Skip to main content

Automated control test library

A library of customizable tests for proof collected by Hypersync.

Hyperproof provides a library of evidence tests that you can link to your Hypersyncs to automatically test proof as it is collected. For detailed information on how to link tests to a Hypersync, see Using the automated control test library.

Available tests are listed by Hypersync and proof type. If no records are returned in the collected proof, the test result is marked either Failed or Needs review.

ActiveCampaign

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank, and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Aha!

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name and flags groups without a description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value, and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that remain unresolved, revealing aging work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank, and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Ashby

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value, Job Title has a value, and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS

Asset Inventory

Test name

Test description

Test logic

AWS - EC2 Instance Inventory Records Are Complete

Checks that every EC2 instance reported by Systems Manager inventory records an instance ID, host name, IP address, and operating system name and version.

Every record must satisfy: Instance ID has a value, Computer Name has a value, IP Address has a value, Platform has a value, and Platform Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - Systems Manager Managed Instances Report A Healthy Agent

Checks that every inventoried EC2 instance has a management agent installed, reporting a well-formed version, and has not lost its connection to the management service.

Every record must satisfy: Agent Type has a value and Agent Version matches the pattern "^[0-9]{1,6}(\.[0-9]{1,6}){2,3}$" and Instance Status does not equal "ConnectionLost". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Backup Jobs

Test name

Test description

Test logic

RDS and DocumentDB daily backups enabled

Confirm backup Retention Period >= 1 and automated Backups Enabled = true

Every record must satisfy: Backup Job ID has a value and Status equals "COMPLETED". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Bucket Object Lock

Test name

Test description

Test logic

AWS - S3 Bucket Object Lock Enabled With A Default Retention Period

Checks that every S3 bucket has Object Lock enabled with a default retention period configured.

Every record must satisfy: Bucket has a value, Object lock status equals "Enabled," and Retention Period has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Bucket Policy Status

Test name

Test description

Test logic

S3 Bucket Policy Status confirms restricted access

Examine: Bucket policy JSON documents

Every record must satisfy: Bucket has a value, and Policy Type equals "Not Public". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cluster Backup Retention Period

Test name

Test description

Test logic

AWS - Aurora Cluster Backup Retention Meets Minimum

Checks that every Amazon RDS/Aurora cluster in the evidence retains automated backups for at least seven days.

Every record must satisfy: Cluster Identifier has a value, and Cluster Backup Retention Period is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cluster Storage Encrypted

Test name

Test description

Test logic

AWS - Aurora Cluster Storage Encrypted At Rest

Checks that storage encryption is enabled on every Amazon RDS/Aurora cluster listed in the evidence.

Every record must satisfy: Cluster Identifier has a value, and Cluster Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cross-Region Aggregation

Test name

Test description

Test logic

AWS - Security Hub Aggregates Findings From Linked Regions

Confirms Security Hub cross-region finding aggregation is configured and that each linked region is recorded against an aggregation region.

Every record must satisfy: Home Region has a value, and Linked Region has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Findings

Test name

Test description

Test logic

AWS - Security Hub Active Findings Have No Failed Compliance Checks

Flags active Security Hub findings whose compliance check failed and that have not been resolved or suppressed.

A record is marked failed when: Status equals "FAILED" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - Security Hub High And Critical Findings Remediated Within 30 Days

Flags active high and critical Security Hub findings that have gone unresolved for more than 30 days.

A record is marked failed when: Severity is one of "CRITICAL" or "HIGH" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 30. The test passes only if every record passes.

Security Hub Low Findings Remediated Within 180 Days

Flags active LOW severity Security Hub findings older than 180 days that have not been resolved or suppressed.

A record is marked failed when: Severity equals "LOW" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 180. A record is marked failed when: Severity equals "LOW" and Record State equals "ACTIVE" and Workflow Status is empty and Age (Days) is greater than 180. The test passes only if every record passes.

Security Hub Medium Findings Remediated Within 90 Days

Flags active MEDIUM severity Security Hub findings older than 90 days that have not been resolved or suppressed.

A record is marked failed when: Severity equals "MEDIUM" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 90. A record is marked failed when: Severity equals "MEDIUM" and Record State equals "ACTIVE" and Workflow Status is empty and Age (Days) is greater than 90. The test passes only if every record passes.

IAM Password Policy

Test name

Test description

Test logic

AWS - IAM Account Password Policy Enforces A 14 Character Minimum

Checks that each AWS account enforces a custom IAM password policy with a strong minimum length.

Every record must satisfy: Policy equals "Custom password policy" and Minimum password length is 14 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - IAM Account Password Policy Prevents Reuse Of The Last 24 Passwords

Checks that each AWS account's IAM password policy prevents reuse of recent passwords.

Every record must satisfy: Policy equals "Custom password policy" and Count of passwords to remember to prevent reuse has a value and Count of passwords to remember to prevent reuse is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Instance Backup Retention Period

Test name

Test description

Test logic

AWS - RDS Instance Backup Retention Meets Minimum

Checks that every Amazon RDS database instance in the evidence retains automated backups for at least seven days.

Every record must satisfy: Instance Identifier has a value and Instance Backup Retention Period is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Instance Storage Encrypted

Test name

Test description

Test logic

AWS - RDS Instance Storage Encrypted At Rest

Checks that every Amazon RDS database instance in the proof has storage encryption enabled.

Every record must satisfy: Instance Identifier has a value, and Instance Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Integrations Providing Findings

Test name

Test description

Test logic

AWS - Security Hub Findings Integrations Are Identified

Confirms the account has enabled product integrations feeding findings into Security Hub, and that each one is identified by product and vendor.

A record is sent for review when: Name is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Access Keys

Test name

Test description

Test logic

AWS - IAM Active Access Keys Rotated Within 90 Days

Checks that active IAM user access keys have been rotated within the last 90 days.

A record is sent for review when: Creation Time is empty. A record is marked failed when: Status equals "Active" and Creation Time is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - IAM Active Access Keys Unused For 45 Days Are Disabled

Checks that active IAM user access keys which are unused or have never been used are not left enabled.

A record is marked failed when: Status equals "Active" and Last Used Date is more than 45 days in the past. A record is marked failed when: Status equals "Active" and Last Used Date is empty and Creation Time is more than 45 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of ACLs

Test name

Test description

Test logic

AWS - WAF Web ACLs Are Associated With A Protected Resource

Highlights WAF web ACLs that are not associated with any protected resource, so unused or orphaned ACLs get reviewed.

A record is sent for review when: Resources is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - WAF Web ACLs Enforce A Block Default Action

Checks that each WAF web ACL blocks requests by default, so traffic reaches the protected application only by explicit rule.

Every record must satisfy: Default Action equals "Block". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Backup Plans

Test name

Test description

Test logic

AWS - Backup Plans Have Executed At Least Once

Checks that every AWS Backup plan is named and has actually run at least once, so a defined plan is not silently producing no backups.

Every record must satisfy: Backup Plan Name has a value and Last Runtime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS Backup Plans Have Executed Within The Last 35 Days

Flags AWS Backup plans that have not run in the last 35 days, and routes plans that have never run to review.

A record is marked failed when: Last Runtime is more than 35 days in the past. A record is sent for review when: Last Runtime is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Client VPN Endpoints

Test name

Test description

Test logic

AWS - Client VPN Endpoints Use Private Client CIDR Ranges

Checks that each AWS Client VPN endpoint assigns connecting clients addresses from a private, non-internet-routable IP range.

Every record must satisfy: Client CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Configurations

Test name

Test description

Test logic

AWS - Lambda Functions Do Not Run On Deprecated Runtimes

Flags serverless functions running on a vendor-deprecated language runtime.

A record is marked failed when: Runtime matches the pattern "^(nodejs|nodejs4\.3(-edge)?|nodejs6\.10|nodejs8\.10|nodejs(10|12|14|16|18|20)\.x|python2\.7|python3\.[6-9]|ruby2\.[57]|ruby3\.2|java8|go1\.x|provided|provided\.al2|dotnetcore(1\.0|2\.0|2\.1|3\.1)|dotnet(5\.0|6|7))$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - Lambda Functions Have Been Updated Within The Last Year

Flags serverless functions whose code has not been redeployed within the last year.

A record is sent for review when: Last Modified is empty. A record is sent for review when: Last Modified is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Containers

Test name

Test description

Test logic

AWS - ECS Container Instances Are Not Inactive Or Failed Registration

Checks that registered ECS container instances are in a usable, active state.

A record is marked failed when: Status is one of "INACTIVE" or "REGISTRATION_FAILED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - ECS Container Instances Report Host Identity And Docker Engine Version

Checks that registered ECS container instances report the host identity and container runtime details needed to attribute workloads.

Every record must satisfy: EC2 Instance ID has a value and Docker Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of EKS Clusters

Test name

Test description

Test logic

AWS - EKS Clusters Are Healthy And Not Running An End Of Support Kubernetes Version

Checks that each EKS cluster reports status ACTIVE and a Kubernetes version that is still within vendor support. Only ACTIVE passes: a cluster in CREATING, DELETING, PENDING or UPDATING does not evidence a healthy running cluster and is flagged too.

Every record must satisfy: Name has a value and Status equals "ACTIVE" and Kubernetes version has a value and Kubernetes version does not match the pattern "^1\.([0-9]|1[0-9]|2[0-9]|30)([^0-9]|$)". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Groups

Test name

Test description

Test logic

AWS - IAM Groups Avoid Inline Policies And Have Members

Checks that IAM groups grant permissions through managed policies rather than inline policies, and flags groups that have no members.

A record is marked failed when: Inline Policy is true. A record is sent for review when: Users equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM Roles

Test name

Test description

Test logic

AWS - IAM Role Maximum Session Duration Is Not Excessive

Checks that IAM roles do not permit an excessive maximum session duration.

A record is marked failed when: Session Duration matches the pattern "^([89]|1[0-2]) hours". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - IAM Roles Do Not Trust Wildcard Principals

Checks that IAM role trust policies do not allow wildcard principals to assume the role.

A record is marked failed when: Trusted Entities contains "*". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM SAML Providers

Test name

Test description

Test logic

AWS - IAM SAML Provider Metadata Is Not Expired Or Expiring

Checks that SAML identity provider metadata documents in IAM have a valid expiration date and are not expired or close to expiring.

A record is marked failed when: Expiration Time is less than 30 days in the future. A record is sent for review when: Expiration Time is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Images

Test name

Test description

Test logic

AWS - EC2 AMIs Are Not Publicly Shared

Checks that no AWS EC2 machine image owned by the account is shared publicly with all other AWS accounts.

Every record must satisfy: Visibility equals "Private". The test passes only if every record passes. If the proof contains no records, the test is marked passed.

AWS - EC2 AMIs Use EBS-Backed Root Volumes

Checks that every AWS EC2 machine image boots from an EBS-backed root volume, which unlike ephemeral local disk can be encrypted at rest.

Every record must satisfy: Root Device Type equals "ebs". The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Instance IPs

Test name

Test description

Test logic

AWS - EC2 Instances Stopped For More Than 90 Days

Flags EC2 instances that have been sitting in a stopped state for more than 90 days so dormant compute can be reviewed or decommissioned.

A record is sent for review when: State equals "stopped" and State Transition Time is empty. A record is marked failed when: State equals "stopped" and State Transition Time is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - Running EC2 Instances Do Not Expose Public IPv4 Addresses

Flags running EC2 instances that have a public IPv4 address so internet-reachable compute is reviewed and justified.

A record is marked failed when: State equals "running" and Public IP Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Running EC2 Instances Do Not Expose Public IPv6 Addresses

Flags running EC2 instances that carry a globally routable IPv6 address.

A record is marked failed when: State equals "running" and IPv6 Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Instances

Test name

Test description

Test logic

AWS - Aurora Instances Are Attached To A VPC

Checks that Aurora database instances are attached to a VPC.

Every record must satisfy: Instance Identifier has a value and VPC has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - Aurora Instances Report An Available Status

Checks that Aurora database instances report an available operational status.

Every record must satisfy: Instance Identifier has a value and Status equals "Available". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - RDS Instance Inventory Complete And VPC-Attached

Checks that each Amazon RDS database instance record identifies its engine, size and VPC so the database inventory is complete.

Every record must satisfy: Instance Identifier has a value and Engine has a value and Size has a value and VPC has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - RDS Instances Configured For Multi-AZ

Checks that every Amazon RDS database instance in the evidence is deployed with Multi-AZ redundancy.

Every record must satisfy: Instance Identifier has a value and Multi-AZ is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Rule Groups

Test name

Test description

Test logic

AWS - WAF Rule Groups Are Fully Identified In Inventory

Confirms every WAF rule group in the evidence carries a name, an identifier, and a well-formed ARN so the inventory is complete and traceable.

Every record must satisfy: Name has a value and Rule Group ID has a value and Rule Group ARN matches the pattern "^arn:aws[a-z-]*:wafv2:". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Running Instances

Test name

Test description

Test logic

Inventory maintained for EC2, EKS, RDS, Lambda, and more

Examine: Inventory records for infrastructure components

Every record must satisfy: Instance ID has a value and Instance Type has a value and Availability Zone has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Security Groups

Test name

Test description

Test logic

AWS - Default Security Group Denies All Inbound Traffic

Flags any default security group that still carries inbound rules, so unassigned resources cannot inherit permissive network access.

A record is marked failed when: Security Group Name equals "default" and Inbound Rules is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - Security Group Inventory Attributes Are Complete

Checks that every security group records an ID, name, owning account, parent network, and a description explaining its purpose.

Every record must satisfy: Security Group ID has a value and Security Group Name has a value and VPC ID has a value and Description has a value and Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Default Security Group Denies All Outbound Traffic

Flags a VPC default security group that still has outbound rules attached.

A record is marked failed when: Security Group Name equals "default" and Outbound Rules is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Snapshots

Test name

Test description

Test logic

AWS - EBS Snapshots Are Encrypted At Rest

Checks that every block storage snapshot in the report is encrypted at rest and carries a snapshot identifier.

Every record must satisfy: Snapshot ID has a value and Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - EBS Snapshots Completed Successfully

Checks that every block storage snapshot in the report reached a completed state and records the time it was started.

Every record must satisfy: Snapshot ID has a value and Status equals "completed" and Started has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of SSO Users

Test name

Test description

Test logic

AWS - Identity Center SSO Users Carry A User Name And User Id

Checks that every IAM Identity Center SSO user record carries both a user name and a unique user identifier so access reviews can be completed.

Every record must satisfy: User Name has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Subnets

Test name

Test description

Test logic

CIDR ranges reviewed

Examine: CIDR assignments and VPC/subnet allocation documentation

Every record must satisfy: Subnet ID has a value and State equals "available" and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Public/private subnet separation enforced

Checks that every subnet returned carries a subnet id, its parent VPC id and an IPv4 CIDR block, so each subnet in the proof is identifiable and attributable to a VPC. Does not establish that every subnet in the account was collected. Does not determine whether a subnet is public or private: the proof does not expose mapPublicIpOnLaunch or route table associations.

Every record must satisfy: Subnet ID has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Routing tables reviewed

Examine: Route table configurations and change control documentation

Every record must satisfy: Subnet ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

VPC configurations documented per region

Checks that every subnet returned carries a subnet id, its parent VPC id and an IPv4 CIDR block across the collected regions.

Every record must satisfy: Subnet ID has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

AWS - IAM Users With Console Passwords Unused For 90 Days

Flags AWS IAM users whose console password has not been used in the last 90 days so dormant accounts can be reviewed, disabled, or removed.

A record is sent for review when: Password Last Used is empty. A record is marked failed when: Password Last Used is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users with MFA Devices

Test name

Test description

Test logic

AWS - IAM Users Do Not Rely On SMS MFA

Flags AWS IAM users enrolled in SMS text-message MFA, which is weaker than app-based or hardware security key authenticators.

A record is marked failed when: MFA Devices contains "SMS". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS - IAM Users Have An MFA Device Enrolled

Checks that every AWS IAM user in the evidence has at least one multi-factor authentication device enrolled.

Every record must satisfy: MFA equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users with MFA Settings

Test name

Test description

Test logic

MFA enabled for all users with console or privileged access

Confirm MFA is enforced via IAM policies or service control policies (SCPs) for all users with console or privileged access

Every record must satisfy: MFA contains "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Volumes

Test name

Test description

Test logic

AWS - EBS Volumes Are Encrypted At Rest

Checks that every block storage volume in the report is encrypted at rest and records its identifier and lifecycle state.

Every record must satisfy: Volume ID has a value and State has a value and Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of VPCs

Test name

Test description

Test logic

VPC flow logging enabled

Verify that flow logging is enabled for all VPCs and traffic is directed to a secure destination (e.g., CloudWatch, S3)

Every record must satisfy: VPC ID has a value and State equals "available". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Workloads

Test name

Test description

Test logic

AWS - EKS Deployments Have Available Pods And No Unavailable Replicas

Checks that every deployed workload has at least one available pod and reports zero failed replicas at the time evidence was collected.

Every record must satisfy: Name has a value and Pod Count is greater than 0 and Status matches the pattern "(^|[^0-9])0 Failed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - EKS Workloads Are Not Deployed In The Default Namespace

Checks that every Kubernetes workload runs in a purpose-named namespace instead of the default namespace, so resources stay separated and policy can be scoped.

Every record must satisfy: Name has a value and Namespace has a value and Namespace does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Policies & Access Control

Test name

Test description

Test logic

AWS - Lambda Deployment Packages Are Encrypted With A Customer Managed KMS Key

Checks that serverless function deployment packages are encrypted with a customer managed key.

Every record must satisfy: Encryption equals "Yes" and AWS KMS Key has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - Lambda Execution Roles Do Not Use Broadly Privileged Role Names

Flags serverless functions whose execution role name indicates broad or administrative privilege.

A record is sent for review when: IAM Role matches the pattern ":role/.*(Administrator|PowerUser|FullAccess)". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Restore Testing

Test name

Test description

Test logic

AWS - Backup Restore Test Jobs Completed Successfully

Checks that every restore test job run during the reporting period finished in a completed state with a recorded completion time.

Every record must satisfy: Restore Job Id has a value and Status equals "COMPLETED" and Completion Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - Backup Restore Test Validation Did Not Fail

Checks that no restore test job reported a failed or timed-out validation result, so restored data is confirmed usable and not just recoverable.

A record is sent for review when: Validation Status equals "VALIDATING". Every record must satisfy: Restore Job Id has a value and Validation Status is none of "FAILED" or "TIMED_OUT". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Access Control List

Test name

Test description

Test logic

S3 bucket ACLs are private or restrictive

Examine: S3 ACL configurations and AWS Config rules

Every record must satisfy: Grantee ID has a value and Grantee Type equals "CanonicalUser" and Permission has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Encryption

Test name

Test description

Test logic

S3 buckets encrypted at rest using AWS-managed or customer-managed KMS keys

Verifies that S3 buckets are encrypted at rest using AWS-managed or customer-managed KMS keys. Verify that BucketEncryption is enabled and SSEAlgorithm is either aws:kms or AES256.

Every record must satisfy: Bucket has a value and Encryption Key Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Lifecycle Configuration

Test name

Test description

Test logic

AWS - S3 Bucket Lifecycle Rules Are Enabled

Checks that every S3 bucket lifecycle rule in the proof is in an enabled state rather than disabled.

Every record must satisfy: Bucket has a value and Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS - S3 Lifecycle Rules Do Not Expire Current Objects Within 90 Days

Flags S3 lifecycle rules that expire current object versions in fewer than 90 days.

A record is marked failed when: Status equals "Enabled" and Action equals "Expire" and Applies to equals "Current Objects" and Days to Transition is less than 90. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

S3 Bucket Replication

Test name

Test description

Test logic

If used for backup, S3 replication configuration supports contingency

Examine: S3 replication rules and target regions

Every record must satisfy: Bucket has a value and Replication Rule Name has a value and Status equals "Enabled" and Destination Bucket has a value. The test passes if at least 50% of records pass. If the proof contains no records, the test is marked failed.

S3 Bucket Versioning

Test name

Test description

Test logic

S3 bucket versioning configuration documented

Examine: S3 configuration and versioning policy

Every record must satisfy: Bucket has a value and Bucket Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account)

Backup Plan Details

Test name

Test description

Test logic

AWS (Single Account) - Backup Plan Rules Copy To A Secondary Vault

Checks that each backup plan rule copies backups to a secondary vault so a single vault is not the only copy.

Every record must satisfy: Destination Backup Vault ARN has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account) - Backup Plan Rules Target A Vault And Cover Resources

Checks that each backup plan rule names a destination vault and that the plan has at least one resource selection assigned.

