actually assess, and what is left for you?

Score versus coverage

A compliance score says what proportion of assessed controls pass. Coverage says what proportion of the framework's controls were assessed at all. Reporting the first without the second is how a framework with a third of its controls unmapped shows a reassuring score.

The view reports both: framework assessment scores and control coverage.

Why a control might not be automatically assessed

ReasonWhat it means
Requires an agentThe control is evaluated at host level, not through a cloud API
Hardware-levelPhysical or hardware controls no remote collector can reach
Process controlThe control is about a documented process, not a configuration
Not applicableThe control's technology is not present in this estate

Controls in the first three groups are classified as manual rather than reported as passing. A control nothing checked is never scored as if it passed.

Collection method

Every control records whether it is collected via API or requires an agent. This is the honest version of coverage: it tells an auditor exactly which assertions are continuously verified and which rest on a documented process.

Coverage across frameworks

Onam maps 78 frameworks. Coverage varies between them — a cloud-native benchmark maps almost entirely to automated checks, while a broad control framework like NIST 800-53 has substantial process content that no scanner can assess. The coverage view makes that difference visible per framework instead of averaging it away.

Related: Compliance for the framework list and evidence export.