MBSSM

Minimum Baseline Security Standards Manager

Minimum Baseline Security Standards Manager

Set the security baseline once — then prove every asset meets it, control by control.
MBSSM turns your minimum baseline security standard into a living program. Build one catalog of controls across 26 security domains, choose the international standards and national regulations that apply, then assess every asset against it. Partial compliance is scored, evidence is attached, every assessment runs an admin → owner → admin review, and the result is a weighted compliance picture — by asset, by domain and by framework — that you can export as board-ready evidence on demand.

What you get

The outcomes that matter

One baseline, every framework

Author controls once across 26 domains; MBSSM maps each to the standards and regulations you’ve switched on, so one assessment answers many auditors.

Compliance you can defend

Weighted scoring with partial-compliance percentages, attached evidence, and an admin → owner → admin review on every assessment — not a spreadsheet’s say-so.

Gaps, ranked and owned

Every non-compliant control rolls up by asset, by criticality and by department, with per-record CSV / PDF you can hand to the owner who must fix it.

Inside MBSSM

Every module, end to end

MBSSM is organized into the work your team actually does → define the baseline, assess the estate, and prove it. Each module below is part of one integrated platform.

Build the baseline

Baseline Control Catalog
190+ controls across 26 security domains — governance & risk, network, endpoint, data protection, identity, app security, cloud computing, post-quantum cryptography and more — each with severity, rationale and a test procedure.
Applicable Frameworks
Switch on the international standards and national regulations in scope; the choice drives the coverage matrix, the catalog filter and the dashboard everywhere.
Framework Mapping
Every control carries its references into each framework (e.g. ISO 27001 A.x, NIST CSF), so coverage is computed, not claimed.

Inventory & scope

Asset Register
Systems, applications and devices with criticality, data classification, owner, owner-email and department.
Department Scoping
Assets, assessments, findings and users are filterable and visibility-scoped by department, so each team sees its own estate.

Assess & review

Per-Asset Assessments
Assess an asset against its applicable controls; each item is Compliant, Partially Compliant, Non-Compliant, Not Applicable or Not Assessed.
Weighted Compliance & Partial Scoring
A partially-compliant control contributes the assessor’s exact 1–99% (not a flat half), rolling into a weighted compliance percentage per asset and domain.
Evidence Attachments
Upload evidence — documents, images, exports — against each control as the proof behind every result.
Review Workflow
Draft → Submitted → Approved / Returned, routed admin → owner → admin, with reviewer, comment and timestamps recorded.

Find & remediate

Findings Register
Every asset with controls that aren’t compliant, with the breakdown by control criticality (Critical / High / Medium / Low) and the highest severity surfaced.
Per-Record Export
One-click CSV and print-ready PDF for any asset’s non-compliant controls, co-branded with your organization.

See & prove

Framework Coverage Matrix
How the live control set covers each in-scope framework, by domain and percentage.
Live Dashboard
Compliance %, results by domain and by criticality, frameworks in scope, assessment status by department, and open-findings counts — every tile clickable.
Branded CSV & PDF Reporting
Export any register or report carrying your organization’s name and logo alongside the TDSPEE | MBSSM mark and export date.
Immutable Activity Log
Every change, sign-in, authorization failure and export recorded with who, what, when, from where and the outcome.

Operate & secure

User Management & Directory Sync
Local accounts plus Active Directory / LDAP integration: connect, fetch users (email, title, department) and choose who to onboard and at what role.
Platform Certificate
Generate a CSR in-platform and install the CA-signed certificate; HTTPS reloads without a restart.
Organization Branding
Your name and logo in the sidebar and on every PDF / CSV export.
Role & License Control
Administrator, Auditor and Assessor profiles with department-scoped visibility, behind a time-bound platform license.