Every record must satisfy: Backup Plan Name has a value and Rule Name has a value and Target Backup Vault Name has a value and Backup Selections does not equal "[]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

IAM Password Policy

Test name

Test description

Test logic

AWS IAM Password Policy Enforces Character Complexity

Verifies the account password policy requires uppercase, lowercase, number, and symbol characters (NIST 800-53 Rev5 IA-5(1)). Checks booleanField.requireUppercase/requireLowercase/requireNumbers/requireSymbols.

Every record must satisfy: Require Uppercase is true and Require Lowercase is true and Require Numbers is true and Require Symbols is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS IAM Password Policy Prevents Reuse Of Last 24 Passwords

Verifies the account password policy prevents reuse of at least the previous 24 passwords (NIST 800-53 Rev5 IA-5(1); CIS AWS Foundations 1.9). Checks numberField.passwordReuseCount; an unset reuse count yields NeedsReview at threshold 1.0.

Every record must satisfy: Password Reuse Count is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS IAM Password Policy Requires 14+ Character Minimum Length

Verifies the account password policy enforces a minimum length of at least 14 characters (NIST 800-53 Rev5 IA-5(1); CIS AWS Foundations 1.8). Checks numberField.minPasswordLength.

Every record must satisfy: Minimum Password Length is 14 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

IAM Password Policy Enforces Complexity And Reuse Prevention

CIS AWS 1.9 / NIST 800-53 Rev5 IA-5(1): verify the IAM account password policy requires symbols, numbers, uppercase and lowercase characters, and prevents reuse of the last 24 passwords. Fields: requireSymbols, requireNumbers, requireUppercase, requireLowercase, passwordReuseCount.

Every record must satisfy: Require Symbols is true and Require Numbers is true and Require Uppercase is true and Require Lowercase is true and Password Reuse Count is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Instance Storage Encrypted

Test name

Test description

Test logic

AWS RDS Instances Have Storage Encryption Enabled

Verifies every RDS database instance has storage encryption enabled at rest (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.3.1).

Every record must satisfy: Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Backup Plans

Test name

Test description

Test logic

AWS (Single Account) - Backup Plans Have Executed Within The Last 35 Days

Flags backup plans that have not run in more than 35 days, so gaps in backup coverage are caught before they matter.

A record is marked failed when: Last Execution Date is more than 35 days in the past. A record is sent for review when: Last Execution Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Client VPN Endpoints

Test name

Test description

Test logic

AWS (Single Account) - Client VPN Endpoints Are Documented And Use Private Client CIDR Ranges

Checks that every Client VPN endpoint records a description of its purpose and issues client addresses from a private, non-internet-routable range.

A record is marked failed when: Description is empty. A record is marked failed when: Client CIDR does not match the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of EC2 Assets

Test name

Test description

Test logic

AWS EC2 Instances Report An Active SSM Inventory Agent

Verifies every inventoried EC2 instance has an Active SSM agent so patch and configuration state can be managed and reported (NIST 800-53 Rev5 CM-8/SI-2). Checks textField.instanceStatus equals the display value 'Active'.

Every record must satisfy: Instance Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of EC2 Images

Test name

Test description

Test logic

AWS (Single Account) - EC2 AMIs Are Not Publicly Shared

Verifies no EC2 Amazon Machine Image is shared publicly, which could expose baked-in secrets or data (NIST 800-53 Rev5 AC-3/SC-7). Checks textField.visibility equals the display value 'private'.

Every record must satisfy: Visibility equals "private". The test passes only if every record passes. If the proof contains no records, the test is marked passed.

AWS EC2 AMIs Rebuilt Within The Last Year

Flags AMIs that have not been rebuilt in the last year, since an image bakes in the patch level it was created with.

A record is sent for review when: Creation Date is empty. A record is marked failed when: Creation Date is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of EC2 Running Instances

Test name

Test description

Test logic

AWS (Single Account) - Running EC2 Instances Do Not Expose Public IPv4 Addresses

Flags running EC2 instances that carry a public IPv4 address.

A record is marked failed when: IP Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS EC2 Instances Have Detailed Monitoring Enabled

Verifies each running EC2 instance has detailed CloudWatch monitoring enabled to support continuous monitoring and anomaly detection (NIST 800-53 Rev5 SI-4/AU-12). Checks textField.monitoring equals the display value 'enabled'.

Every record must satisfy: Monitoring equals "enabled". The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of EC2 Security Groups

Test name

Test description

Test logic

EC2 Security Groups Are VPC Scoped And Documented

NIST 800-53 Rev5 CM-8 SC-7: verify every EC2 security group belongs to a VPC (no legacy EC2-Classic) and carries a non-empty description for inventory/attack-surface governance. Fields: vpcID, description.

Every record must satisfy: VPC ID has a value and Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of EC2 Snapshots

Test name

Test description

Test logic

AWS EBS Snapshots Are Encrypted At Rest

Verifies every EBS snapshot is encrypted at rest (NIST 800-53 Rev5 SC-28). Checks booleanField.encryption is true.

Every record must satisfy: Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

AWS EBS Snapshots Completed Successfully

Flags EBS snapshots that did not reach the completed state.

A record is marked failed when: Status equals "error". A record is sent for review when: Status does not equal "completed". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of EC2 Volumes

Test name

Test description

Test logic

AWS EBS Volumes Are Encrypted At Rest

Verifies every EBS volume is encrypted at rest (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.2.1). Checks booleanField.encryption is true.

Every record must satisfy: Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

EC2 EBS Volumes Encrypted At Rest

CIS AWS 2.2.1 / NIST 800-53 Rev5 SC-28: verify every EBS volume is encrypted at rest. Fields: encryption (boolean), id.

Every record must satisfy: Encryption is true and Volume Id has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of EKS Clusters

Test name

Test description

Test logic

AWS (Single Account) - EKS Clusters Are Active And Not Running An End Of Life Kubernetes Version

Confirms each Kubernetes cluster is in an active state and is not running a release that has reached end of life.

Every record must satisfy: Status equals "ACTIVE" and Kubernetes Version has a value and Kubernetes Version does not match the pattern "^1\.([12][0-9]|30)$". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Groups

Test name

Test description

Test logic

AWS IAM Groups Do Not Use Inline Policies

Verifies IAM groups attach managed policies rather than inline policies, supporting least-privilege review and reuse (NIST 800-53 Rev5 AC-6; CIS AWS Foundations 1.15). Checks booleanField.inlinePolicy is false.

Every record must satisfy: Inline Policy is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of IAM Roles

Test name

Test description

Test logic

AWS (Single Account) - IAM Role Maximum Session Duration Is Not Excessive

Flags IAM roles whose maximum session duration is eight hours or longer.

A record is marked failed when: Session Duration matches the pattern "^([89]|1[0-2]) hours". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS (Single Account) - IAM Roles Do Not Trust Wildcard Principals

Flags IAM roles whose trust policy can be assumed by any principal, so overly open role access can be found and corrected.

A record is marked failed when: Trusted Entity contains "*". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM SAML Providers

Test name

Test description

Test logic

AWS (Single Account) - IAM SAML Provider Federation Metadata Is Not Expired

Checks that each SAML identity provider used for federated sign-in has valid metadata that is not expired or expiring within 30 days.

A record is sent for review when: Expiration Time is empty. A record is marked failed when: Expiration Time is less than 30 days in the future. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM Users

Test name

Test description

Test logic

AWS (Single Account) - IAM Console Credentials Unused For More Than 90 Days

Flags IAM users whose console password has not been used in more than 90 days so dormant credentials can be reviewed and disabled.

A record is sent for review when: Password Last Used is empty. A record is marked failed when: Password Last Used is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM Users MFA

Test name

Test description

Test logic

AWS IAM Users Have MFA Enabled

Verifies every IAM user with console access has an MFA device enrolled (NIST 800-53 Rev5 IA-2(1); CIS AWS Foundations 1.10). Checks textField.mfa contains the display value 'MFA Enabled'.

Every record must satisfy: MFA contains "MFA Enabled". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of IAM Users MFA Devices

Test name

Test description

Test logic

AWS (Single Account) - IAM Users Enrolled In Phishing-Resistant MFA

Checks that IAM users are protected by a FIDO security key rather than only SMS or authenticator-app multi-factor methods.

Every record must satisfy: MFA Devices contains "U2F". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account) - IAM Users Have An MFA Device Enrolled

Checks that every IAM user in the evidence has at least one multi-factor authentication device enrolled.

Every record must satisfy: MFA equals "MFA Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Integrations Providing Findings

Test name

Test description

Test logic

AWS (Single Account) - Security Hub Finding Providers Are Enabled And Identified

Confirms Security Hub has at least one finding provider enabled for import and that each enabled provider is identified by product and vendor name.

Every record must satisfy: Product Name has a value and Company Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Network ACLs

Test name

Test description

Test logic

AWS (Single Account) - Custom Network ACLs Do Not Allow Unrestricted Inbound Traffic

Flags customer-managed network ACL rules that allow inbound traffic from any IPv4 or IPv6 address.

A record is marked failed when: Default equals "No" and Rule Number contains "Inbound Rule:" and Action equals "allow" and Source/Destination matches the pattern "^(0\.0\.0\.0/0|::/0)$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS (Single Account) - Subnet-Associated Network ACLs Do Not Allow Unrestricted Outbound Traffic

Flags customer-managed network ACLs in use on a subnet that allow outbound traffic to any IPv4 or IPv6 destination.

A record is marked failed when: Default equals "No" and Associated With is 1 or more and Rule Number contains "Outbound Rule:" and Action equals "allow" and Source/Destination matches the pattern "^(0\.0\.0\.0/0|::/0)$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Security Hub Findings

Test name

Test description

Test logic

Active Security Hub Findings Are Triaged

NIST 800-53 Rev5 IR-4 CA-7: verify no active Security Hub finding is left in the untriaged NEW workflow state. A row is a violation (Failed) when recordState is ACTIVE and workflowStatus is NEW. Fields: recordState, workflowStatus (WorkflowState).

A record is marked failed when: Record State equals "ACTIVE" and Workflow Status equals "NEW". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS Security Hub Has No Critical Or High Severity Findings

Verifies Security Hub reports no CRITICAL or HIGH severity findings, indicating vulnerabilities are remediated within SLA (NIST 800-53 Rev5 RA-5/SI-2). Checks textField.severity is neither 'CRITICAL' nor 'HIGH'.

Every record must satisfy: Severity is none of "CRITICAL" or "HIGH". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

No Active Failed Security Hub Findings

NIST 800-53 Rev5 RA-5 CA-7: verify no Security Hub finding is both an active record and a failed compliance check. A row is a violation (Failed) when recordState is ACTIVE and status is FAILED. Fields: status (Compliance.Status), recordState.

A record is marked failed when: Status equals "FAILED" and Record State equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of SSO Users

Test name

Test description

Test logic

AWS (Single Account) - IAM Identity Center SSO Users Are Individually Identifiable

Flags single sign-on accounts that use a generic or shared name such as admin, root, or service instead of identifying an individual person.

A record is sent for review when: User Name is empty. A record is marked failed when: User Name matches the pattern "^([Aa][Dd][Mm][Ii][Nn]([Ii][Ss][Tt][Rr][Aa][Tt][Oo][Rr])?|[Rr][Oo][Oo][Tt]|[Gg][Uu][Ee][Ss][Tt]|[Ss][Hh][Aa][Rr][Ee][Dd]|[Ss][Vv][Cc]|[Ss][Ee][Rr][Vv][Ii][Cc][Ee]|[Tt][Ee][Ss][Tt])[-_.0-9]*(@[^@]*)?$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of VPC Subnets

Test name

Test description

Test logic

AWS (Single Account) - Subnets Are Available And Mapped To A Parent VPC

Checks that every subnet is in the available state and records the subnet ID, parent VPC, and IPv4 CIDR block it belongs to.

Every record must satisfy: State equals "available" and Subnet Id has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account) - Subnets Use Private RFC 1918 IPv4 CIDR Ranges

Checks that every subnet is carved from a private, non-internet-routable IPv4 range rather than public address space.

Every record must satisfy: IPv4 CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of VPCs

Test name

Test description

Test logic

AWS (Single Account) - Default VPC Does Not Exist

Checks that no virtual private cloud in the selected regions is the provider-created default VPC, so network boundaries rest on purpose-built, reviewed networks. DescribeVpcs reports only whether a VPC is the default; it says nothing about whether workloads use it.

Every record must satisfy: Default equals "No". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account) - VPC IPv4 CIDR Blocks Use Private Address Space

Checks that each virtual private cloud's primary IPv4 CIDR block falls within private, non-internet-routable address space.

Every record must satisfy: IPv4 CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|100\.(6[4-9]|[7-9][0-9]|1[01][0-9]|12[0-7])\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Access Control List

Test name

Test description

Test logic

AWS (Single Account) - S3 Bucket ACL Contains Only A Canonical-User FULL_CONTROL Grant

Checks that every entry in a bucket's access control list is a canonical-user FULL_CONTROL grant with no email grantee - the ACL shape left behind when Object Ownership is set to BucketOwnerEnforced. The grant rows carry no bucket-owner identity, so a cross-account canonical-user grant is not distinguishable here.

Every record must satisfy: Permission equals "FULL_CONTROL" and Grantee ID has a value and Grantee Email is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Encryption

Test name

Test description

Test logic

AWS S3 Buckets Use Default Server-Side Encryption

Verifies each S3 bucket has default server-side encryption set to AES256, aws:kms, or aws:kms:dsse (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.1.1). Checks textField.keyType against the valid SSE algorithms.

A record is marked failed when: SSE Algorithm is empty. A record is marked failed when: SSE Algorithm is none of "AES256", "aws:kms" or "aws:kms:dsse". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

S3 Buckets Encrypted With KMS Keys

NIST 800-53 Rev5 SC-28(1) / SC-12: verify S3 buckets use SSE-KMS (aws:kms) with a real KMS key managed for the bucket, rather than SSE-S3 only. Fields: keyType, kmsKey (kmsKey is 'NA' when no KMS key is bound).

Every record must satisfy: SSE Algorithm equals "aws:kms" and KMS Key ID does not equal "NA". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Lifecycle Configuration

Test name

Test description

Test logic

AWS (Single Account) - S3 Lifecycle Actions Trigger On Object Age Not A Fixed Date

Confirms S3 lifecycle actions are triggered by how old an object is rather than a fixed calendar date, so the schedule keeps applying instead of firing once and stopping.

Every record must satisfy: Transition Date is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS (Single Account) - S3 Lifecycle Rules Are Named And Enabled

Confirms each S3 bucket lifecycle rule is named and in an enabled state, so the retention and cleanup schedule is actually being applied to objects in the bucket.

Every record must satisfy: Rule has a value and Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Object Lock Configuration

Test name

Test description

Test logic

AWS S3 Buckets Have Object Lock Enabled

Verifies each S3 bucket has Object Lock enabled to provide write-once-read-many (WORM) immutability for retained data (NIST 800-53 Rev5 AU-9/CP-9). Checks textField.enabled equals the display value 'Enabled'.

Every record must satisfy: Enabled equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

AWS S3 Object Lock Is Enabled With A Default Retention Period

Flags buckets with Object Lock enabled but no default retention period configured.

A record is marked failed when: Enabled equals "Enabled" and Retention Period equals "NA". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

S3 Bucket Policy Status

Test name

Test description

Test logic

AWS S3 Buckets Are Not Publicly Accessible

Verifies each S3 bucket's policy status is Private, not Public (NIST 800-53 Rev5 AC-3/SC-7; CIS AWS Foundations 2.1.5). Checks textField.policyType equals the display value 'Private'.

Every record must satisfy: Policy Type equals "Private". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Replication

Test name

Test description

Test logic

AWS (Single Account) - S3 Bucket Replication Rule Is Enabled With A Destination Bucket

Confirms the bucket has a named replication rule that is enabled and points at a destination bucket, so a second copy of the data is being maintained.

Every record must satisfy: Replication Rule Name has a value and Status equals "Enabled" and Destination Bucket has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket Versioning

Test name

Test description

Test logic

AWS S3 Buckets Have Versioning Enabled

Verifies each S3 bucket has object versioning enabled to protect against accidental or malicious deletion (NIST 800-53 Rev5 CP-9/SI-1; CIS AWS Foundations 2.1.2). Checks textField.status equals the display value 'Enabled'.

Every record must satisfy: Bucket Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

S3 Bucket MFA Delete Enabled

NIST 800-53 Rev5 CP-9 SC-28: verify MFA Delete is Enabled on versioned S3 buckets so object/version deletion requires MFA. Field: mfa (Enabled | Disabled | Never Enabled).

Every record must satisfy: Multifactor Authentication Delete equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Security Group Details

Test name

Test description

Test logic

AWS (Single Account) - Default Security Group Does Not Permit Traffic

Flags any traffic rule configured on a default security group, which should not permit inbound or outbound traffic.

A record is marked failed when: Security Group Name equals "default" and Network Rules has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AWS (Single Account) - Security Group Inbound Rules Do Not Expose Non-Web Ports To The Internet

Flags security group inbound rules that are open to the entire internet on ports other than the standard web ports.

A record is marked failed when: Network Rules matches the pattern "^Inbound:.*"destination":"(0\.0\.0\.0/0|::/0)".*$" and Network Rules does not match the pattern "^Inbound:.*"portRange":"(80|443)".*$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure

Azure Activity Logs

Test name

Test description

Test logic

Azure Activity Log Entries Are Within Retention Window

Verifies Azure activity-log entries are present and were recorded within the last 90 days, evidencing that management-plane logging is active and retained (NIST 800-53 Rev5 AU-2 / AU-11); checks timeStamp is not more than 90 days ago.

A record is sent for review when: Timestamp is empty. A record is marked failed when: Timestamp is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure Firewalls

Test name

Test description

Test logic

Azure Firewall Boundary Devices Are Fully Identified in the Inventory

Checks that every row of the Azure Firewall evidence is a real firewall resource with a name and an owning resource group.

Every record must satisfy: Type equals "Microsoft.Network/azureFirewalls" and Name has a value and Resource Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Backup Configuration

Test name

Test description

Test logic

Azure SQL Database Uses Geo-Redundant Backup Storage

Verifies Azure SQL databases use geo-redundant backup storage so backups survive a regional outage (NIST 800-53 Rev5 CP-6 / CP-9); checks backupStorageRedundancy contains Geo.

Every record must satisfy: Backup Storage Redundancy contains "Geo". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Backup Retention Days

Test name

Test description

Test logic

Azure SQL Databases Retain Backups for at Least Seven Days

NIST SP 800-53 CP-9: conduct system backups and retain them to support recovery. Verifies every Azure SQL database short-term backup retention policy keeps backups for at least 7 days.

Every record must satisfy: Backup Retention Days is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure SQL Databases Retain Point-in-Time Backups for at Least 30 Days

NIST SP 800-53 CP-9: conduct and retain system backups sufficient for recovery. Verifies every Azure SQL database short-term (point-in-time restore) retention policy keeps backups for at least 30 days.

Every record must satisfy: Backup Retention Days is 30 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Firewall Policies

Test name

Test description

Test logic

Azure Firewall Policies Enable Threat Intelligence Filtering

NIST SP 800-53 SC-7: monitor and control communications at external boundaries. Verifies every Azure Firewall policy enables threat intelligence-based filtering (threat intel mode is not Off).

Every record must satisfy: Threat Intel Mode does not equal "Off". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

IDPS Signatures

Test name

Test description

Test logic

Azure Firewall IDPS Signatures Actively Block Traffic

Verifies Azure Firewall Premium IDPS signatures are set to block (deny) rather than alert-only so intrusions are prevented, not just logged (NIST 800-53 Rev5 SI-4 / SC-7); checks the alertOnly flag is false.

Every record must satisfy: Alert Only is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Alerts

Test name

Test description

Test logic

Azure Defender Security Alerts Have Been Triaged

Verifies Microsoft Defender for Cloud security alerts are not left in an Active state (must be Resolved or Dismissed) evidencing incident handling (NIST 800-53 Rev5 IR-4 / SI-4); checks alert status.

A record is marked failed when: Status is none of "Resolved" or "Dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Application Configurations

Test name

Test description

Test logic

Azure App Configuration Stores Are Located in United States Regions

Checks that every Azure App Configuration store is deployed in a United States region, which is where its configuration data resides.

Every record must satisfy: Location matches the pattern "^(eastus|westus|centralus|northcentralus|southcentralus|westcentralus|usgov|usdod|usnat|ussec)|(^| )US( |$|[0-9])|^United States". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure App Configuration Stores Use a SKU That Supports Private Link

Checks that every Azure App Configuration store runs on a pricing tier that supports private endpoints, so store traffic does not have to traverse a public endpoint.

Every record must satisfy: Pricing Tier does not equal "Free" and Pricing Tier has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Backup Jobs

Test name

Test description

Test logic

Azure Backup Jobs Complete Successfully

NIST SP 800-53 CP-9: system backup. Verifies every Azure backup job in the proof period finished with a Completed status, confirming backups are running successfully.

