| Identity lifecycle |
Do joiner, mover, and leaver triggers, owners, timing, systems, approvals, exceptions, and escalation address unauthorized access risk? |
HR integration, directory workflow, application scope, roles, schedules, service accounts, and ticket fields are configured and assigned. |
Period population reconciled to identity stores; selected or complete events show timely action, approvals, exceptions, and follow-up. |
Inspection, full-population analytics, sampling, reperformance, timestamp comparison. |
A workflow screenshot without evidence that all identity stores receive complete events. |
Could local, cloud, privileged, contractor, or application accounts be absent? |
| Privileged access |
Are privilege grants, reviews, emergency access, session controls, and revocation rules capable of limiting powerful access? |
Roles, vaults, MFA, approval paths, break-glass accounts, session logging, and reviewer assignments exist. |
Grants and reviews during the period are authorized, timely, independent, complete, and linked to actual group membership and use. |
Configuration comparison, inspection, sampling, negative testing, analytics. |
MFA enabled for administrators while unmanaged local or service accounts bypass it. |
Does effective privilege match the reviewed entitlement? |
| Firewall change control |
Does the process require business need, security review, testing, approval, rollback, expiration, and independent verification? |
Ticket workflow, device logging, administrators, rule review, emergency path, and configuration backup are enabled. |
Changes reconcile between tickets and devices; required approvals, testing, peer review, and expiry operated throughout the period. |
Inspection, reconciliation, sampling, reperformance, configuration diff. |
Approved tickets with out-of-band changes not captured by the population. |
Can device changes occur outside the governed workflow? |
| Vulnerability remediation |
Do discovery, ownership, prioritization, deadlines, exception, validation, and escalation address exposure risk? |
Scanner coverage, credentials, asset linkage, service levels, ownership, tickets, exception workflow, and rescan process exist. |
Due findings are remediated or validly accepted; closures are independently validated; overdue and repeated failures escalate. |
Coverage validation, analytics, sampling, reperformance, inspection. |
A falling dashboard count caused by assets leaving scan scope. |
Does closure mean the weakness was fixed on the same affected asset? |
| Endpoint hardening |
Is the approved baseline capable of reducing defined threats across supported endpoint classes? |
Policies, assignments, inheritance, exclusions, agents, enforcement, monitoring, and exception processes are configured. |
Period evidence and direct checks show policies reached active devices, deviations were detected, and exceptions were approved and resolved. |
Configuration comparison, endpoint validation, analytics, sampling, negative testing. |
A management console reporting compliance while stale or disconnected devices are excluded. |
Does the population include inactive, remote, acquired, and unsupported devices? |
| Security logging |
Do source selection, event requirements, transport, time synchronization, retention, detection, triage, and escalation meet monitoring objectives? |
Sources connect, parsers work, retention and access are configured, alerts route to responsible analysts, and clocks synchronize. |
Required sources remained available; alerts fired, were triaged, escalated, and closed; failures were detected and corrected. |
Positive/negative test, source reconciliation, inspection, analytics, observation. |
A SIEM dashboard showing ingestion without validating required event types or response. |
Would a material source failure be noticed promptly? |
| Backup and recovery |
Do scope, frequency, immutability, encryption, retention, monitoring, restore objectives, and escalation address recovery risk? |
Jobs, repositories, isolation, credentials, monitoring, restore procedures, ownership, and test schedules exist. |
Jobs ran across the period, failures were resolved, protected systems reconcile to scope, and representative restores met approved objectives. |
Inspection, observation, restore reperformance, analytics, sampling. |
Successful backup jobs treated as proof that systems can be restored. |
Can critical services be recovered within approved time and data-loss limits? |
| Cloud security guardrails |
Do preventive policies and detective rules address prohibited public exposure, privilege, encryption, regions, and configuration drift? |
Policies are deployed to intended accounts/subscriptions, exceptions are governed, logging works, and remediation routes exist. |
Guardrails evaluated resources throughout the period; violations were blocked or detected; exceptions and remediation were handled. |
Configuration comparison, safe negative test, analytics, inspection, reperformance. |
A policy defined centrally but not assigned to acquired or development environments. |
Which accounts, regions, resource types, and exception paths are outside enforcement? |
| Incident response |
Do roles, severity, communications, evidence preservation, legal/privacy escalation, containment authority, and recovery criteria address credible scenarios? |
Plan, contact paths, tooling, playbooks, access, logging, training, and exercise schedules exist. |
Incidents and exercises show timely classification, decisions, communication, evidence handling, containment, lessons, and corrective actions. |
Inspection, tabletop observation, record tracing, sampling, reperformance of timelines. |
A current plan with no evidence that responders can access tools or exercise decisions. |
Can the team execute under degraded systems and incomplete information? |