How it works

From baseline to evidence

  1. 01

    Define

    Curate the baseline catalog and switch on the international standards and national regulations that apply.
  2. 02

    Register

    Add the assets in scope with owner, criticality, classification and department.
  3. 03

    Assess

    Score each asset’s controls, attach evidence, and route the assessment owner → admin for review.
  4. 04

    Prove

    Watch compliance roll up by asset, domain and framework; export evidence and drive findings to closure — all on an immutable log.

Coverage

One baseline catalog, mapped to 24 frameworks across international standards and GCC regulations

International standards & frameworks
ISO/IEC 27001NIST CSFNIST SP 800-53 Rev. 5CIS Controls v8.1OWASP ASVSSOC 2PCI DSSSWIFT CSCFCSA Cloud Controls MatrixISO/IEC 42001 (AI)NIST AI RMFNERC CIPHIPAAGDPRPDPL
GCC & regional regulations
Saudi NCA ECCSAMA CSFUAE IAS (NESA / SIA)Central Bank of Bahrain CSFCentral Bank of Jordan CSFOman CSRFKuwait CITRAIraq National Cybersecurity FrameworkSyria National Cybersecurity Framework

26 security domains from governance & third-party risk through cloud computing and post-quantum cryptography — every control mapped to the frameworks you’ve switched on.

Added value

The value it creates

A control catalog is the mechanism. This is what proving every asset meets the baseline is worth to the business.

One baseline

Define “secure enough” once

A single catalog of minimum controls replaces per-team interpretation — every asset is measured against exactly the same bar.

Honest scoring

Partial credit, real picture

Weighted partial scoring shows true posture by asset, domain and framework — not a misleading pass/fail tick-box.

Evidence attached

Prove it, don’t assert it

Every control state carries its evidence and an admin → owner → admin review, so the score withstands scrutiny.

Own the gaps

Close findings on a schedule

Gaps become owned findings with due dates, turning a one-off assessment into a programme that measurably improves.

Regulatory fit

Where MBSSM fits your obligations

The standards your baseline must answer to — and exactly how MBSSM helps you satisfy each.

ISO/IEC 27001:2022International

Maps the baseline to all 93 Annex A controls and reports coverage as evidenced state, not intent.

NCA ECCKSA

Assesses assets against the Essential Cybersecurity Controls and exports the regulator’s evidence.

SAMA CSFKSA

Scores the baseline against the financial-sector framework, domain by domain.

CIS Controls · BenchmarksInternational

Anchors the catalog to CIS safeguards and hardening benchmarks for each platform.

NIST CSF 2.0International

Rolls control state up to Govern, Identify, Protect, Detect, Respond and Recover.

PCI-DSS v4.0International

Tracks the baseline controls that underpin the cardholder-data environment.

UAE IA StandardsUAE

Covers the national information-assurance controls expected of UAE entities.

Risk mitigation

The risk it takes off the table

“We’re compliant” means little without evidence per asset. Here is your posture without MBSSM — and with it.

Without MBSSMWith MBSSM

“Baseline security” means something different to every team.

One catalog of minimum controls applied to every asset.

Compliance is a pass/fail tick-box that hides real weakness.

Weighted partial scoring that reflects true posture.

Claims of compliance have no evidence behind them.

Every control state carries attached evidence and a review.

Each new framework means starting the assessment over.

Assess once, report against two dozen frameworks from the same data.

Gaps are noted in a report and quietly forgotten.

Owned findings with due dates and scheduled re-assessment.

Deployment & security

Yours to run, built to defend

Every Televestigo platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.

On-premise or sovereign cloud

Runs inside your estate and owned by you; assessment evidence never leaves your control.

Three roles, department-scoped

Administrator, Auditor and Assessor, with assessment and finding visibility scoped by department.

Hardened by default

Directory bind secret encrypted at rest, CA-signed TLS through an in-platform CSR, strict security headers, and a time-bound license gate.

Evidenced & exportable

An immutable activity log over every action, with CSV and print-ready PDF carrying your organization branding.

See MBSSM in your environment

Tell us about your systems and obligations. We’ll come back with a clear, practical view of where you stand → and what we’d do next.