Every record must satisfy: Status equals "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure Backup Jobs Did Not Fail

NIST SP 800-53 CP-9: ensure backups run reliably. Verifies no Azure backup job in the proof period ended in a Failed status (Completed, CompletedWithWarnings, and InProgress are acceptable), surfacing backup failures for follow-up.

Every record must satisfy: Status does not equal "Failed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Backup Policies

Test name

Test description

Test logic

Azure Backup Policies Are Scheduled at Least Daily

Checks that every backup policy in the Recovery Services vault runs on a daily or hourly schedule rather than weekly or less often.

Every record must satisfy: Frequency is none of "Weekly" or "Monthly" and Frequency has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Backups

Test name

Test description

Test logic

Azure MySQL Server Backup Completed Recently

Verifies each Azure MySQL server backup completed within the last 8 days so restore points stay current (NIST 800-53 Rev5 CP-9); checks completedTime is not more than 8 days ago.

Every record must satisfy: Time of Completion has a value. A record is marked failed when: Time of Completion is more than 8 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure PostgreSQL Flexible Server Backup Completed Recently

Verifies each Azure PostgreSQL flexible-server backup completed within the last 8 days so restore points stay current (NIST 800-53 Rev5 CP-9); checks completedTime is not more than 8 days ago.

Every record must satisfy: Time of Completion has a value. A record is marked failed when: Time of Completion is more than 8 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Databases

Test name

Test description

Test logic

Azure MySQL Servers Run A Supported Major Version

Verifies Azure MySQL servers run a supported major version (8.x); 5.7 and earlier are end-of-life and unpatched (NIST 800-53 Rev5 SI-2 / CM-6); checks the version starts with 8.

Every record must satisfy: Version matches the pattern "^8\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure PostgreSQL Servers Run A Supported Major Version

Verifies Azure PostgreSQL flexible servers run a supported major version (13 or newer); versions 12 and earlier are end-of-life (NIST 800-53 Rev5 SI-2 / CM-6); checks the version major number.

Every record must satisfy: Version matches the pattern "^(1[3-9]|[2-9][0-9])". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure SQL Databases Enable Infrastructure Encryption

NIST SP 800-53 SC-28: protect the confidentiality and integrity of information at rest. Verifies every Azure SQL database has infrastructure (double) encryption enabled.

Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure SQL Databases Located Outside United States Regions

Flags Azure SQL databases located outside United States regions.

A record is marked failed when: Location has a value and Location does not match the pattern "^(eastus|westus|centralus|northcentralus|southcentralus|westcentralus|usgov|usdod|usnat|ussec)|(^| )US( |$|[0-9])|^United States". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure SQL Databases Run a Supported Engine Version

NIST SP 800-53 CM-2 / SI-2: maintain supported, patched software baselines. Verifies every Azure SQL database reports a v12.0 engine generation (the current supported Azure SQL Database version family).

Every record must satisfy: Version contains "v12.0". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Disk Encryption Details

Test name

Test description

Test logic

Azure Managed Disks Are Encrypted With Customer-Managed Keys

NIST SP 800-53 SC-12 / SC-28(1): manage cryptographic keys under organizational control. Verifies every Azure managed disk uses a customer-managed key, either alone (EncryptionAtRestWithCustomerKey) or alongside the platform key (EncryptionAtRestWithPlatformAndCustomerKeys), rather than only a platform-managed key.

A record is marked failed when: Encryption Type is none of "EncryptionAtRestWithCustomerKey" or "EncryptionAtRestWithPlatformAndCustomerKeys". A record is marked failed when: Encryption Type is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure Managed Disks Report an Encryption Type

NIST SP 800-53 SC-28: protect the confidentiality and integrity of information at rest. Verifies every Azure managed disk reports a configured at-rest encryption type.

Every record must satisfy: Encryption Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure Managed Disks Use a Recognized At-Rest Encryption Type

NIST SP 800-53 SC-28: protect information at rest with approved encryption. Verifies every Azure managed disk reports a recognized server-side encryption type (platform-managed key, customer-managed key, or platform-and-customer key), confirming at-rest encryption is in a known-good configuration.

A record is marked failed when: Encryption Type is none of "EncryptionAtRestWithPlatformKey", "EncryptionAtRestWithCustomerKey" or "EncryptionAtRestWithPlatformAndCustomerKeys". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Disks

Test name

Test description

Test logic

Azure Managed Disks Are Encrypted At Rest

Verifies every Azure managed disk has server-side encryption at rest enabled (NIST 800-53 Rev5 SC-28); checks the encryptionEnabled flag.

Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Locks

Test name

Test description

Test logic

Azure Critical Resources Protected By Management Lock

Verifies resources carry a CanNotDelete or ReadOnly management lock to prevent accidental or unauthorized deletion/modification (NIST 800-53 Rev5 CM-3 / CP-9); checks the lock level (Delete / Read only).

A record is marked failed when: Lock Type is none of "Delete" or "Read only". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Network Security Groups

Test name

Test description

Test logic

Network Security Groups Are Inventoried And Scoped To A Resource Group

Checks that the network security group inventory is not empty and that every group is attributed to the resource group that owns it.

Every record must satisfy: Resource Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Resource Groups

Test name

Test description

Test logic

Resource Groups Located Outside United States Regions

Flags any resource group whose region falls outside the United States, so workloads placed in unintended geographies are surfaced.

A record is marked failed when: Location has a value and Location does not match the pattern "US|United States". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Resources

Test name

Test description

Test logic

Retired Azure Classic Deployment Model Resources Are Not In Use

Flags Azure resources still using the retired classic deployment model, which modern access control and policy governance cannot manage.

A record is marked failed when: Resource has a value and Resource Type matches the pattern "^Microsoft\.Classic". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Role Assignments

Test name

Test description

Test logic

Azure Owner Role Assignments Are Reviewed

Routes Azure RBAC assignments of the built-in Owner role to review as privileged access.

A record is sent for review when: Role equals "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure RBAC Assignments Resolve To A Known Principal

Verifies every Azure role assignment resolves to a known principal type (User, Group, ServicePrincipal, ForeignGroup, or Device) rather than an orphaned/Unknown identity left behind by a deleted account (NIST 800-53 Rev5 AC-2 / AC-3); checks principalType.

A record is marked failed when: Type is none of "User", "Group", "ServicePrincipal", "ForeignGroup" or "Device". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Virtual Machines

Test name

Test description

Test logic

Azure Virtual Machines Have Secure Boot Enabled

Verifies each Azure VM has Secure Boot enabled to protect against boot-level rootkits and unsigned firmware (NIST 800-53 Rev5 SI-7 / CM-6); checks the secureBootEnabled field.

Every record must satisfy: Secure Boot Enabled equals "Yes". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Virtual Network Gateways

Test name

Test description

Test logic

Azure VPN Gateways Use Route-Based Connections

Verifies virtual network gateways use the RouteBased VPN type, which supports modern IKEv2/strong ciphers unlike legacy PolicyBased gateways (NIST 800-53 Rev5 SC-7 / SC-8); checks the gateway type.

Every record must satisfy: Type contains "RouteBased". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Log Collection

Test name

Test description

Test logic

Azure PostgreSQL Server Logs Are Recently Collected

Verifies Azure PostgreSQL server log files were collected within the last 30 days, evidencing that database logging is enabled and current (NIST 800-53 Rev5 AU-2 / AU-4); checks lastModified is not more than 30 days ago.

A record is sent for review when: Last Modified is empty. A record is marked failed when: Last Modified is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Minimum TLS Version

Test name

Test description

Test logic

Azure MySQL Flexible Servers Enforce TLS 1.2 or Higher

NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for MySQL flexible server sets a minimum TLS version of 1.2 (the tls_version parameter does not permit TLS 1.0 or 1.1).

Every record must satisfy: Minimum TLS Version does not match the pattern "[Tt][Ll][Ss][Vv]?1(\.[01])?(,|$)|[Tt][Ll][Ss]1_[01](,|$)" and Minimum TLS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure PostgreSQL Flexible Servers Require Secure Transport

NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for PostgreSQL flexible server enforces encrypted (TLS) connections by setting require_secure_transport to ON.

Every record must satisfy: Require Secure Transport equals "True". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure PostgreSQL Flexible Servers Set Minimum TLS 1.2

NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for PostgreSQL flexible server sets ssl_min_protocol_version to TLSv1.2 or TLSv1.3, disallowing the deprecated TLSv1 and TLSv1.1.

A record is marked failed when: Minimum TLS Version is none of "TLSv1.2" or "TLSv1.3". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Recommendations

Test name

Test description

Test logic

Azure Defender for Cloud Recommendations Are Resolved

NIST SP 800-53 RA-5: monitor and scan for vulnerabilities and remediate findings. Verifies every Microsoft Defender for Cloud recommendation is in a completed (healthy) state.

Every record must satisfy: Status equals "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure DevOps

Deployment Approval Policy

Test name

Test description

Test logic

Deployment Approval Policy Names Explicit Approvers

Segregation of duties / accountability: verifies the pre-deployment approval policy lists named approvers rather than an empty/automated approver set. Maps to NIST 800-53 Rev5 CM-5 (access restrictions for change) and AC-5, and ISO/IEC 27001:2022 Annex A A.5.3 (segregation of duties) and A.8.32. Checks textField.approvers is populated on the deploymentApprovalPolicy proof.

Every record must satisfy: Approvers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deployment Environment Requires Pre-Deployment Approval

Change control: verifies the release environment's pre-deployment approval gate is enabled (not fully automated). Maps to NIST 800-53 Rev5 CM-3 / CM-5, CMMC 2.0 / NIST 800-171 3.4.5, and ISO/IEC 27001:2022 Annex A A.8.32 (change management). Checks booleanField.enabled on the deploymentApprovalPolicy proof.

Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deployments In An Environment

Test name

Test description

Test logic

Every Deployment Has A Recorded Approver

Change control evidence: verifies each release deployment carries a recorded approver, so no change reached the environment without approval. Maps to NIST 800-53 Rev5 CM-3 (configuration change control) and SA-11, and ISO/IEC 27001:2022 Annex A A.8.32 (change management). Checks textField.approvedBy is populated on each deployments row.

Every record must satisfy: Approved By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Every Deployment Is Attributable To An Identity

Accountability / audit trail: verifies each deployment records who initiated it so releases are traceable to an individual or trusted automation identity. Maps to NIST 800-53 Rev5 AU-12 and CM-3, CMMC 2.0 / NIST 800-171 3.3.2 (traceability to individual users), and ISO/IEC 27001:2022 Annex A A.8.15 (logging). Checks textField.deployedBy is populated on each deployments row.

Every record must satisfy: Deployed By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

No Organization User Account Is Inactive Beyond 90 Days

Inactive-account review: verifies every member has accessed the organization within the last 90 days, flagging dormant accounts that should be disabled. Maps to NIST 800-53 Rev5 AC-2(3) (disable inactive accounts), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18 (access rights review). Checks dateField.lastAccessed is not more than 90 days ago on each listOfUsers row.

A record is sent for review when: Last Accessed is empty. A record is marked failed when: Last Accessed is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Organization User Accounts Have An Identifiable Email

Account management: verifies every organization member has an email address on file, guarding against shared/anonymous accounts and supporting access recertification. Maps to NIST 800-53 Rev5 AC-2 (account management), CMMC 2.0 / NIST 800-171 3.5.1, and ISO/IEC 27001:2022 Annex A A.5.16 (identity management). Checks textField.email is populated on each listOfUsers row.

Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Members in Permission Group

Test name

Test description

Test logic

Permission Group Members Are Attributed To A Group

Authorization records: verifies each user surfaced in the permission-group membership proof is attributed to at least one named group, giving auditors a clean least-privilege authorization record. Maps to NIST 800-53 Rev5 AC-2 / AC-6 (least privilege), CMMC 2.0 / NIST 800-171 3.1.5, and ISO/IEC 27001:2022 Annex A A.5.18 (access rights). Checks textField.memberOf is populated on each membersInPermissionGroup row.

Every record must satisfy: Member Of has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Azure Kubernetes Service

List of AKS Clusters

Test name

Test description

Test logic

AKS API Server Is a Private Cluster

Verifies each AKS cluster is provisioned as a private cluster so the Kubernetes API server endpoint is not exposed to the public internet and is only reachable over the private network. Maps to CIS Kubernetes Benchmark / AKS hardening (restrict API server access), NIST 800-53 Rev5 SC-7 (boundary protection) and AC-17 (remote access), and ISO/IEC 27001:2022 Annex A.8.20 (networks security). Checks clustersList.enablePrivateCluster.

Every record must satisfy: Private cluster is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AKS Cluster Enforces a Network Policy Engine

Verifies each AKS cluster has a Kubernetes network policy engine (azure, calico, or cilium) configured so pod-to-pod traffic is restricted by policy rather than fully open. Maps to CIS Kubernetes Benchmark 5.3.2 (network policies), NIST 800-53 Rev5 SC-7 (boundary protection) / AC-4 (information flow enforcement), and ISO/IEC 27001:2022 Annex A.8.22 (segregation of networks). Checks clustersList.networkPolicy.

A record is marked failed when: Network Policy is none of "azure", "calico" or "cilium". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AKS Runs a Supported Kubernetes Version

Verifies each AKS cluster runs a current, vendor-supported Kubernetes minor version (1.26 or newer) so it continues to receive security patches, rather than an end-of-life version. Maps to NIST 800-53 Rev5 SI-2 (flaw remediation) and CM-8 (system component inventory), NIST 800-171 3.14.1, and ISO/IEC 27001:2022 Annex A.8.8 (management of technical vulnerabilities). Checks clustersList.kubernetesVersion with a regex on the major.minor prefix.

Every record must satisfy: Kubernetes version matches the pattern "^1\.(2[6-9]|[3-9][0-9])\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AKS Uses the Azure CNI Network Plugin

Verifies each AKS cluster uses the Azure CNI network plugin rather than kubenet, giving pods first-class VNet IPs so enterprise network controls (NSGs, route tables, network policy) apply directly to pod traffic. Maps to NIST 800-53 Rev5 CM-6 (configuration settings baseline) and SC-7 (boundary protection), and ISO/IEC 27001:2022 Annex A.8.20 (networks security). Checks clustersList.networkPlugin.

Every record must satisfy: Network type (plugin) equals "azure". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AKS Uses the Standard Load Balancer SKU

Verifies each AKS cluster uses the Standard load balancer SKU rather than the deprecated Basic SKU, which is the baseline required to support API-server authorized IP ranges, availability zones, and outbound rules. Maps to NIST 800-53 Rev5 CM-6 (configuration settings baseline) and CIS/SOC 2 CC7/CC8 (secure configuration). Checks clustersList.loadBalancerSku.

Every record must satisfy: Load balancer equals "standard". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Deployments

Test name

Test description

Test logic

AKS Workloads Are Not Deployed to the Default Namespace

Verifies each AKS deployment runs in a purpose-named namespace rather than the shared default namespace, enabling namespace-scoped RBAC, network policy, and quota boundaries between workloads. Maps to CIS Kubernetes Benchmark 5.7.4 (the default namespace should not be used), NIST 800-53 Rev5 AC-6 (least privilege) / CM-6 (configuration settings), and NIST 800-171 3.1.5. Checks deploymentsList.namespace.

Every record must satisfy: Namespace does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

AKS Workloads Run With Redundant Replicas

Verifies each AKS deployment has at least two available replicas so a single pod or node failure does not take the workload offline, supporting availability and graceful failover. Maps to NIST 800-53 Rev5 CP-2 (contingency planning) / SC-6 (resource availability) and ISO/IEC 27001:2022 Annex A.8.14 (redundancy of information processing facilities). Checks deploymentsList.availableReplicas.

Every record must satisfy: Available is 2 or more. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Basecamp

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Bitbucket

List of Commits

Test name

Test description

Test logic

Bitbucket - Commits Are Attributed to an Author

Enforces non-repudiation of code changes per NIST 800-53 Rev5 AU-3/SA-10: every commit must identify its author. Checks the author field.

Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Bitbucket - Commits Include a Change Message

Supports change documentation per NIST 800-53 Rev5 CM-3/SA-10: every commit must include a non-empty message describing the change. Checks the message field.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Pull Requests

Test name

Test description

Test logic

Bitbucket - Merged Pull Requests Are Documented

Supports change documentation per NIST 800-53 Rev5 CM-3/SA-10: any pull request in the MERGED state must carry a non-empty description. Open or declined pull requests are not required to have one. Checks the state and description fields.

A record is marked failed when: Status equals "MERGED" and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Bitbucket - Pull Requests Are Attributed to an Author

Enforces change accountability and non-repudiation per NIST 800-53 Rev5 CM-3/AU-3: every pull request (change record) must identify its author.

Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Users

Test name

Test description

Test logic

Bitbucket - Workspace Members Hold a Recognized Permission Level

Verifies configuration baseline for access grants per NIST 800-53 Rev5 CM-6/AC-3: every workspace member's permission field must be one of the approved values owner, collaborator, or member.

A record is marked failed when: Permission is none of "owner", "collaborator" or "member". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Bitbucket - Workspace Owner Access Is Reviewed

Routes Bitbucket workspace members holding owner permission to review as privileged access.

A record is sent for review when: Permission equals "owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Bitbucket Workspace Accounts Inactive Over 90 Days

Flags Bitbucket workspace user accounts that have not been accessed in the last 90 days.

A record is marked failed when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Breezy

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Capsule

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CATS

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Checkmarx CxOne

Create Report

Test name

Test description

Test logic

Checkmarx One - No Critical or High Severity Findings in Scan Report

Verifies the Checkmarx One scan report contains no software-composition findings at Critical or High severity, evidencing that serious vulnerabilities are remediated. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Testing and Evaluation). Checks the 'severity' field from the Create Report proof. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Severity is none of "Critical" or "High". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Checkmarx One - Report Findings Are Severity-Classified and Categorized

Verifies every finding in the scan report is triaged with a severity and a category, so vulnerabilities can be risk-ranked and routed for remediation. Supports NIST SP 800-53 Rev 5 SA-11 (Developer Testing and Evaluation - flaw tracking) and RA-5 (analysis of scan results). Checks 'severity' and 'category' are non-empty. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Severity has a value and Category has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Checkmarx One - Scan Report Evidence Is Recent

Verifies each finding in the scan report carries a scan date that is present and not more than 90 days old, so the evidence reflects a current scan rather than a stale export. Supports NIST SP 800-53 Rev 5 RA-5 (scan frequency / currency of results). Two conditions per row: 'lastScan' must be non-empty and not older than 90 days. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Last Scan has a value. A record is marked failed when: Last Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List All Projects

Test name

Test description

Test logic

Checkmarx One - No Projects at High or Critical Risk

Verifies that no project in the Checkmarx One inventory carries a Critical or High overall risk level, evidencing timely remediation of scanner findings. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Testing and Evaluation). Checks the 'riskLevel' field from the List All Projects proof; empty inventory fails because no coverage can be demonstrated.

Every record must satisfy: Risk Level is none of "Critical" or "High". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Checkmarx One - Project Inventory Records Are Complete

Verifies each project record in the scanning inventory identifies a project name and a project id, so the SAST asset inventory is complete and traceable. Supports NIST SP 800-53 Rev 5 CM-8 (System Component Inventory) and SA-11 (scoping of testing). Checks 'projectName' and 'projectId' are non-empty. Empty inventory fails because no assets are enrolled in scanning.

Every record must satisfy: Project Name has a value and Project Id has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Checkmarx One - Projects Scanned Within Last 90 Days

Verifies every project has been scanned recently (lastScanDate is present and not more than 90 days ago), demonstrating an operating scan cadence. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning - frequency). Two conditions per row: lastScanDate must be non-empty and must not be older than 90 days. Empty inventory fails because scan cadence cannot be demonstrated.

Every record must satisfy: Last Scan has a value. A record is marked failed when: Last Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Checkmarx SCA

List of Projects

Test name

Test description

Test logic

No High-Severity Open Vulnerabilities In Scanned Projects

Verifies every scanned project's latest SCA risk report shows zero high-severity vulnerabilities, evidencing timely remediation of open findings. Maps to NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Security Testing), CMMC 2.0 RA.L2-3.11.2 / SI.L2-3.14.1 (NIST 800-171 3.11.2), and ISO/IEC 27001:2022 A.8.8 (Management of technical vulnerabilities). Checks numberField.highVulnerabilityCount.

Every record must satisfy: High Vulnerabilities equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Scanned Projects Have An Assigned Owning Team

Verifies every scanned project is assigned to at least one team, establishing accountable ownership for remediating vulnerabilities against inventoried components. Maps to NIST 800-53 Rev5 CM-8 (System Component Inventory) and RA-5, and ISO/IEC 27001:2022 A.5.9 (Inventory of information and other associated assets) and A.8.8. Checks textField.assignedTeamNames.

Every record must satisfy: Team has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerability Scans Performed Within Last 30 Days

Verifies each project has a successful SCA scan within the last 30 days so vulnerability posture is monitored at a defined frequency rather than going stale. Maps to NIST 800-53 Rev5 RA-5(2) (Update Frequency) and SA-11, CMMC 2.0 RA.L2-3.11.2 (NIST 800-171 3.11.2), and ISO/IEC 27001:2022 A.8.8 (Management of technical vulnerabilities). Checks numberField.daysSinceLastSuccessfulScan.

Every record must satisfy: Days Since Last Successful Scan is 30 or less. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

No Dormant Active User Accounts

Flags any enabled account that has not logged in for more than 90 days, evidencing timely disabling of dormant credentials. An account fails only when it is active AND its last login is more than 90 days ago. Maps to NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts), CMMC 2.0 AC.L2-3.1.1, ISO/IEC 27001:2022 A.5.18 (Access rights review/removal), CIS Control 5.3 (Disable Dormant Accounts), and SOC 2 CC6.2/CC6.3. Checks booleanField.active and dateField.lastLoginDate.

A record is marked failed when: Active is true and Last Login Date is empty. A record is marked failed when: Active is true and Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Have An Assigned Role

Verifies every Checkmarx SCA account is assigned at least one role, evidencing role-based authorization so no account holds undefined or default access. Maps to NIST 800-53 Rev5 AC-2 (Account Management) and AC-6 (Least Privilege), CMMC 2.0 AC.L2-3.1.5 (NIST 800-171 3.1.5), ISO/IEC 27001:2022 A.5.15/A.5.18 (Access control / Access rights), and SOC 2 CC6.1/CC6.3. Checks textField.roleNames.

Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Clear Books

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Vendor and Customer Master Lists

Test name

Test description

Test logic

Supplier Master Records Have A Tax Identification Number

Flags supplier records on the vendor master list that have no tax identification number on file.

A record is marked failed when: Entity Type contains "Supplier" and Tax ID is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vendor And Customer Master Records Are Named And Classified

Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified.

Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ClickUp

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Clockwork

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Close

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloudflare

Firewall Rules

Test name

Test description

Test logic

Cloudflare Firewall Rules Are Documented

NIST SP 800-53 CM-6: configuration settings must be documented so their intent can be reviewed. Verifies every Cloudflare firewall rule includes a description.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloudflare Firewall Rules Are Enabled

NIST SP 800-53 SC-7: boundary protection requires that traffic-filtering rules at the network boundary are actively enforced. Verifies every Cloudflare firewall rule is enabled (not paused).

Every record must satisfy: Disabled is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloudflare Firewall Rules Enforce a Protective Action

NIST SP 800-53 SC-7: boundary protection must deny or challenge unwanted traffic, not merely observe it. Verifies every Cloudflare firewall rule takes a protective action (Block or a challenge) rather than only logging or allowing traffic.

Every record must satisfy: Action matches the pattern "^(Block|.*Challenge)$". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of WAF Managed Rules

Test name

Test description

Test logic

Cloudflare WAF Managed Rules Are Documented

NIST SP 800-53 CM-6: configuration settings must be documented so their intent can be reviewed. Verifies every Cloudflare WAF managed rule includes a description.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloudflare WAF Managed Rules Are Enabled

NIST SP 800-53 SI-4: system monitoring requires that detection mechanisms are active. Verifies every Cloudflare WAF managed rule is enabled.

Every record must satisfy: Enabled equals "Yes". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloudflare WAF Managed Rules Enforce a Protective Action

NIST SP 800-53 SC-7: boundary protection must mitigate malicious traffic, not merely observe it. Verifies every Cloudflare WAF managed rule takes a protective action rather than only logging matching requests.

Every record must satisfy: Action does not equal "log". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Comeet

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Copper

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cornerstone TalentLink

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Coupa

List of Approvals

Test name

Test description

Test logic

Coupa Approvals Are Approved With A Named Approver

NIST 800-53 Rev5 AC-6 / segregation-of-duties: approval records in scope must be in the approved state and attributable to a named approver, enforcing authorization accountability. Fields: status (text, raw Coupa value 'approved'), approverName (text).

Every record must satisfy: Status equals "approved" and Approval Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa Approvals Are In A Recognized Workflow State

Verifies every approval record is in one of Coupa's recognized workflow states (pending_approval, approved, rejected, cancelled) via a single OR condition on textField.status, confirming approval-workflow integrity and flagging records in unexpected states (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / CM-3 Configuration Change Control). Uses OR with '=' (never 'in') per the text evaluator. Checks the List of Approvals proof.

A record is marked failed when: Status is none of "pending_approval", "approved", "rejected" or "cancelled". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa Approvals Have A Named Approver

Verifies every approval record identifies the approver by name (textField.approverName non-empty), so each requisition/PO/invoice approval is attributable to an accountable individual (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / AU-2 Event Logging / segregation-of-duties evidence). Checks the List of Approvals proof.

Every record must satisfy: Approval Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Commodities

Test name

Test description

Test logic

Coupa Commodity Records Carry An Identifier, Name And Creation Date

Confirms every commodity record carries a valid numeric identifier, a name, and a creation date so the spend taxonomy is complete and traceable.

Every record must satisfy: Commodity ID is greater than 0 and Commodity Name has a value and Created At has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Coupa Commodity Taxonomy Contains Only Active Entries

Flags commodities that are marked inactive, surfacing retired entries left enabled in the spend classification taxonomy.

Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Entities

Test name

Test description

Test logic

Coupa Entities Have A Status And Type

Verifies each business entity (legal/spend hierarchy node) has a non-empty status (textField.status) and type (textField.type), enforcing organizational-structure governance so authorization boundaries and spend scopes are well-defined (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / AC-3). Checks the List of Entities proof.

Every record must satisfy: Status has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Items

Test name

Test description

Test logic

Coupa Catalog Items Have A Number And Name

Verifies every catalog item has a non-empty item number (textField.itemNumber) and name (textField.name), enforcing catalog integrity so procurement is limited to identified, controlled items rather than untracked spend (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / CM-7 Least Functionality). Checks the List of Items proof.

Every record must satisfy: Item Number has a value and Item Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Risks

Test name

Test description

Test logic

Coupa Risk Evaluations Are Completed And Rated

NIST 800-53 Rev5 RA-3 risk assessment: supplier/entity risk evaluations in scope must be Completed and carry a final risk rating, so no assessment is left unresolved. Fields: status (text, vlookup display 'Completed'), riskRating (text).

Every record must satisfy: Status equals "Completed" and Risk Rating has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa Supplier Risk Assessments Have A Rating And Score

Verifies each supplier risk assessment has a non-empty final rating (textField.riskRating) and a final score (numberField.riskScore), so third-party risk evaluations reach a scored, ratable conclusion; assessments left without a rating/score fail cleanly via !isEmpty and are surfaced for follow-up (NIST SP 800-53 Rev 5 RA-3 Risk Assessment / SR-6 Supplier Assessments and Reviews). Checks the List of Risks proof.

Every record must satisfy: Risk Rating has a value and Risk Score has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Suppliers

Test name

Test description

Test logic

Coupa Suppliers Are Active

NIST 800-53 Rev5 SR-6 / PM-30 supply-chain and vendor management: suppliers in scope must be in an active status, so inactive or deprovisioned vendors are not transacting. Fields: status (text, raw Coupa value 'active').

Every record must satisfy: Status equals "active". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa Suppliers Have A Defined Payment Method

Verifies every supplier has a defined payment method (textField.paymentMethod non-empty). A supplier with no payment method indicates incomplete onboarding and a disbursement-control gap; a blank value fails cleanly via !isEmpty (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / SA-9 External System Services). Checks the List of Suppliers proof.

Every record must satisfy: Payment Method has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Coupa Suppliers Have A Supplier Number

Verifies every supplier record carries a non-empty supplier number (textField.number), enforcing vendor-master integrity so that payments and purchase orders trace to an onboarded, uniquely identified supplier (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / AC-3). Checks the List of Suppliers proof.

Every record must satisfy: Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Coupa Suppliers Use An Approved Payment Method

NIST 800-53 Rev5 SR-6 / financial disbursement controls: every supplier must settle through an approved payment method (Coupa Pay or Invoice), preventing unsanctioned payment channels. Fields: paymentMethod (text, raw Coupa codes 'coupa_pay' / 'invoice').

A record is marked failed when: Payment Method is none of "coupa_pay" or "invoice". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Coupa Active Users Have Assigned Roles

NIST 800-53 Rev5 AC-2 / AC-6: every active Coupa user account must have at least one role assigned, guarding against privilege-less or orphaned active accounts. Fields: active (boolean), role (text).

A record is marked failed when: Active is true and Role is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa User Accounts Have A Valid Email Identifier

Verifies every Coupa user account carries a non-empty email that contains '@', so each account maps to a real, addressable identity (NIST SP 800-53 Rev 5 AC-2 Account Management / IA-4 Identifier Management). Checks textField.email is present and well-formed on the List of Users proof.

Every record must satisfy: Email has a value and Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Coupa Users Have At Least One Role Assigned

Verifies every Coupa user account has at least one role assigned (textField.role non-empty) so access is provisioned deliberately rather than left undefined, supporting least-privilege and access-review controls (NIST SP 800-53 Rev 5 AC-6 Least Privilege / AC-2 Account Management). Role is the comma-joined list of the user's Coupa roles on the List of Users proof.

Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Crelate

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CrowdStrike

Device Control Policies

Test name

Test description

Test logic

CrowdStrike Device Control Policies Assigned To Host Groups

Removable media protection enforcement (NIST 800-53 Rev5 MP-7): each device-control policy must be assigned to at least one host group so it actually enforces. Checks textField.groups is not empty.

Every record must satisfy: Groups has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CrowdStrike Device Control Policies Enabled

Removable media / port and I/O device control (NIST 800-53 Rev5 MP-7, SC-41): every USB device-control policy must be enabled. Checks booleanField.enabled isTrue.

Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Endpoint Detections

Test name

Test description

Test logic

Automated Incident Response Triggering

Confirms that high-severity or critical CrowdStrike endpoint detections automatically trigger incident response procedures.

Every record must satisfy: Vulnerability has a value and Severity has a value and First Detected has a value and Status has a value and Hours to Resolution has a value and Hostname has a value and Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CrowdStrike Detections Are Triaged Within 30 Days

Flags CrowdStrike detections still in the new state more than 30 days after they were raised.

A record is sent for review when: First Detected is empty. A record is marked failed when: Status equals "new" and First Detected is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Detection Host Attribution

Confirms every CrowdStrike endpoint detection is attributed to a named host running a recognized platform so responders can locate and contain the endpoint (NIST 800-53 Rev5 IR-4, CM-8). Fields: hostName, displayName, platformName (mapped from device.platform_name; display values Windows/Mac/Linux).

Every record must satisfy: Hostname has a value and Vulnerability has a value. A record is marked failed when: Platform is none of "Windows", "Mac" or "Linux". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Detection Severity Classified

Ensures every CrowdStrike endpoint detection carries a recognized severity classification and is attributable (host + name + time) to support risk-based incident triage (NIST 800-53 Rev5 IR-4, IR-5, RA-5). Fields: displayName, hostName, detectTime, maxSeverityDisplay (mapped from severity_name; display values Critical/High/Medium/Low/Informational).

Every record must satisfy: Vulnerability has a value and Hostname has a value and First Detected has a value. A record is marked failed when: Severity is none of "Critical", "High", "Medium", "Low" or "Informational". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Endpoint Detection Coverage Verification

Ensures that all endpoints have CrowdStrike sensors actively deployed and monitoring to detect malicious code.

Every record must satisfy: Vulnerability has a value and Severity has a value and Status has a value and Hostname has a value and Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Host Groups

Test name

Test description

Test logic

CrowdStrike Host Groups Are Documented

Asset inventory grouping (NIST 800-53 Rev5 CM-8): each host group must carry a description so the grouping rationale used to scope protection policies is recorded. Checks textField.description is not empty.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Hosts

Test name

Test description

Test logic

CrowdStrike Endpoint Sensor Installed On All Hosts

Malicious code protection (NIST 800-53 Rev5 SI-3): verifies every managed host reports a Falcon sensor version so no endpoint is left unprotected. Checks textField.sensorVersion is not empty.

Every record must satisfy: Sensor Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CrowdStrike Hosts Checked In Within 30 Days

Asset inventory currency (NIST 800-53 Rev5 CM-8, AU-6): each host's last check-in (dateField.lastSeen) must be within 30 days so stale or abandoned endpoints are flagged.

A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

CrowdStrike Hosts Not Stuck In Pending Containment

Incident handling (NIST 800-53 Rev5 IR-4): no host may remain in a Containment Pending or Lift Containment Pending state, which indicates a stalled isolation action. Checks textField.status against both pending states.

Every record must satisfy: Containment Status is none of "Containment Pending" or "Lift Containment Pending". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

CrowdStrike Hosts Record An Operating System Baseline

Checks that each CrowdStrike host records its platform and operating system version.

Every record must satisfy: Platform has a value and OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

CrowdStrike Sensor Version Meets Minimum Baseline

Flaw remediation / version currency (NIST 800-53 Rev5 SI-2): the Falcon sensor major version must be 7 or newer so agents stay patched. Regex-matches textField.sensorVersion.

Every record must satisfy: Sensor Version matches the pattern "^(7|8|9|[1-9][0-9]+)\.". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Host Active And Monitored

Confirms each host has a sensor installed and has checked in within the last 30 days so monitoring is current and stale endpoints are surfaced (NIST 800-53 Rev5 SI-4, CM-8). Fields: sensorVersion (textField.sensorVersion), lastSeen (dateField.lastSeen, mapped from last_seen).

A record is sent for review when: Last Seen is empty. Every record must satisfy: Sensor Version has a value. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Host Sensor Deployed

Verifies every CrowdStrike-managed host reports an installed sensor agent version, evidencing endpoint protection coverage (NIST 800-53 Rev5 SI-3, CM-8). Fields: hostName (textField.hostName), sensorVersion (textField.sensorVersion, mapped from agent_version).

Every record must satisfy: Hostname has a value and Sensor Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

CrowdStrike Console Users Have Assigned Roles

Account management / least privilege (NIST 800-53 Rev5 AC-2, AC-6): every Falcon console user must have at least one explicitly assigned role. Checks textField.roles is not empty.

Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prevention Policies

Test name

Test description

Test logic

Malicious Code Prevention Policy Enforcement

Ensures CrowdStrike prevention policies are enabled and actively enforced to prevent execution of malicious code across all applicable endpoints. Assessment Procedures:

Every record must satisfy: Enabled is true and Created On has a value. The test passes if at least 80% of records pass. If the proof contains no records, the test is marked failed.

Prevention Policy Assigned To Host Groups

Confirms enabled CrowdStrike prevention policies are assigned to at least one host group so protection is actually enforced (NIST 800-53 Rev5 SI-3, CM-6). Fields: enabled (booleanField.enabled), groups (textField.groups).

Every record must satisfy: Enabled is true and Groups has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Prevention Policy Enabled With Settings

Verifies each CrowdStrike prevention policy is enabled and has at least one prevention setting configured (NIST 800-53 Rev5 SI-3). Fields: enabled (booleanField.enabled), details (textField.details), name (textField.name).

Every record must satisfy: Enabled is true and Policy Details has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Sensor Update Policies

Test name

Test description

Test logic

Sensor Policy Version Pinned And Protected

Confirms enabled CrowdStrike sensor update policies pin an approved sensor version and do not disable uninstall protection (NIST 800-53 Rev5 SI-2, SI-3, CM-2). Fields: enabled (booleanField.enabled), sensor_version (textField.sensor_version), uninstall_protection (textField.uninstall_protection) whose disabled display value is Disabled.

Every record must satisfy: Enabled is true and Sensor Version has a value and Uninstall Protection does not equal "Disabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Sensor Uninstall Protection Enabled

Ensures enabled CrowdStrike sensor update policies enforce uninstall (tamper) protection so the agent cannot be removed by an attacker (NIST 800-53 Rev5 SI-3, SI-7, CM-5). Fields: enabled (booleanField.enabled), uninstall_protection (textField.uninstall_protection) which vlookups to the display value Enabled.

Every record must satisfy: Enabled is true and Uninstall Protection equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Sensor Update Policies

Verifies that CrowdStrike sensors installed on endpoints match the organization's approved sensor version and that sensor policies are actively enabled with uninstall protection enforced.

Every record must satisfy: Name has a value and Platform has a value and Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Datadog

Alert Configurations

Test name

Test description

Test logic

Datadog Monitors Have Critical and Warning Alert Thresholds

Verifies each Datadog monitor defines both a warning and a critical alerting threshold so operators get graduated notification before a failure. Supports NIST 800-53 Rev5 SI-4(5) / AU-5 by checking the criticalThreshold and warningThreshold fields are populated.

Every record must satisfy: Critical Threshold has a value and Warning Threshold has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Active Users

Test name

Test description

Test logic

Datadog Active Users Have Recorded Name and Email

Verifies every active Datadog account records both a name and an email so each account is attributable to a real identity for account management. Supports NIST 800-53 Rev5 AC-2 by checking the users' name and email fields are populated.

Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Hosts

Test name

Test description

Test logic

Datadog Hosts Are Actively Reporting (Agent Up)

Verifies every host in the Datadog inventory has an ACTIVE status, confirming its monitoring agent is up and telemetry is flowing. Supports NIST 800-53 Rev5 SI-4 / CM-8 by checking the hosts' status field.

Every record must satisfy: Status equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Datadog Hosts Have a Recorded OS Platform

Verifies every host in the Datadog inventory records its OS platform, ensuring the asset inventory is complete enough to map hosts to configuration baselines. Supports NIST 800-53 Rev5 CM-8 by checking the hosts' platform field is populated.

Every record must satisfy: Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Incidents

Test name

Test description

Test logic

Datadog Incidents Are Resolved or Completed

Verifies each Datadog incident has reached a closed state (Resolved or Completed) rather than lingering Active/Stable, evidencing incident closure. Supports NIST 800-53 Rev5 IR-4 / IR-5 by checking the incidents' state field.

A record is marked failed when: State is none of "Resolved" or "Completed". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Datadog Incidents Have a Triaged Severity

Fails any Datadog incident whose severity is still UNKNOWN, confirming each incident was triaged and assigned a severity for prioritized response. Supports NIST 800-53 Rev5 IR-4 by checking the incidents' severity field.

Every record must satisfy: Severity does not equal "UNKNOWN". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Monitors

Test name

Test description

Test logic

Datadog Monitors Are Actively Evaluating (No Data Gaps)

Fails any Datadog monitor in a 'No Data' state, which indicates the monitor is no longer receiving telemetry and monitoring coverage has silently broken. Supports NIST 800-53 Rev5 SI-4 / AU-6 by checking the monitors' status field.

Every record must satisfy: Status does not equal "No Data". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Datadog Monitors Have a Defined Alert Priority

Verifies every Datadog monitor has an assigned priority (not 'Not Defined') so alerts are ranked and routed for response. Supports NIST 800-53 Rev5 SI-4 / AU-6 by checking the monitors' priority field.

Every record must satisfy: Priority does not equal "Not Defined". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Dixa

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Elastic Cloud

Deployment Instances

Test name

Test description

Test logic

Elastic Cloud Deployment Instances Have Availability Zone Assigned

Verifies every Elastic Cloud deployment instance is placed in a named availability zone (zone is not empty), evidence of a resilient multi-zone topology baseline. Supports NIST SP 800-53 Rev 5 CP-2 (Contingency Planning) and CM-6 (Configuration Settings). Checks the 'zone' field emitted by the deploymentInstances proof.

Every record must satisfy: Zone has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Deployments

Test name

Test description

Test logic

Elastic Cloud Deployment Inventory Is Complete

Verifies each inventoried Elastic Cloud deployment record carries an identifying name and a resource kind (both non-empty), so the deployment inventory is complete and attributable. Supports NIST SP 800-53 Rev 5 CM-8 (System Component Inventory). Checks the 'name' and 'kind' fields emitted by the deployments proof.

Every record must satisfy: Name has a value and Applications has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elastic Cloud Deployment Inventory Record Is Complete

Confirms each deployment record carries a well-formed unique identifier and a name so it can be tracked in the system component inventory.

Every record must satisfy: Id has a value and Id matches the pattern "^[0-9a-fA-F]{32}$" and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Elastic Cloud Deployments Reside In US Regions

Verifies every Elastic Cloud deployment is hosted in a US cloud region (region name has a 'us-' segment at the start or after a provider prefix, e.g. us-east-1, aws-us-east-1, gcp-us-central1). Enforces data residency / data-location boundary requirements per NIST SP 800-53 Rev 5 SA-9 (External System Services) and AC-4 (Information Flow Enforcement). Uses a JS+.NET-compatible regex (no inline flags). Checks the 'region' field emitted by the deployments proof.

Every record must satisfy: Region matches the pattern "(^|-)us-". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Elastic Cloud Users Have An Organization Role Assigned

Verifies every Elastic Cloud organization user has at least one explicit role assignment (role is not empty), so no account has undefined or orphaned access. Supports least-privilege access governance per NIST SP 800-53 Rev 5 AC-2 (Account Management) and AC-6 (Least Privilege). Checks the 'role' field emitted by the userList proof.

Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elasticsearch

List of Users

Test name

Test description

Test logic

Elasticsearch Accounts Are Active

Account lifecycle management: verifies each listed account is enabled (active), supporting review that no disabled or dormant account is unexpectedly retained with access. NIST 800-53 Rev5 AC-2, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.16. Field checked: enabled.

Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elasticsearch Accounts Do Not Hold The Superuser Role

Restrict privileged access: flags accounts granted the built-in superuser role, which confers unrestricted cluster-wide privileges, so privileged access can be justified and minimized. NIST 800-53 Rev5 AC-6(5), NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2. Field checked: roles.

Every record must satisfy: Roles does not contain "superuser". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elasticsearch Accounts Do Not Use Generic Or Shared Names

Unique identification / no shared accounts: flags accounts whose username is a generic or shared identifier (admin, root, test, guest, shared, service) so each account maps to a single accountable identity. NIST 800-53 Rev5 IA-4 and AC-2, NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16. Field checked: username. Case-explicit anchored regex, no inline flags.

Every record must satisfy: User Name is none of "admin", "root", "test", "guest", "shared" or "service" (ignoring case). The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elasticsearch Accounts Have A Contact Email

Accountability / traceability of accounts to an individual: verifies each account records a contact email so ownership and communication for access reviews and incident response are possible. NIST 800-53 Rev5 AC-2 and IA-2, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.16. Field checked: email.

Every record must satisfy: Email Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Elasticsearch Accounts Have An Assigned Role

Least-privilege authorization: verifies every Elasticsearch account has at least one security role assigned (roles field not empty) so access is granted only through defined roles. NIST 800-53 Rev5 AC-6, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2, SOC 2 CC6.3. Field checked: roles.

Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

EngageATS

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Eploy

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Fountain

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

FreeAgent

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

FreshBooks

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Vendor and Customer Master Lists

Test name

Test description

Test logic

Supplier Master Records Have A Tax Identification Number

Flags supplier records on the vendor master list that have no tax identification number on file.

A record is marked failed when: Entity Type contains "Supplier" and Tax ID is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vendor And Customer Master Records Are Named And Classified

Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified.

Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Freshdesk

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Freshservice

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Front

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Gem

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitHub

Branch Protection

Test name

Test description

Test logic

GitHub Branch Protection Enabled

Confirms every monitored branch has a branch protection rule in effect (protectionEnabled=true). Unprotected branches allow direct pushes and force-pushes that bypass change control. Supports NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and SI-10 (Information Input Validation) / FedRAMP 20x. Field checked: booleanField.protectionEnabled.

Every record must satisfy: Branch Protection Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitHub Enforce Branch Protection For Administrators

Verifies branch protection rules also apply to repository administrators (enforceAdmins=true) so privileged users cannot bypass required reviews and status checks. Closes the common least-privilege gap where admins push directly to protected branches. Supports NIST SP 800-53 Rev 5 AC-6(1) (Authorize Access to Security Functions), CM-5 (Access Restrictions for Change), and CM-3. Field checked: booleanField.enforceAdmins.

Every record must satisfy: Include administrators is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitHub Require Code Owner Review And Dismiss Stale Approvals

Verifies protected branches require review from designated code owners and automatically dismiss stale approvals when new commits are pushed (requireCodeOwnerReview=true AND dismissStaleReviews=true). Prevents merging unreviewed changes slipped in after approval. Supports NIST SP 800-53 Rev 5 AC-5 (Separation of Duties), CM-3 (Configuration Change Control), and SA-11. Fields checked: booleanField.requireCodeOwnerReview, booleanField.dismissStaleReviews.

Every record must satisfy: Require review from Code Owners is true and Dismiss Stale Reviews is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitHub Require Pull Request Reviews Before Merging

Verifies each protected branch requires a pull request review with at least one approving reviewer before merge (requireReview=true AND requireApprovals>=1). Enforces peer review / separation of duties on code changes. Supports NIST SP 800-53 Rev 5 AC-5 (Separation of Duties), SA-11 (Developer Testing and Evaluation), and CM-3. Fields checked: booleanField.requireReview, numberField.requireApprovals.

Every record must satisfy: Require a pull request before merging is true and Required number of approvals is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitHub Require Status Checks Before Merging

Verifies protected branches require status checks (CI build, tests, security scans) to pass before a pull request can be merged (requiresStatusChecks=true). Prevents merging code that fails automated integrity and security gates. Supports NIST SP 800-53 Rev 5 SI-7 (Software, Firmware, and Information Integrity), SA-11 (Developer Testing and Evaluation), and CM-3. Field checked: booleanField.requiresStatusChecks.

Every record must satisfy: Require status checks to pass before merging is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

External Repository Members

Test name

Test description

Test logic

GitHub External Collaborators Read Only Access

Enforces least privilege for outside (external) repository collaborators: each must be limited to read-level access (permissions is 'Read' or 'Triage'), never Write/Maintain/Admin. The connector emits the display permission value, so operands match the rendered labels. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege), AC-3 (Access Enforcement), and AC-2 (Account Management). Field checked: textField.permissions.

Every record must satisfy: Permissions has a value. A record is marked failed when: Permissions is none of "Read" or "Triage". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Issues

Test name

Test description

Test logic

Open Issues Are Remediated Within 90 Days

Fails when an issue is still open more than 90 days after it was created, evidencing that tracked remediation items are closed within the expected window.

A record is sent for review when: Created is empty. A record is marked failed when: State equals "Open" and Created is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Open Issues Have An Assigned Owner

Fails when an open issue has no assignee, so every in-flight tracked item has a named person accountable for closing it.

A record is marked failed when: State equals "Open" and Assignee is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Member Repository Access

Test name

Test description

Test logic

GitHub Restrict Member Repository Admin Access

Enforces least privilege on a monitored member's repository access: the member must not hold admin permission on any repository (permissions != 'admin'). GitHub's collaborator permission API returns lowercase values (admin/maintain/write/triage/read/none). Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and AC-6(1). Field checked: textField.permissions.

Every record must satisfy: Permissions does not equal "admin". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Organization Members

Test name

Test description

Test logic

Check Deprovisioned Accounts

Validate that GitHub accounts are deprovisioned when personnel leave the organization.

Every record must satisfy: Username has a value and Name has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Validate Organization Member Roles

Verify that organization members have appropriate roles assigned.

Every record must satisfy: Username has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Repository Admins

Test name

Test description

Test logic

Validate Repository Admin Authorization

Confirm that only authorized personnel have administrative rights to repositories.

Every record must satisfy: Repository has a value and Access has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Repository Workflows

Test name

Test description

Test logic

GitHub Actions Workflows Active

Verifies each CI/CD GitHub Actions workflow is in the 'active' state (not disabled_manually or disabled_inactivity). Disabled security or build workflows silently stop enforcing automated tests, scans, and gates. The connector emits GitHub's lowercase workflow state value. Supports NIST SP 800-53 Rev 5 CM-6 (Configuration Settings), SI-7 (Software, Firmware, and Information Integrity), and SI-4. Field checked: textField.state.

Every record must satisfy: State equals "active". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Team Members

Test name

Test description

Test logic

Team Maintainer Privileges Are Reviewed

Surfaces every team member holding maintainer privileges so the reviewer can confirm each elevated role is still justified.

A record is sent for review when: Role equals "Maintainer". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab

Branch Protection

Test name

Test description

Test logic

GitLab Branch Protection Enabled

Verifies that every branch-protection rule returned for the repository actually has protection enabled. Missing or disabled protection on default/release branches allows unreviewed changes. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and AC-3 (Access Enforcement). Checks booleanField.protectionEnabled from the GitLab Branch Protection proof.

Every record must satisfy: Branch Protection Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitLab Protected Branch Force Push Disabled

Verifies that force push is not allowed on any protected branch. Force push can rewrite history and bypass the reviewed commit trail, undermining change integrity. Maps to NIST SP 800-53 Rev 5 CM-5 (Access Restrictions for Change) and SI-7 (Software, Firmware, and Information Integrity). Checks booleanField.allowForcePush from the GitLab Branch Protection proof.

Every record must satisfy: Allow force push is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitLab Protected Branch Push Access Restricted

Verifies that direct push to protected branches is not open to everyone. The connector emits the display string 'All' for the allowed-to-push level only when the branch is unprotected/unrestricted; a restricted branch reports a role list (e.g. 'Maintainers'). Enforces least privilege for change promotion. Maps to NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and CM-5 (Access Restrictions for Change). Checks textField.allowedToPush from the GitLab Branch Protection proof.

Every record must satisfy: Allowed to Push does not equal "All" and Allowed to Push does not contain "Developers". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Commits

Test name

Test description

Test logic

GitLab Commits Are Attributed To An Author

Checks that every GitLab commit records an author name.

Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Members

Test name

Test description

Test logic

GitLab Project Members Least Privilege

Access-review control: verifies no member on the reviewed group/project list holds the Owner role, which grants full administrative control (member management, deletion, protected-branch bypass). Owner assignments should be tightly scoped and reviewed. The connector maps GitLab access level 50 to the display string 'Owner' in maxRole. Maps to NIST SP 800-53 Rev 5 AC-6 (Least Privilege), AC-6(5) (Privileged Accounts) and AC-2 (Account Management). Checks textField.maxRole from the GitLab Members proof. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Max Role does not equal "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Merge Request Settings

Test name

Test description

Test logic

GitLab MR Approvals Reset On New Commits

Verifies the project requires new merge-request approvals when new commits are pushed after approval. Without this, an approved MR can be silently altered before merge, defeating change review. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and CM-5 (Access Restrictions for Change). Checks booleanField.approvalsOnPush from the GitLab Merge Request Settings proof.

Every record must satisfy: Require new approvals when new commits are added to an MR is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

GitLab MR Self Approval Prevented

Verifies separation of duties on merge-request approvals: the author cannot approve their own MR and users who committed to the MR cannot approve it. Enforces independent review of code changes. Maps to NIST SP 800-53 Rev 5 AC-5 (Separation of Duties) and CM-3 (Configuration Change Control). Checks booleanField.authorApproval (true = author approval prevented) and booleanField.disableCommittersApproval from the GitLab Merge Request Settings proof.

Every record must satisfy: Prevent MR approvals by the author is true and Prevent MR approvals from users who make commits to the MR is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Merge Requests

Test name

Test description

Test logic

GitLab Merged Requests Peer Approved

Verifies that every merge request merged into the target branch during the period carries at least one recorded approver. The connector emits the display string 'Approvers not available' when an MR was merged with no approval. Provides evidence of change review. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and AC-5 (Separation of Duties). Checks textField.approvedBy from the GitLab Merge Requests proof. Empty proof (no merges in period) is routed to Needs Review for human confirmation.

Every record must satisfy: Approved By has a value and Approved By does not equal "Approvers not available". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab Merged Requests Record Merger

Verifies that every merged merge request records the user who performed the merge, establishing accountability and a complete change-approval audit trail. The connector emits an empty string for mergedBy when no merger is recorded. Maps to NIST SP 800-53 Rev 5 AU-2 (Event Logging), AU-3 (Content of Audit Records) and CM-3 (Configuration Change Control). Checks textField.mergedBy from the GitLab Merge Requests proof. Empty proof (no merges in period) is routed to Needs Review.

Every record must satisfy: Merged By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab Self-Managed

Commits

Test name

Test description

Test logic

GitLab Commits Record Author Attribution

Change traceability / audit record generation: every commit in the branch history records an author name, supporting accountability and non-repudiation for code changes (NIST 800-53 Rev5 AU-3 / CM-3, ISO/IEC 27001:2022 A.8.15, CIS Control 8). Checks textField.authorName is not empty on the commitHistory proof.

Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Members

Test name

Test description

Test logic

GitLab Members Have Identifiable Email On Record

Account accountability / unique identification: each member account maps to a known email rather than the emitted placeholder 'N/A', so every access grant is attributable to an identifiable person (NIST 800-53 Rev5 AC-2 / IA-4, NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16). Checks textField.email is not empty and not 'N/A' on the listMembers proof.

Every record must satisfy: Email has a value and Email does not equal "N/A". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab Members Have Time-Bound Access Expiration

Access provisioning lifecycle: every group/project membership carries an expiration date so access is time-bound and forced through periodic re-certification (NIST 800-53 Rev5 AC-2(3), NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.18). Checks dateField.expiration is not empty on the listMembers proof.

Every record must satisfy: Access expires has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab Members Not Granted Owner Access

Least privilege / restriction of privileged access: no group or project member holds the Owner role, which grants full administrative control over the namespace (NIST 800-53 Rev5 AC-6(5), NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2). Checks textField.maxRole is not the emitted label 'Owner' on the listMembers proof.

Every record must satisfy: Max Role does not equal "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Merge Requests

Test name

Test description

Test logic

GitLab Merged Requests Have Documented Approvers

Change control / peer review and segregation of duties: every merged request records at least one approver instead of the emitted placeholder 'Approvers not available', evidencing that code changes were independently reviewed before merge (NIST 800-53 Rev5 CM-3 / SA-11, ISO/IEC 27001:2022 A.8.32, SOC 2 CC8.1). Checks textField.approvedBy is not empty and not 'Approvers not available' on the mergeRequests proof.

Every record must satisfy: Approved By has a value and Approved By does not equal "Approvers not available". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GitLab Merged Requests Record The Merging User

Change accountability: every merged request records the user who performed the merge, ensuring traceability of who introduced changes into the target branch (NIST 800-53 Rev5 CM-5 / AU-3, ISO/IEC 27001:2022 A.8.32). Checks textField.mergedBy is not empty on the mergeRequests proof.

Every record must satisfy: Merged By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Gladly

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Cloud Platform

Cloud Storage: Bucket Encryption

Test name

Test description

Test logic

GCP Cloud Storage Buckets Use Customer-Managed Encryption Keys

Verifies every Cloud Storage bucket is encrypted with a customer-managed key (CMEK) rather than the default Google-managed key. The connector emits encryptionType as the display value 'Customer-managed key' or 'Google-managed key'; test asserts textField.encryptionType = 'Customer-managed key'. Supports NIST SP 800-53 Rev 5 SC-12 / SC-28 (key management, protection at rest) and CIS GCP 3.7. Field checked: encryptionType.

Every record must satisfy: Encryption Type equals "Customer-managed key". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Cloud Storage: Bucket Lifecycle Rules

Test name

Test description

Test logic

Bucket Age-Based Lifecycle Delete Rules Retain Objects For At Least 30 Days

Flags storage lifecycle rules that permanently delete objects less than 30 days old, so data is not purged before its retention window elapses.

A record is marked failed when: Action contains "Delete" and Age is less than 30. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Bucket Lifecycle Rules Specify A Recognized Lifecycle Action

Checks that every storage bucket in scope has at least one lifecycle rule and that each rule names a recognized delete, storage-class transition, or abort-upload action.

Every record must satisfy: Bucket has a value and Action has a value and Action matches the pattern "(Delete|Set Storage Class|Abort Incomplete Multipart Upload)". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloud Storage: Bucket Replication

Test name

Test description

Test logic

Google Cloud Storage Buckets Use A Geo-Redundant Location Type

Checks that each Cloud Storage bucket is placed in a dual-region or multi-region location so object data is replicated across separate sites.

Every record must satisfy: Location Type has a value and Bucket Name has a value and Location has a value and Location Type does not equal "region". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloud Storage: Bucket Retention Settings

Test name

Test description

Test logic

Google Cloud Storage Buckets Enforce A Locked Retention Policy

Checks that each Cloud Storage bucket has a retention policy in place and that the policy is locked so objects cannot be deleted early.

Every record must satisfy: Bucket Name has a value and Retention Period does not equal "No Policy" and Effective Time has a value and Locked is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Cloud Storage: Bucket Settings

Test name

Test description

Test logic

GCP Cloud Storage Bucket Hardening Baseline

Baseline configuration check across every Cloud Storage bucket: object versioning enabled (textField.versioning = 'Enabled') AND customer-managed encryption (textField.encryptionType = 'Customer-managed key'). Both roll up as fail-fast AND per bucket. Supports NIST SP 800-53 Rev 5 CM-6 (configuration settings), SC-28 (protection at rest), CP-9 (backup) and CIS GCP 3.x storage hardening. Fields checked: versioning, encryptionType.

Every record must satisfy: Versioning equals "Enabled". Every record must satisfy: Encryption Type equals "Customer-managed key". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Cloud Storage: Bucket Versioning

Test name

Test description

Test logic

GCP Cloud Storage Object Versioning Enabled

Verifies object versioning is enabled on every Cloud Storage bucket so overwritten or deleted objects can be recovered. The connector emits versioning as the display value 'Enabled' or 'Disabled'; test asserts textField.versioning = 'Enabled'. Supports NIST SP 800-53 Rev 5 CP-9 (backup) / SI-12 (information handling and retention) and data-protection hardening. Field checked: versioning.

Every record must satisfy: Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Compute Engine: Firewall Rules

Test name

Test description

Test logic

GCP VPC Firewall Rule Logging Enabled

Verifies Firewall Rules Logging is enabled on every VPC firewall rule (booleanField.logConfig isTrue) so allowed/denied connections are auditable. Supports NIST SP 800-53 Rev 5 AU-2 / AU-12 (audit events, audit record generation) and CIS GCP 3.9. Field checked: logConfig (log configuration enable flag). Note: rules with no log configuration emit an empty logConfig, which correctly fails isTrue at threshold 1.0.

Every record must satisfy: Log Config is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Compute Engine: List of Disk Encryption Settings

Test name

Test description

Test logic

GCP Compute Disks Use Customer-Managed Encryption Keys

Verifies every Compute Engine persistent disk is encrypted with a customer-supplied or customer-managed key (booleanField.isCustomerManaged isTrue) instead of relying solely on Google default encryption. Supports NIST SP 800-53 Rev 5 SC-12 / SC-28 (key management, protection at rest) and CIS GCP 4.7. Field checked: isCustomerManaged.

Every record must satisfy: Customer-managed key is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Compute Engine: List of Images

Test name

Test description

Test logic

Google Cloud Custom Images Carry Inventory Labels And A Storage Location

Confirms every Compute Engine custom image carries inventory labels and a recorded storage location, so it can be attributed to an owner and purpose and located. Machine images are a separate resource and are not covered.

Every record must satisfy: Name has a value and Location has a value and Labels has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Cloud Custom Images Rebuilt Within The Last Year

Confirms every Compute Engine custom image in the project was rebuilt within the last year, so images do not drift far behind current patches. Machine images are a separate resource and are not covered.

A record is sent for review when: Creation Time is empty. A record is marked failed when: Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Compute Engine: List of Instance Groups

Test name

Test description

Test logic

Managed Instance Groups Deploy From An Instance Template

Checks that every managed instance group is backed by an instance template so all of its replicas launch from a governed baseline configuration.

A record is sent for review when: Template is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Managed Instance Groups Have Autoscaling Enabled

Confirms each managed instance group has an autoscaler attached so capacity adjusts to demand instead of remaining at a fixed size.

Every record must satisfy: Name has a value and Autoscaling is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Compute Engine: List of Instance Templates

Test name

Test description

Test logic

Instance Templates Are Refreshed Within The Last Year

Surfaces virtual machine templates created more than a year ago, which still pin their original base image because templates cannot be edited after creation.

A record is sent for review when: Creation Time is empty. A record is sent for review when: Creation Time has a value and Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Instance Templates Do Not Reference End Of Life Operating System Images

Flags virtual machine templates whose boot image is a Linux or Windows release that has reached end of life and no longer receives vendor security patches.

Every record must satisfy: Image has a value and Image does not match the pattern "(debian-(8|9|10)|ubuntu-(1204|1404|1604|1804)|centos-(6|7|8)|centos-stream-8|rhel-(6|7)|windows-(server-)?(2008|2012))". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Compute Engine: List of Snapshots

Test name

Test description

Test logic

GCP Snapshots Are Stored In United States Locations

Checks that every disk snapshot reports a United States storage location and flags any stored elsewhere or with no location reported.

A record is marked failed when: Location has a value and Location does not match the pattern "^us(-|$)". A record is sent for review when: Location is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GCP Snapshots Older Than One Year Are Reviewed For Retention

Surfaces disk snapshots created more than a year ago so they can be checked against your backup retention policy.

A record is sent for review when: Creation Time is empty. A record is sent for review when: Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Compute Engine: Minimum TLS Version

Test name

Test description

Test logic

GCP SSL Policies Enforce TLS 1.2 Minimum

Verifies every Compute SSL policy enforces a minimum TLS version of at least 1.2 (textField.minTlsVersion is one of 'TLS_1_2' or 'TLS_1_3', matched via a single OR condition with '=' arguments — never the illegal 'in' operator on text). Supports NIST SP 800-53 Rev 5 SC-8 / SC-23 (transmission confidentiality, session authenticity) and CIS GCP TLS hardening. Field checked: minTlsVersion (raw GCP enum e.g. TLS_1_0/TLS_1_1/TLS_1_2).

A record is marked failed when: Minimum TLS version is none of "TLS_1_2" or "TLS_1_3". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

IAM: Custom Project Roles

Test name

Test description

Test logic

Google Cloud Custom Project Roles Are Documented

Flags custom project roles that are missing a title or a description, so every custom role can be reviewed for appropriate privilege.

A record is marked failed when: Description is empty. A record is marked failed when: Title is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kubernetes Engine: List of Pod Security Policies

Test name

Test description

Test logic

GKE Pods Declare A Pod-Level Security Context

Surfaces Kubernetes pods that declare no pod-level user or non-root setting, so their runtime privilege level can be reviewed.

A record is sent for review when: Run As Non Root is empty and Run As User is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GKE Pods Do Not Run As The Root User Or Group

Flags Kubernetes pods whose pod-level security context explicitly requests root: non-root disabled, user ID 0, or group ID 0.

A record is marked failed when: Run As Non Root is false. A record is marked failed when: Run As User equals 0. A record is marked failed when: Run As Group equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kubernetes Engine: List of Workloads

Test name

Test description

Test logic

GKE Workloads Are Not Deployed To The Default Namespace

Flags Kubernetes deployments running in the default namespace instead of a purpose-built namespace.

A record is marked failed when: Namespace equals "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GKE Workloads Report Available Pods And A Healthy Condition

Flags Kubernetes deployments that have no available pods, or whose most recent status condition is not healthy.

A record is marked failed when: Pods matches the pattern "^0/[1-9]". A record is marked failed when: Status has a value and Status does not equal "OK". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SQL: Backup Configuration

Test name

Test description

Test logic

GCP Cloud SQL Automated Backups Enabled

Verifies every Cloud SQL instance has automated backups enabled (booleanField.enabled isTrue). Supports contingency planning / backup requirements: NIST SP 800-53 Rev 5 CP-9 (System Backup) and CIS GCP Foundations 6.7. Field checked: enabled (Backup Enabled).

Every record must satisfy: Backup Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GCP Cloud SQL Point-in-Time Recovery And Backup Retention

Verifies each Cloud SQL instance enables point-in-time recovery (booleanField.pointInTimeRecoveryEnabled isTrue) and retains at least 7 automated backups (numberField.retainedBackups >= 7). Both conditions roll up as fail-fast AND per instance. Supports NIST SP 800-53 Rev 5 CP-9 / CP-10 (recovery) and CIS GCP 6.7. Fields checked: pointInTimeRecoveryEnabled, retainedBackups.

Every record must satisfy: Point In Time Recovery is true. Every record must satisfy: Retained Backups is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SQL: Backup Runs

Test name

Test description

Test logic

GCP Cloud SQL Backup Runs Completed Successfully

Verifies every recorded Cloud SQL backup run completed successfully (textField.status = 'SUCCESSFUL', the GCP backup-run status enum) so backup evidence is proven, not just configured. Supports NIST SP 800-53 Rev 5 CP-9 (System Backup) / CP-10 (recovery) and CIS GCP 6.7. Field checked: status (raw GCP enum e.g. SUCCESSFUL/FAILED/SKIPPED).

Every record must satisfy: Status equals "SUCCESSFUL". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

VPC: List of Networks

Test name

Test description

Test logic

Default VPC Network Is Not Present

Checks that the automatically created default virtual network has been removed from each project so workloads run only on deliberately designed networks.

Every record must satisfy: ID has a value and Name does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

VPC Networks Use Custom Subnet Mode

Verifies each virtual network is in custom subnet mode rather than automatically creating a subnet in every region with predetermined address ranges.

Every record must satisfy: Name has a value and Mode equals "Custom". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

VPC: List of Subnets

Test name

Test description

Test logic

GCP Subnets Do Not Belong To The Default VPC Network

Flags VPC subnets that belong to the auto-created default network rather than a purpose-built VPC.

A record is marked failed when: Network equals "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

GCP Subnets Use Private IPv4 Address Space

Flags VPC subnets whose IPv4 range falls outside private (RFC 1918 / RFC 6598) address space.

A record is marked failed when: IPv4 CIDR has a value and IPv4 CIDR does not match the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|100\.(6[4-9]|[7-9][0-9]|1[01][0-9]|12[0-7])\.)". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Google Workspace

Admin Audit Log

Test name

Test description

Test logic

Google Workspace - Admin Audit Log Freshness (30-Day)

Verifies that the Google Workspace administrative audit log is being collected and is current within the last 30 days. Supports NIST SP 800-53 Rev. 5 AU-2 and AU-6 and FedRAMP 20x KSI-MLA-RVL and KSI-CMT-LMC.

A record is sent for review when: Date is empty. A record is marked failed when: Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Group Membership

Test name

Test description

Test logic

Groups Do Not Grant Whole-Domain Membership

Flags groups that grant membership to the entire organization instead of to named users or groups.

A record is marked failed when: Type equals "CUSTOMER". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Chrome Devices

Test name

Test description

Test logic

Enrolled Chrome Devices Record User And Serial Number

Checks that every enrolled Chrome device records an assigned user and a serial number.

Every record must satisfy: User has a value and Serial Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Workspace Chrome Devices Record An Operating System Version

Checks that each enrolled Chrome device records its operating system version.

Every record must satisfy: OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Groups

Test name

Test description

Test logic

Google Workspace Groups Do Not Permit Domain-Wide Open Access

Checks that no Google Workspace group is configured so that anyone in the domain can join it, view its membership, and post to it.

Every record must satisfy: Access Type has a value and Access Type does not equal "Public". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Inbound SAML SSO Profiles

Test name

Test description

Test logic

Google Workspace - SSO SAML Profile Configured

Verifies that the Google Workspace organization has at least one inbound SAML single sign-on profile configured with an identity-provider entity ID. Supports NIST SP 800-53 Rev. 5 IA-2, IA-8, and AC-17(1) and FedRAMP 20x KSI-IAM-AAM. Note: confirms SSO is configured, not enforced for every user.

Every record must satisfy: IDP Entity ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Google Workspace - MFA Enforced for All Users

Verifies that 2-Step Verification (multi-factor authentication) is enforced (not merely available) for every Google Workspace user account. Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA.

Every record must satisfy: MFA Enforced is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Workspace - MFA Enrolled for All Users

Verifies that every Google Workspace user account is enrolled in 2-Step Verification (multi-factor authentication). Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA.

Every record must satisfy: MFA Enrolled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Workspace - No Users With 90-Day Inactivity

Identifies Google Workspace accounts that have not signed in within the last 90 days so that stale or unused accounts can be reviewed, disabled, or removed. Supports NIST SP 800-53 Rev. 5 AC-2(3) and FedRAMP 20x KSI-IAM-SUS.

A record is sent for review when: Last Sign In is empty. A record is marked failed when: Last Sign In is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Login Audit Log

Test name

Test description

Test logic

Google Workspace - Login Audit Log Freshness (30-Day)

Verifies that the Google Workspace login (authentication) audit log is being collected and is current within the last 30 days. Supports NIST SP 800-53 Rev. 5 AU-2 and AU-6 and FedRAMP 20x KSI-MLA-LET.

A record is sent for review when: Date is empty. A record is marked failed when: Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Security Report

Test name

Test description

Test logic

Google Workspace - Less Secure App Access Disabled for All Users

Verifies that 'less secure app' (legacy/basic-auth) access is disabled for every Google Workspace user account, closing a password-only sign-in path that bypasses 2-Step Verification. Supports NIST SP 800-53 Rev. 5 AC-6(5) and CM-7 and FedRAMP 20x KSI-IAM-ELP.

Every record must satisfy: Less Secure Apps Access is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Google Workspace - Security Keys Enrolled for All Users

Verifies that every Google Workspace user account has at least one hardware security key enrolled for phishing-resistant multi-factor authentication. Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA. Note: requiring hardware security keys is a phishing-resistant posture that exceeds the FedRAMP Moderate baseline.

Every record must satisfy: Security Keys Enrolled is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Gorgias

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Greenhouse

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Help Scout

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Hive

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Homerun

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

HubSpot

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

HubSpot Ticketing

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Infinite BrassRing

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Insightly

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Intercom

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Ironclad

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Jamf

List of Computer Groups

Test name

Test description

Test logic

Automate verification that macOS devices are correctly assigned to authorized computer groups.

Checks if macOS devices are assigned to authorized computer groups.

Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Computer Groups Record Id Name And Smart Static Classification

Confirms every computer group records a stable id, a name, and its smart/static classification so policy scoping targets are well defined. Supports NIST 800-53 Rev5 CM-8 (System Component Inventory) and CM-2 (Baseline Configuration). Fields: id, name, isSmart.

Every record must satisfy: ID has a value and Name has a value and Is Smart has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Computers

Test name

Test description

Test logic

Validate asset details including hostname, serial numbers, OS versions, hardware configurations, and inventory updates.

Validate asset details including hostname, serial numbers, OS versions, hardware configurations, and inventory updates.

Every record must satisfy: Name has a value and Username has a value and Model has a value and Operating System has a value and OS Version has a value and FileVault 2 Partition Encryption State has a value. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed.

Verify FileVault Disk Encryption Is Enabled On All Managed macOS Computers

Confirms managed Macs report their boot partition as ENCRYPTED (FileVault). Supports NIST 800-53 Rev5 SC-28 (Protection of Information at Rest). Fields: fileVault2EncryptionState, managed.

Every record must satisfy: FileVault 2 Partition Encryption State equals "ENCRYPTED" and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Jamf accurately records and maintains the current inventory of all managed macOS computers.

Verify Jamf accurately records and maintains the current inventory of all managed macOS computers.

Every record must satisfy: Operating System matches the pattern "[Mm][Aa][Cc] ?[Oo][Ss]" and Managed is true. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed.

Verify Operating System Name And Version Are Recorded For Managed Computers

Confirms managed Macs report both OS name and OS version so patch level and vulnerability exposure can be assessed. Supports NIST 800-53 Rev5 SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring). Fields: operatingSystem, operatingSystemVersion, managed.

Every record must satisfy: Operating System has a value and OS Version has a value and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify The Host Firewall Is Enabled On All Managed macOS Computers

Confirms managed Macs report the built-in application firewall as enabled. Supports NIST 800-53 Rev5 SC-7 (Boundary Protection). Fields: firewallEnabled, managed.

Every record must satisfy: Firewall Enabled is true and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Mobile Devices

Test name

Test description

Test logic

Verify accurate inventory of enrolled iOS and iPadOS devices in Jamf

Verify accurate inventory of enrolled iOS and iPadOS devices in Jamf

Every record must satisfy: Device Name has a value and Model has a value and Username has a value and Managed is true. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed.

Verify Enrolled Mobile Devices Are Managed And Inventoried

Confirms every enrolled iOS/iPadOS device is Jamf-managed and carries an inventory id and model. Supports NIST 800-53 Rev5 CM-8 (System Component Inventory) and AC-19 (Access Control for Mobile Devices). Fields: managed, model, id.

Every record must satisfy: Managed is true and Model has a value and ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Managed Mobile Devices Have An Assigned User

Confirms each managed mobile device records an assigned user for accountability and ownership tracking. Supports NIST 800-53 Rev5 AC-19 (Access Control for Mobile Devices) and CM-8 (component ownership). Fields: username, managed.

Every record must satisfy: Username has a value and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of OSX Configuration Profiles

Test name

Test description

Test logic

Automate regular validation of enforced configuration profiles to maintain macOS security integrity.

Checks that every macOS configuration profile returned by Jamf carries an identifier and a name, so the enforced profile set is enumerable and attributable. Does not evaluate individual profile payload settings such as screen lock timeout or login window, which this proof type does not expose.

Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Automate validation of macOS profile enforcement, including screen lock timeout and login window settings

Checks that every macOS configuration profile returned by Jamf carries an identifier and a name. Does not evaluate screen lock timeout or login window settings: the profile list proof exposes only the profile identifier and name, not payload contents.

Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Policies

Test name

Test description

Test logic

Automate checks that all Jamf policies enforce approved baseline configurations.

Automate checks that all Jamf policies enforce approved baseline configurations.

Every record must satisfy: Name has a value and Enabled is true and Triggers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Automate verification of scheduled maintenance tasks, including updates and patching policies.

Checks if scheduled macOS maintenance and patching policies run as intended.

Every record must satisfy: Name has a value and Enabled is true and Triggers has a value. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed.

Validate policy deployment status and ensure no unauthorized changes occur without proper approvals

Checks if deployed Jamf policies match approved baselines.

Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Enabled Policies Have A Defined Execution Frequency

Confirms enabled Jamf policies specify an execution frequency so maintenance and patch automation runs on a defined cadence. Supports NIST 800-53 Rev5 SI-2 (Flaw Remediation) and CM-6 (Configuration Settings). Fields: enabled, executionFrequency, name.

A record is marked failed when: Enabled is true and Execution Frequency is empty. A record is marked failed when: Enabled is true and Name is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Verify Every Policy Has A Stable Identifier Name And Trigger

Confirms each policy records a stable id, a name, and a trigger so configuration changes are traceable and reviewable. Supports NIST 800-53 Rev5 CM-2 (Baseline Configuration) and CM-3 (Configuration Change Control). Fields: policyId, name, trigger.

Every record must satisfy: ID has a value and Name has a value and Triggers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Restricted Software

Test name

Test description

Test logic

Restricted Software Rules Notify On Detection

Checks that each restricted software rule raises a notification when it triggers, so attempts to run prohibited software are surfaced to administrators.

Every record must satisfy: Name has a value and Send Notification is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Restricted Software Rules Terminate Prohibited Processes

Checks that each restricted software rule names a target process and is set to terminate it, so prohibited applications are actually blocked rather than just recorded.

Every record must satisfy: Process Name has a value and Kill Process is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

OSX Configuration Profile

Test name

Test description

Test logic

Configuration Profile Is Auto Installed And Not User Removable

Confirms the selected macOS configuration profile installs automatically and cannot be removed by the end user, so its settings stay enforced on the device.

Every record must satisfy: Distribution Method equals "Install Automatically" and User Removable is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Configuration Profile Is Scoped To The Computer Level

Confirms the selected macOS configuration profile applies at the computer level so its settings cover every user of the device, not just one account.

Every record must satisfy: Name has a value and Level contains "computer". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JazzHR

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Jira Cloud (OAuth)

List of Issues

Test name

Test description

Test logic

Incident Management Tasks Completed

Checks that each issue in the Jira issue list records an issue type and a status.

Every record must satisfy: Issue Type has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Incident Resolution Tasks Completed

Ensure that all incident issues have a resolution date.

Every record must satisfy: Issue Type has a value and Resolution has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

P0 Security Issues Resolved

Ensure that all P0 (highest priority) security issues are resolved.

Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes if at least 70% of records pass. If the proof contains no records, the test is marked failed.

P1 Security Issues Resolved

Ensure that all P1 security issues are resolved.

Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Records of Security Issues Being Assigned to Owners

Verify that all security issues are assigned to an owner.

Every record must satisfy: Issue Type has a value and Assignee has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Jira Cloud (Token Auth)

List of Groups

Test name

Test description

Test logic

Jira Groups Have At Least One Member

Checks that every group in the Jira site has at least one member, flagging empty groups that linger with permissions still attached.

Every record must satisfy: Name has a value and Members is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Approval Verification

Verify all change issues are approved before work.

Every record must satisfy: Issue Type has a value and Assignee has a value. A record is marked failed when: Status is none of "Awaiting Approval" or "Approved". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Incident Resolution Timeliness

Validate timely resolution of incident issues.

Every record must satisfy: Issue Type has a value and Status has a value and Priority has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Jira Cloud - No Deactivated Accounts in User Access List

Flags deactivated Jira Cloud accounts that still appear in the user access list so their access and group membership can be removed.

Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Jira Server

List of Groups

Test name

Test description

Test logic

Jira Access Groups Contain At Least One Member

Access-construct hygiene / stale-entitlement cleanup: every Jira Server group must have at least one member so that empty, dormant, or abandoned access groups are identified and removed as part of periodic access review. Maps to NIST 800-53 Rev5 AC-2 (account/group management) and AC-6, NIST 800-171 3.1.5, and ISO/IEC 27001:2022 A.5.18 (access rights review). Checks groupList field members is greater than 0.

Every record must satisfy: Members is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Issues

Test name

Test description

Test logic

Incident Management Tasks Completed

Checks that each issue in the Jira issue list records an issue type and a status.

Every record must satisfy: Issue Type has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Incident Resolution Tasks Completed

Ensure that all incident issues have a resolution date.

Every record must satisfy: Issue Type has a value and Resolution has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

P0 Security Issues Resolved

Ensure that all P0 (highest priority) security issues are resolved.

Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes if at least 70% of records pass. If the proof contains no records, the test is marked failed.

P1 Security Issues Resolved

Ensure that all P1 security issues are resolved.

Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Records of Security Issues Being Assigned to Owners

Verify that all security issues are assigned to an owner.

Every record must satisfy: Issue Type has a value and Assignee has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Jira User Accounts Are Assigned To At Least One Access Group

Least-privilege / role-based access hygiene: every Jira Server user account must belong to at least one group so that access is governed through defined group-based authorization rather than ad hoc or orphaned accounts. Maps to NIST 800-53 Rev5 AC-6 (least privilege) and AC-2, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.5.18 (access rights), and SOC 2 CC6.1/CC6.3. Checks userList field groupNames is non-empty.

Every record must satisfy: Group has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Jira User Accounts Have Complete Identity Attributes

Access accountability / unique user identification: every Jira Server account in the user list must have a display name and an email address on file so that access can be attributed to a real, identifiable person. Maps to NIST 800-53 Rev5 AC-2 (account management) and IA-4 (identifier management), NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16 (identity management), and SOC 2 CC6.1. Checks userList fields displayName and emailAddress are non-empty.

Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JobAdder

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JobDiva

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JobScore

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Jobvite

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud

Directory Events

Test name

Test description

Test logic

JumpCloud - Audit Records Capture Event Type and Source IP

NIST 800-53 Rev5 AU-3: audit records must establish what type of event occurred and its source. Checks each Directory Insights record carries a non-empty eventType and clientIp. An empty result is reported as needing review rather than failing: AU-3 governs what an audit record contains, and a window that produced no records is indistinguishable from a collection that did not run, so it is put in front of a person instead of judged.

Every record must satisfy: Event Type has a value and Client IP has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JumpCloud - Directory Insights Audit Events Carry A Timestamp

Checks that each Directory Insights audit event carries a timestamp. Empty proof is routed to review because absent events mean nothing was collected rather than nothing happened.

A record is sent for review when: Timestamp is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JumpCloud Audit Records Identify The Initiating Account

Routes Directory Insights audit records that carry no initiating account to review.

A record is sent for review when: Initiator is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Devices

Test name

Test description

Test logic

JumpCloud Device Inventory Records Are Complete

NIST SP 800-53 CM-8: system component inventory. Verifies every JumpCloud managed device records a device name, operating system, and serial number.

Every record must satisfy: Device Name has a value and OS has a value and Serial Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Devices Have Checked In Recently

NIST SP 800-53 CM-8/SI-4: managed devices must remain actively monitored. Verifies every JumpCloud managed device last contacted the directory within the past 30 days, flagging stale or abandoned endpoints. Field: lastContact (date).

A record is sent for review when: Last Contact is empty. A record is marked failed when: Last Contact is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JumpCloud Devices Record Operating System Baseline

NIST SP 800-53 CM-8/CM-2: component inventory must capture the software baseline. Verifies every JumpCloud managed device records its operating system, OS family, and OS version. Fields: os, osFamily, version.

Every record must satisfy: OS has a value and OS Family has a value and OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Managed Devices Are Active

NIST SP 800-53 CM-8: maintain an accurate inventory of active system components. Verifies every JumpCloud managed device reports an Active status so decommissioned or disconnected devices are surfaced. Field: status (vlookup display value Active/Inactive).

Every record must satisfy: Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

JumpCloud User Passwords Are Active and Not Expired

NIST SP 800-53 IA-5: authenticator management. Verifies every JumpCloud user account has an active password state (not expired or pending), confirming credentials are managed and current.

Every record must satisfy: Password State equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud User Passwords Are Not Expired

NIST SP 800-53 IA-5: authenticator management. Verifies no JumpCloud user account is left with an expired password, which would indicate a stale credential still present on the directory. Field: passwordState (vlookup display value Active/Pending/Expired).

Every record must satisfy: Password State does not equal "Expired". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud User Records Identify an Account Owner

NIST SP 800-53 AC-2: account records must identify the individual owner. Verifies every JumpCloud user account records a first and last name so accounts are attributable. Fields: firstname, lastname.

Every record must satisfy: First Name has a value and Last Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud User Records Include Username and Email

NIST SP 800-53 AC-2: account management requires identifiable account records. Verifies every JumpCloud user has a username and email address.

Every record must satisfy: User Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Users Are Enrolled in Multi-Factor Authentication

NIST SP 800-53 IA-2(1): multi-factor authentication for network access. Verifies every JumpCloud user account is enrolled in MFA.

Every record must satisfy: MFA Enrollment equals "Enrolled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Password Policy

Test name

Test description

Test logic

JumpCloud Password Policy Enforces a Minimum Length

NIST SP 800-53 IA-5(1): password-based authenticators must meet a minimum length. Verifies the JumpCloud password policy requires at least 12 characters.

Every record must satisfy: Minimum length in characters is 12 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Enforces Account Lockout

NIST SP 800-53 AC-7: limit consecutive invalid logon attempts. Verifies the JumpCloud password policy enables lockout and locks accounts after at most 5 failed attempts.

Every record must satisfy: Enable failed password + TOTP MFA attempts until lockout is true and Failed password + TOTP MFA attempts until lockout is 5 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Enforces Failed-Attempt Counter Reset Window

NIST SP 800-53 AC-7(a): enforce a limit of consecutive invalid attempts over a time window. Verifies the JumpCloud password policy enables the reset-lockout counter and uses a window of at least 15 minutes so failed attempts are counted across a meaningful period. Fields: enableResetLockoutCounter, resetLockoutCounterMinutes.

Every record must satisfy: Enable failed password attempts counter is true and Minutes until failed password attempts counter is automatically reset is 15 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Enforces Lockout Duration

NIST SP 800-53 AC-7(b): automatically lock a locked-out account for a defined duration. Verifies the JumpCloud password policy enables a lockout time and holds the account for at least 900 seconds (15 minutes). Fields: enableLockoutTimeInSeconds, lockoutTimeInSeconds.

Every record must satisfy: Enable time until lockout is automatically unlocked is true and Seconds until lockout is automatically unlocked is 900 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Enforces Password Expiration

NIST SP 800-53 IA-5(1): enforce a maximum password lifetime. Verifies the JumpCloud password policy enables password expiration and forces rotation within at most 90 days. Fields: enablePasswordExpirationInDays, passwordExpirationInDays.

Every record must satisfy: Enable days until password expiration is true and Days until password expiration is 90 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Enforces Password Reuse History

NIST SP 800-53 IA-5(1): prevent reuse of previous passwords. Verifies the JumpCloud password policy enables password history and retains at least 24 prior passwords.

Every record must satisfy: Enable most recent passwords cannot match is true and Most recent passwords that cannot match is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Prohibits Username in Password

NIST SP 800-53 IA-5: passwords must not contain the account username. Verifies the JumpCloud password policy disallows the username as a password substring.

Every record must satisfy: Allow username within password is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JumpCloud Password Policy Requires Mixed Case, Number, and Symbol

NIST SP 800-53 IA-5(1): password complexity. Verifies the JumpCloud password policy requires lowercase, uppercase, numeric, and symbol characters.

Every record must satisfy: Must include a lowercase letter is true and Must include an uppercase letter is true and Must include a number is true and Must include a special character is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Policy Results

Test name

Test description

Test logic

JumpCloud - Configuration Policy Applied Successfully to All Systems

NIST 800-53 Rev5 CM-6: the configuration baseline (JumpCloud policy) must be enforced on every targeted system. Checks the per-system policy result 'state' equals 'success'. Empty result returns needsReview because no systems reported a status.

Every record must satisfy: Status equals "success". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JumpCloud - Policy Results Identify Target System and OS

NIST 800-53 Rev5 CM-8: systems under a configuration policy must be inventoried and identifiable. Checks that each policy result row carries a non-empty systemName and os so the enforced baseline maps to a known managed component. Empty result returns needsReview.

Every record must satisfy: System Name has a value and OS has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Group Membership List

Test name

Test description

Test logic

JumpCloud - No Suspended Users Retain Group Membership

Checks that no suspended JumpCloud user retains group membership. Empty proof is routed to review because zero rows means nothing was collected, not that nothing is wrong.

Every record must satisfy: User State does not equal "Suspended". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JumpCloud - User Group Members Are Enrolled in MFA

NIST 800-53 Rev5 IA-2(1): every member of the reviewed JumpCloud user group must have multi-factor authentication enrolled. Checks the mfaEnrollment display field equals 'Enrolled'. Empty group returns needsReview because enrollment cannot be asserted with no members.

Every record must satisfy: MFA Enrollment equals "Enrolled". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JupiterOne

List of Alerts

Test name

Test description

Test logic

JupiterOne Alerts Have Known Severity Rating

Verifies every JupiterOne alert finding carries a recognized severity rating (CRITICAL, HIGH, MEDIUM, LOW, or INFO) so findings can be triaged and prioritized (NIST SP 800-53 Rev 5 CA-7, RA-5). Uses one OR condition of equality checks on textField.severity (avoids the illegal text 'in' operator).

A record is marked failed when: Severity is none of "CRITICAL", "HIGH", "MEDIUM", "LOW" or "INFO". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JupiterOne No Critical Severity Alerts

Verifies no JupiterOne alert finding is classified CRITICAL severity, evidencing timely remediation of the most severe risks (NIST SP 800-53 Rev 5 RA-5, SI-2). Checks textField.severity.

Every record must satisfy: Severity does not equal "CRITICAL". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JupiterOne No High Or Critical Severity Alerts

Verifies no JupiterOne alert finding is HIGH or CRITICAL severity, evidencing that high-risk security findings are remediated within SLA (NIST SP 800-53 Rev 5 RA-5, SI-2). Single condition ANDs two inequality checks on textField.severity so both must hold per row.

Every record must satisfy: Severity is none of "CRITICAL" or "HIGH". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Assets

Test name

Test description

Test logic

JupiterOne Asset Inventory Records Complete

Verifies every discovered asset in the JupiterOne graph has both a name and a resource type populated, evidencing a complete and identifiable system component inventory (NIST SP 800-53 Rev 5 CM-8). Single condition ANDs textField.name !isEmpty and textField.type !isEmpty. Empty proof fails because an empty asset inventory is itself a control gap.

Every record must satisfy: Name has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

JupiterOne Assets Classified In Graph

Verifies every asset carries at least one graph class (e.g. DataStore, Host, Bucket) so assets are categorized for control mapping and risk assessment (NIST SP 800-53 Rev 5 CM-8, RA-2). Checks textField.class !isEmpty (the class column is a comma-joined list of entity classes). Empty proof fails because an empty inventory cannot evidence classification.

Every record must satisfy: Class has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

JupiterOne Active Accounts With No Sign-In In 90 Days

Flags active JupiterOne accounts that have not signed in within the last 90 days.

A record is marked failed when: Active is true and Last Login is more than 90 days in the past. A record is sent for review when: Active is true and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JupiterOne No Inactive User Accounts

Verifies every JupiterOne user account is active, evidencing that disabled or deprovisioned accounts have been removed rather than lingering (NIST SP 800-53 Rev 5 AC-2, AC-2(3)). Checks booleanField.isActive isTrue (operand omitted).

Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

JupiterOne User Accounts Have Email Identifier

Verifies every JupiterOne user account has an email address so each account maps to an identifiable individual for access reviews and accountability (NIST SP 800-53 Rev 5 AC-2, IA-2). Checks textField.email !isEmpty.

Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji

List of Device Details

Test name

Test description

Test logic

Kandji - Device Enrollment Timestamps Recorded

Verifies that every managed device records both a first-enrollment and last-enrollment timestamp, evidencing that MDM enrollment lifecycle data is complete for each asset. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory) and CM-8(3) (Automated Unauthorized Component Detection). Fields: firstEnrollment, lastEnrollment.

Every record must satisfy: First Enrollment has a value and Last Enrollment has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Kandji - Device OS Version Recorded in Valid Format

Verifies that every managed device reports a non-empty OS version in a valid numeric dotted-version format (e.g. 18.3, 14.7.1), which is a prerequisite for flaw-remediation/patch-level assessment across the fleet. Supports NIST SP 800-53 Rev. 5 SI-2 (Flaw Remediation) and CM-8. Field: osVersion.

Every record must satisfy: OS Version has a value and OS Version matches the pattern "^[0-9]+(\.[0-9]+)*$". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Kandji - Managed Devices Run a Supported Apple Platform

Verifies that every device in Kandji device details reports a supported, MDM-managed Apple platform (Mac, iPad, or iPhone), so no unexpected/unmanaged platform is present in the enrolled fleet. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory). Field: platform.

A record is marked failed when: Platform is none of "Mac", "iPad" or "iPhone". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji Devices Are Enrolled In MDM

CM-2/CM-8: every device in the details report must carry an MDM enrollment timestamp, evidencing it is under managed configuration control. Checks firstEnrollment is non-empty on hp_listDeviceDetails.

Every record must satisfy: First Enrollment has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji Devices Belong To An Approved Platform Type

CM-6/CM-8: only approved Apple device platforms (Mac, iPhone, iPad, Apple TV) may be enrolled per the configuration baseline. On hp_listDeviceDetails, platform must regex-match the approved set; any other value fails.

Every record must satisfy: Platform is one of "Mac", "iPhone", "iPad" or "AppleTV". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji Devices Report An OS Version

SI-2: an OS version must be recorded for every managed device so patch level and flaw-remediation status can be assessed. Checks osVersion is non-empty on hp_listDeviceDetails.

Every record must satisfy: OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji macOS Devices Run A Supported OS Version

SI-2/CM-6: macOS devices must run a vendor-supported major version (macOS 14 Sonoma or later) to remain eligible for security updates. On hp_listDeviceDetails, a row passes if it is not a Mac or its osVersion begins with major version 14+.

A record is marked failed when: Platform equals "Mac" and OS Version has a value and OS Version does not match the pattern "^(1[4-9]|[2-9][0-9])\.". A record is sent for review when: Platform equals "Mac" and OS Version is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Devices

Test name

Test description

Test logic

Kandji - Device Inventory Hardware Identifiers Populated

Verifies that every enrolled device inventory record has a device name, serial number, and hardware model populated, so each asset is uniquely and completely identified in the inventory. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory). Fields: deviceName, serialNumber, model.

Every record must satisfy: Device Name has a value and Serial Number has a value and Model has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Kandji - Device Serial Numbers Well-Formed

Verifies that every device inventory record carries a non-empty serial number matching the expected uppercase-alphanumeric hardware serial format, supporting reliable unique asset identification and anti-tamper tracking. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory) and CM-8(1). Field: serialNumber.

Every record must satisfy: Serial Number has a value and Serial Number matches the pattern "^[A-Z0-9]{8,14}$". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Kandji Devices Have An Asset Tag Assigned

CM-8: each managed device must be labeled with an organizational asset tag for property accountability. Checks assetTag is non-empty on hp_listDevices. Asset tag is an optional Kandji field, so devices without a tag will fail at threshold 1.0 (the intended finding).

Every record must satisfy: Asset Tag has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Kandji Active User Roster Excludes Archived Accounts

AC-2: archived (offboarded) accounts must not remain in the active user roster. Checks the archived flag is false for every row on hp_users; an archived account present fails.

Every record must satisfy: Archived is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Kandji Users Have An Email Identifier

IA-4/AC-2: each directory user must have a unique email identifier for account management and attribution. Checks email is non-empty on hp_users.

Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Keap

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

KnowBe4

List of Acknowledgments

Test name

Test description

Test logic

KnowBe4 - Assigned Policies Are Acknowledged and Completed

Verifies that every assigned policy has been acknowledged by the user and carries a completion date, so acknowledgment is evidenced per person.

Every record must satisfy: Policy Ack. Status equals "Acknowledged" and Completed On has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

KnowBe4 - No Past Due Policy or Training Assignments

Flags policy and training assignments the platform has marked past due, identifying users who have missed their required completion date.

A record is marked failed when: Status equals "Past Due". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Groups

Test name

Test description

Test logic

KnowBe4 - Active Groups Have Assigned Members

Flags active groups that have no members, since group membership drives training and policy campaign enrollment and an empty group enrolls no one.

A record is sent for review when: Member Count equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

KnowBe4 - User Risk Scores Within Tolerance

Checks that no active user carries a risk score above the acceptable threshold, so high-risk individuals can be given targeted follow-up.

Every record must satisfy: Email has a value and Risk Score is 50 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

KnowBe4 Accounts With No Sign-In In 90 Days

Flags KnowBe4 user accounts that have not signed in within the last 90 days.

A record is marked failed when: Last Login is more than 90 days in the past. A record is sent for review when: Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Phishing Security Tests

Test name

Test description

Test logic

Phishing Simulation Campaign Executed and Delivered

Verify each simulated phishing security test is a named, dated campaign that actually delivered messages to targets, evidencing a practical social-engineering exercise (NIST 800-53 Rev5 AT-2(1)). Fields: name, status, started_at, delivered_count.

Every record must satisfy: Campaign Name has a value and Status has a value and Start Date has a value and Delivered Count is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Phishing Simulation Outcome Metrics Tracked

Confirm every phishing security test records the full set of outcome metrics (delivered, opened, clicked, reported) so program effectiveness can be measured and reported (NIST 800-53 Rev5 PM-14, AT-2(1)). Requires delivered messages plus non-empty opened/clicked/reported counters.

Every record must satisfy: Delivered Count is greater than 0 and Opened Count has a value and Clicked Count has a value and Reported Count has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Phishing Simulation Run Window Adequate

Ensure each phishing security test ran for a meaningful window (duration of at least one day) and reached recipients, so results reflect a genuine exercise rather than a mis-configured or immediately-closed campaign (NIST 800-53 Rev5 AT-2(1)). Fields: duration, delivered_count.

Every record must satisfy: Duration Days is 1 or more and Delivered Count is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Training Activity

Test name

Test description

Test logic

All Assigned Training Completed

Verify every training enrollment has been completed - a recorded completion date and a computed completion duration - so no learner in the campaign is left with outstanding required training (NIST 800-53 Rev5 AT-2). Fields: completion_date, days_until_complete.

Every record must satisfy: Completion Date has a value and Days Until Complete has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Initial Security Awareness Training Completion

Verify that all users complete initial security awareness training within 30 days of enrollment (KnowBe4 status Passed or Completed and days_until_complete of 30 or fewer).

Every record must satisfy: Name has a value and Email has a value and Module Name has a value and Enrollment Date has a value and Days Until Complete is 30 or less. A record is marked failed when: Status is none of "Passed" or "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Role-Based Training Assignment

Confirm that users with specific roles (e.g., administrators, developers) are assigned appropriate role-based training modules

Every record must satisfy: Name has a value and Module Name has a value and Status has a value and Enrollment Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Security Awareness Training Completed On Time

Verify every training enrollment was completed within 30 days of enrollment, evidencing timely security awareness training (NIST 800-53 Rev5 AT-2). Requires a non-empty completion_date and days_until_complete <= 30.

Every record must satisfy: Completion Date has a value and Days Until Complete is 30 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Training Enrollment Record Completeness

Confirm each training enrollment record identifies the learner (name, email), the assigned module, and the enrollment date, so training records are complete and auditable (NIST 800-53 Rev5 AT-4). Fields: name, email, module_name, enrollment_date.

Every record must satisfy: Name has a value and Email has a value and Module Name has a value and Enrollment Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Training Campaigns

Test name

Test description

Test logic

KnowBe4 - Training Campaign Completion Rate

Checks that every security awareness training campaign has reached the required completion percentage across the groups it was assigned to.

A record is marked failed when: Campaign Name is empty. A record is marked failed when: Status is empty. A record is sent for review when: Completion Percentage is empty. A record is sent for review when: Completion Percentage equals -1. A record is sent for review when: Status equals "Cancelled". A record is marked failed when: Status equals "Completed" and Completion Percentage does not equal -1 and Completion Percentage is less than 95. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

KnowBe4 - Training Campaigns Auto-Enroll New Group Members

Checks that training campaigns automatically enroll people added to their target groups, so new joiners are covered without manual assignment.

Every record must satisfy: Campaign Name has a value and Groups has a value and Start Date has a value and Auto Enroll is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Kustomer

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Lacework

List of Users

Test name

Test description

Test logic

Lacework No Guest Or External Group Accounts

Fails if any Lacework user is assigned to a group whose name indicates guest or external access, enforcing least privilege by keeping unmanaged external identities out of the security console. Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and AC-2 (Account Management). Field checked: role (join of user group names; case-explicit regex, no inline flags).

Every record must satisfy: Role does not match the pattern "[Gg][Uu][Ee][Ss][Tt]" and Role does not match the pattern "[Ee][Xx][Tt][Ee][Rr][Nn][Aa][Ll]". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Lacework No Personal Email Domain Accounts

Fails if any Lacework user account is registered under a personal/consumer email domain (gmail, yahoo, hotmail, outlook, aol, icloud, protonmail) instead of a managed corporate identity. Enforces provisioning from centrally governed accounts. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management) and IA-2 (Identification and Authentication). Field checked: email (case-explicit regex, no inline flags).

Every record must satisfy: Email does not match the pattern "@(?:[Gg][Mm][Aa][Ii][Ll]|[Yy][Aa][Hh][Oo][Oo]|[Hh][Oo][Tt][Mm][Aa][Ii][Ll]|[Oo][Uu][Tt][Ll][Oo][Oo][Kk]|[Aa][Oo][Ll]|[Ii][Cc][Ll][Oo][Uu][Dd]|[Pp][Rr][Oo][Tt][Oo][Nn][Mm][Aa][Ii][Ll])\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Lacework No Shared Or Generic Named Accounts

Fails if any Lacework user's name is a generic/shared identifier (admin, test, shared, service, guest, root) rather than an individual, enforcing individual accountability and non-repudiation for actions in the security console. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Field checked: name (anchored, case-explicit regex, no inline flags).

Every record must satisfy: Name does not match the pattern "^(?:[Aa][Dd][Mm][Ii][Nn]|[Tt][Ee][Ss][Tt]|[Ss][Hh][Aa][Rr][Ee][Dd]|[Ss][Ee][Rr][Vv][Ii][Cc][Ee]|[Gg][Uu][Ee][Ss][Tt]|[Rr][Oo][Oo][Tt])$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Lacework User Account Inventory Completeness

Verifies every Lacework team user record is fully attributed - name, email, and role (group membership) are all populated - so account management has complete, accountable identity records. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Fields checked: name, email, role.

Every record must satisfy: Name has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Lacework User Email Address Format Validity

Fails if any Lacework user's email is malformed (missing local part, @, or a dotted domain), ensuring account records carry a resolvable identifier for notifications, de-provisioning, and access reviews. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Field checked: email (regex valid in both JS RegExp and.NET, case-explicit, no inline flags).

Every record must satisfy: Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Lever

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Linear

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Microsoft Defender for Endpoint

List of Vulnerabilities

Test name

Test description

Test logic

Microsoft Defender High and Critical Vulnerabilities Are Remediated Within 30 Days

Flags high and critical severity vulnerabilities first detected more than 30 days ago and still open, indicating remediation past its due date.

A record is sent for review when: Severity is one of "Critical" or "High" and First Detected is empty. A record is marked failed when: Severity is one of "Critical" or "High" and First Detected is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Microsoft Defender Vulnerabilities With Publicly Available Exploit Code Are Remediated

Flags open vulnerabilities that have publicly available exploit code, so the most readily weaponized findings are prioritized for remediation.

A record is marked failed when: Exploitable is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Microsoft Dynamics 365 Sales

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Microsoft Entra ID

Assigned Licenses

Test name

Test description

Test logic

Group License Assignments Resolve To A Product And Grant At Least One Service Plan

Checks that each license assigned to the group names a known product and still grants at least one enabled service plan to its members.

Every record must satisfy: Product Name has a value and Licenses does not equal "No Licenses". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Conditional Access Policies

Test name

Test description

Test logic

Conditional Access Policies Are Enabled and Enforced

Verifies each Azure AD Conditional Access policy is in the enabled (enforced) state rather than disabled or report-only, supporting NIST 800-53 Rev5 AC-17 and IA-2 by ensuring access controls are actually enforced. Checks textField.state.

Every record must satisfy: State equals "enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Conditional Access Policies Require Multifactor Authentication

Verifies enabled Conditional Access policies include the MFA grant control, supporting NIST 800-53 Rev5 IA-2(1) multifactor authentication for privileged and network access. Checks textField.builtInControls contains 'mfa' on enabled policies.

Every record must satisfy: State equals "enabled" and Built-in Controls contains "mfa". The test passes if any record passes. If the proof contains no records, the test is marked failed.

Enabled Conditional Access Policies With User Exclusions Are Reviewed

Routes enabled Conditional Access policies that exclude specific users to review, since exclusions are the standard path around an enforced control.

A record is sent for review when: State equals "enabled" and Users Excluded does not equal "No users". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Verify Conditional Access Policies Enforce A Grant Control

Fails any conditional access policy that enforces no built-in grant control, catching misconfigured or empty policies. NIST 800-53 Rev5 AC-17. Fields: displayName, builtInControls.

Every record must satisfy: Name has a value and Built-in Controls does not equal "No Built-in Controls". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Conditional Access Policies Require Multifactor Authentication

Confirms each conditional access policy includes MFA among its built-in grant controls, verifying multifactor enforcement. NIST 800-53 Rev5 IA-2(1). Fields: builtInControls.

Every record must satisfy: Built-in Controls contains "mfa". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Group Membership List

Test name

Test description

Test logic

Group Membership Contains Only Named Individual User Accounts

Checks that every member of the group is a named individual user account, with no nested groups, devices, or other non-human principals.

Every record must satisfy: Name has a value and Type equals "User". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Applications

Test name

Test description

Test logic

Every Application Registration Is Identifiable And Has An Assigned Owner

Checks that every application registration in the directory is named, uniquely identifiable, and has at least one assigned owner.

Every record must satisfy: Application Name has a value and Application ID has a value and Owners has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Directory Role Permissions

Test name

Test description

Test logic

Verify Directory Roles Are Classified As Built-in Or Custom

Confirms every directory role carries a recognized type classification (Built-in or Custom) so custom privileged roles are distinguishable during least-privilege review. NIST 800-53 Rev5 AC-6. Fields: roleType.

A record is marked failed when: Type is none of "Built-in" or "Custom". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Verify Every Directory Role Has A Documented Permission

Fails any directory role definition that expands to an empty allowed-resource-action, ensuring each role's privileges are documented for least-privilege review. NIST 800-53 Rev5 AC-6. Fields: roleName, permission.

Every record must satisfy: Name has a value and Permission has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Domains

Test name

Test description

Test logic

Azure AD Domains Are Administratively Managed

Verifies each directory domain is administratively managed by the organization, supporting NIST 800-53 Rev5 CM-6 baseline configuration ownership over identity domains. Checks booleanField.isAdminManaged is true.

Every record must satisfy: Admin Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Azure AD Domains Are Verified

Verifies every directory domain has completed domain-ownership verification, supporting NIST 800-53 Rev5 IA-5 and CM-6 by preventing use of unverified domains vulnerable to takeover. Checks booleanField.isVerified is true.

Every record must satisfy: Verified is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Groups

Test name

Test description

Test logic

Generate a list of all security and Microsoft 365 groups in Azure AD.

Generate a list of all security and Microsoft 365 groups in Azure AD to maintain an accurate inventory for access control.

Every record must satisfy: Name has a value and Group Type has a value and Object ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Verify Mail-Enabled Groups Have A Populated Email Address

Confirms every Office 365 and Distribution group (mail-enabled group types) carries a populated email address, supporting an accurate, addressable group inventory. Security groups are exempt since they are not mail-enabled. NIST 800-53 Rev5 AC-2. Fields: groupType, email.

A record is marked failed when: Group Type does not equal "Security" and E-mail Address is empty. A record is marked failed when: Group Type is empty and E-mail Address is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Role Assignments

Test name

Test description

Test logic

Verify Every App Role Assignment Identifies Its Principal

Confirms each service-principal app role assignment records the assigned principal's name so privileged access is attributable. NIST 800-53 Rev5 AC-2. Fields: principalName.

Every record must satisfy: Service Principal Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Service Principals

Test name

Test description

Test logic

No Legacy Service Principals in Azure AD

Flags service principals of the deprecated Legacy type, which lack modern app-registration controls, supporting NIST 800-53 Rev5 CM-7 least functionality and AC-6. Checks textField.servicePrincipalType. Empty proof yields Needs Review since a tenant may legitimately have no service principals.

A record is marked failed when: Type equals "Legacy". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Subscriptions

Test name

Test description

Test logic

Azure AD Directory Subscriptions Have Provisioned Licenses

Verifies each directory subscription reports at least one provisioned license so licensed security capabilities are actually available, supporting NIST 800-53 Rev5 CM-8 component inventory accuracy. Checks numberField.totalLicenses is greater than 0. Empty proof yields Needs Review.

Every record must satisfy: Total Licenses is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Azure AD Users Have Strong Password Enforcement Enabled

Verifies no user account has strong-password enforcement disabled (passwordPolicies must not include DisableStrongPassword), supporting NIST 800-53 Rev5 IA-5(1) password-based authentication strength. Checks textField.passwordPolicies.

Every record must satisfy: Password Policy does not contain "DisableStrongPassword". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Flag User Accounts With Passwords Older Than 365 Days

Fails any user whose password was last changed more than 365 days ago, enforcing periodic authenticator rotation. NIST 800-53 Rev5 IA-5. Fields: lastPasswordChangeDateTime.

A record is sent for review when: Password Last Changed is empty. A record is marked failed when: Password Last Changed is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Microsoft Entra ID Accounts With No Sign-In In 90 Days

Flags Entra ID directory accounts that have not signed in within the last 90 days, and routes accounts that have never signed in to review.

A record is sent for review when: Status equals "Active" and Last Login is more than 90 days in the past. A record is sent for review when: Status equals "Active" and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

No Unreviewed External Guest Accounts in Azure AD

Flags any directory account whose userType is Guest so external guest access is reviewed and justified, supporting NIST 800-53 Rev5 AC-2 account management and AC-6 least privilege. Checks textField.userType.

A record is marked failed when: User Type equals "Guest". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Verify Every User Has A Display Name And Principal Name

Confirms every directory user carries both a display name and a user principal name so identities are uniquely attributable. NIST 800-53 Rev5 IA-4. Fields: displayName, principalName.

Every record must satisfy: Name has a value and User Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Password Protection

Test name

Test description

Test logic

Azure AD Account Lockout Threshold Is Configured

Verifies the tenant password-protection lockout threshold is enabled (greater than 0) and set to no more than 10 failed attempts, supporting NIST 800-53 Rev5 AC-7 unsuccessful logon attempt limits. Checks numberField.lockoutThreshold.

Every record must satisfy: Lockout Threshold is greater than 0 and Lockout Threshold is 10 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Microsoft Intune

Devices without a Compliance Policy

Test name

Test description

Test logic

Microsoft Intune - Devices Without An Assigned Compliance Policy

Fails when any managed device is not covered by a compliance policy, since those devices are outside automated configuration enforcement.

A record is marked failed when: Device has a value. A record is sent for review when: Device is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Configuration Policies

Test name

Test description

Test logic

Microsoft Intune - Configuration Policies Are Assigned To A Group

Fails any device configuration policy that is not assigned to a group, since an unassigned policy enforces no settings on any device.

A record is marked failed when: Assigned is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Devices

Test name

Test description

Test logic

Inventory Granularity Verification

Examine documented system inventory to determine if it includes all required components at the necessary granularity for tracking.

Every record must satisfy: Device name has a value and Managed by has a value and Ownership has a value and Compliance has a value and OS has a value and OS version has a value and Last check-in has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Managed Devices

Test name

Test description

Test logic

Managed Devices Have Checked In Within 30 Days

Flags managed devices that have not checked in with the device management service in the last 30 days.

A record is marked failed when: Last check-in is empty. A record is marked failed when: Last check-in is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Managed Devices Report A Compliant State

Checks that every managed device in the device inventory reports a compliant state.

Every record must satisfy: Compliance equals "Compliant". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Microsoft Intune Managed Devices Record An Operating System Baseline

Checks that each Intune managed device records its operating system and version.

Every record must satisfy: OS has a value and OS version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Microsoft Intune - External Guest Accounts Require Review

Surfaces external guest accounts in the user list so each one is justified or removed, while internal member accounts pass.

A record is sent for review when: Username contains "#EXT#". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Microsoft Intune - User Accounts Are Attributable And Have An Account Manager

Checks that every directory account has a name, username, unique ID, and an assigned manager so each account has an accountable owner.

Every record must satisfy: Name has a value and Username has a value and User ID has a value and Manager has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Moneybird

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

MongoDB Atlas

Backup Compliance Policies

Test name

Test description

Test logic

MongoDB Atlas Backup Compliance Policy Active With Authorized Approver

Verify the Atlas backup compliance policy is in the ACTIVE state and designates an authorized approver email (authorizedEmail is present and contains @). Ensures the backup protection controls are actually enforced and an accountable point of contact governs changes. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and AC-6 (Least Privilege / accountability). Fields checked: state, authorizedEmail. Missing policy is non-compliant.

Every record must satisfy: State equals "ACTIVE" and Authorized Email has a value and Authorized Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

MongoDB Atlas Backup Encryption At Rest Enabled

Verify the Atlas backup compliance policy enforces encryption at rest for backup snapshots (encryptionAtRestEnabled is true). Maps to NIST SP 800-53 Rev 5 SC-28 (Protection of Information at Rest). No backup compliance policy configured is treated as non-compliant.

Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

MongoDB Atlas Backup Immutable Copy Protection Enabled

Verify the Atlas backup compliance policy enables copy protection (copyProtectionEnabled is true), preventing deletion/modification of backup snapshots by project owners so backups remain recoverable after account compromise or ransomware. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and SI-7. Missing policy is non-compliant.

Every record must satisfy: Copy Protection is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

MongoDB Atlas Backup Restore Window Meets Minimum

Verify the Atlas backup compliance policy enforces a point-in-time restore window of at least 7 days (restoreWindowDays >= 7), ensuring sufficient recovery coverage for data corruption or ransomware discovered after the fact. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and CP-10 (Recovery and Reconstitution). Field checked: restoreWindowDays. Missing policy is non-compliant.

Every record must satisfy: Restore Window Days is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

MongoDB Atlas Backup Snapshot Retention Configured

Verify every scheduled backup policy item retains snapshots for a positive period (retentionValue >= 1 and retentionUnit is present, e.g. days/weeks/months). Guards against schedule items that back up data but retain it for zero duration. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup). Fields checked: retentionValue, retentionUnit. Each row is one scheduled policy item; missing policy is non-compliant.

Every record must satisfy: Retention Value is 1 or more and Retention Unit has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

MongoDB Atlas Users Have Valid Email And Assigned Role

Verify every Atlas organization/project user account maps to a valid corporate identity (username present, emailAddress present and contains @) and carries an explicit RBAC role assignment (roleName present). Supports account-management completeness and role-based least privilege. Maps to NIST SP 800-53 Rev 5 AC-2 (Account Management) and AC-6 (Least Privilege). Fields checked: username, emailAddress, roleName. Each row is one user-role pairing; an empty user list warrants manual review.

Every record must satisfy: Username has a value and Email has a value and Email contains "@" and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

NetSuite

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Employees with Change in Employment Status

Test name

Test description

Test logic

Deactivated Employees Retain An Employee Number

Flags employees deactivated during the period whose employee number is missing, which breaks traceability when verifying offboarding.

A record is marked failed when: Status equals "INACTIVE" and Employee Number is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Employee Status Change Records Include A Modification Date

Flags employee status changes with no recorded modification date, which makes it impossible to confirm the change was processed on time.

A record is marked failed when: Last Modified is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Employees

Test name

Test description

Test logic

Accounting Employee Records Have A Name And Employee Number

Confirms every employee record in the accounting system carries a name and an employee number so it can be matched during access reviews.

Every record must satisfy: Name has a value and Employee Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Active Accounting Employees Have An Email Address On File

Flags active employees that have no email address recorded, which prevents matching them to their system accounts.

A record is marked failed when: Status equals "ACTIVE" and Email is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vendor and Customer Master Lists

Test name

Test description

Test logic

Vendor And Customer Master Records Are Named And Classified

Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified.

Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Nutshell

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Occupop

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta

Global Session Policies

Test name

Test description

Test logic

Okta Global Session Idle Timeout Bounded

NIST 800-53 Rev5 AC-11/AC-12: global session sign-on rules enforce an idle timeout of at most 2 hours. Field: idleTimeoutHours.

Every record must satisfy: Idle timeout (hours) is 2 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta Global Session Rules Enforce A Maximum Session Lifetime

Flags active global session sign-on rules that place no upper bound on how long a session can remain active.

A record is marked failed when: Status equals "ACTIVE" and Max session lifetime (hours) equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Group Membership List

Test name

Test description

Test logic

Detect Inactive Users in Group

identify users within the group who are not in an active status, which may indicate deprovisioned or suspended accounts.

Every record must satisfy: Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Ensure Timely Removal of Deactivated Users from Groups

Verify that users who have been deactivated are promptly removed from group memberships to prevent unauthorized access.

Every record must satisfy: Status does not equal "Deprovisioned". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Group Membership Accuracy

Checks that every Okta group membership record identifies the person and their username. Does not evaluate whether the membership itself is appropriate, which the proof cannot express.

Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Retrieve All Group Members

Checks that every Okta group membership record returned for the selected groups identifies the person and their username.

Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Validate Group Membership Based on User Attributes

Checks that every Okta group membership record identifies the person and their username. Does not compare membership against user attributes such as department or role; the proof carries no attribute to compare against.

Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Admins

Test name

Test description

Test logic

Okta Administrator Identity Completeness

NIST 800-53 Rev5 AC-6: every privileged (admin) assignment identifies the person, email and role. Fields: name, email, role.

Every record must satisfy: Name has a value and Email has a value and Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of API Tokens

Test name

Test description

Test logic

API Token Validity and Assignment

Ensure that API tokens are valid, assigned to active users, and have appropriate scopes.

Every record must satisfy: ID has a value and Name has a value and Expiration Date has a value and Creation Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta API Token Bounded Lifetime

NIST 800-53 Rev5 AC-2/SC-12: each API token expires within one year. Field: expiresAt.

Every record must satisfy: Expiration Date is less than 365 days in the future. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Deactivated Users

Test name

Test description

Test logic

Deactivated User Access

Confirm that deactivated users do not have active sessions or access to resources.

Every record must satisfy: Person has a value and Username has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Devices

Test name

Test description

Test logic

Device Compliance Status

Checks that each managed device reports an identifier and a device name.

Every record must satisfy: ID has a value and Device Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta Devices In Active State

NIST 800-53 Rev5 CM-8: enrolled devices are in the ACTIVE lifecycle state (raw Okta device status). Field: status (raw ACTIVE/SUSPENDED/DEACTIVATED/CREATED).

Every record must satisfy: Status equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Groups

Test name

Test description

Test logic

Group Definition Completeness

Ensure that all groups have defined purposes and associated access permissions

Every record must satisfy: Group ID has a value and Name has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of User Login Events

Test name

Test description

Test logic

Okta Login Event Audit Completeness

NIST 800-53 Rev5 AU-3: each login/system-log record has actor, timestamp and outcome. Fields: userId, loginDate, status (outcome.result).

Every record must satisfy: User ID has a value and Login Date has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Automate provisioning and deprovisioning processes.

Checks that every account carries a recognized Okta lifecycle status, so provisioning and deprovisioning transitions are auditable.

Every record must satisfy: Status is one of "Active", "Provisioned", "Deprovisioned", "Suspended", "Staged", "Recovery", "Locked out" or "Password expired". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Find users with no status assigned.

Flags user records that carry a username and email address but no assigned status.

A record is marked failed when: Username has a value and Primary Email has a value and Status is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Okta Active Users With No Sign-In In 90 Days

Flags active Okta directory accounts that have not signed in within the last 90 days, and routes accounts that have never signed in to review.

A record is marked failed when: Status equals "Active" and Last Login is more than 90 days in the past. A record is sent for review when: Status equals "Active" and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Okta User Identity Completeness

NIST 800-53 Rev5 IA-4: every user record carries a unique, complete identity (person, username, primaryEmail, userId). Fields: person, username, primaryEmail, userId.

Every record must satisfy: Person has a value and Username has a value and Primary Email has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Retrieve All Users

Ensure that all users in the Okta organization are retrievable, including those with various statuses.

Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Unique User Identification

Verify that each user has a unique identifier, ensuring no duplicate usernames exist.

Every record must satisfy: Username has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users for a Given Application

Test name

Test description

Test logic

Application Access Review

Review and validate user access to applications, ensuring alignment with role-based access controls.

Every record must satisfy: ID has a value and Email has a value and Status has a value and Scope has a value. The test passes if at least 50% of records pass. If the proof contains no records, the test is marked failed.

Application User Assignments

Verify that users assigned to applications have appropriate access rights.

Every record must satisfy: ID has a value and Status has a value and Scope has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users with MFA Settings

Test name

Test description

Test logic

MFA Enrollment Verification

Verify that all users are enrolled in Multi-Factor Authentication (MFA)

Every record must satisfy: MFA equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta No Users Without MFA

NIST 800-53 Rev5 IA-2: no user is left with MFA explicitly None. Field: mfa (vlookup Enabled/None).

Every record must satisfy: MFA does not equal "None". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Password Policies

Test name

Test description

Test logic

Ensures that users cannot reuse previous passwords.

Checks that the password policy prevents reuse of the previous 24 passwords.

Every record must satisfy: Enforce password history is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Exclude First Name From Password

Checks that the password policy forbids using the user's first name in a password.

Every record must satisfy: Does not contain first name is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Exclude Username From Password

Checks that the password policy forbids using the username in a password.

Every record must satisfy: Does not contain part of username is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Minimum Password Length

Checks that the password policy requires a minimum length of at least 12 characters.

Every record must satisfy: Minimum length is 12 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta Password Complexity Character Classes

NIST 800-53 Rev5 IA-5(1): password policy requires lower, upper, number and symbol character classes. Fields: lowerCase, upperCase, number, symbol.

Every record must satisfy: Lower case letter is true and Upper case letter is true and Number (0-9) is true and Symbol (e.g., !@#$%^&*) is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta Password Lockout Threshold Configured

NIST 800-53 Rev5 AC-7: an account lockout threshold is set between 1 and 10 failed attempts. Field: maxAttempts.

Every record must satisfy: Attempts before lockout is 1 or more and Attempts before lockout is 10 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Okta Password Policy Excludes The User's Last Name

Checks that the Okta password policy forbids using the user's last name in a password.

Every record must satisfy: Does not contain last name is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Validates that passwords are checked against a list of commonly used or breached passwords.

Checks that the password policy screens passwords against a list of common or breached passwords.

Every record must satisfy: Restrict use of common passwords is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Onlyfy

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Orca Security

List of Alerts

Test name

Test description

Test logic

Data-At-Risk Findings Remediated

Protection of stored/exposed data: any Orca alert categorized as Data at risk (exposed sensitive data) must be remediated (status closed, snoozed, or dismissed) rather than left open or in progress. Checks alertType + status. Maps to GDPR Art. 32 (security of processing), ISO/IEC 27001:2022 Annex A 8.12 (data leakage prevention), and NIST 800-53 Rev5 SC-28 (protection of information at rest).

A record is marked failed when: Alert Type equals "Data at risk" and Status is none of "closed", "snoozed" or "dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Malicious Activity Findings Remediated

Malware / malicious-code protection: any Orca alert categorized as Malicious activity must be remediated (status closed, snoozed, or dismissed) and not left open or in progress. Checks alertType + status. Maps to NIST 800-53 Rev5 SI-3 (malicious code protection), ISO/IEC 27001:2022 Annex A 8.7 (protection against malware), and SOC 2 CC6.8.

A record is marked failed when: Alert Type equals "Malicious activity" and Status is none of "closed", "snoozed" or "dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - Alerts Are Attributable to a Named Asset

Ensures every security finding is traceable to the affected resource for accountability and triage (NIST 800-53 Rev5 CM-8/AU-3/SI-4). Each Orca alert must identify the affected asset (asset field) and carry a finding description (alertName field); a row missing either fails.

Every record must satisfy: Asset has a value and Alert Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - No Open Critical Alerts

Verifies remediation of the highest-severity cloud security findings (NIST 800-53 Rev5 RA-5(5)/SI-2/CA-5). A critical-severity Orca alert (severity field) must not remain in the Open status (status field); such a row fails.

A record is marked failed when: Severity equals "critical" and Status equals "open". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - Vulnerability Alerts Are Remediated

Confirms flaw remediation of vulnerability findings (NIST 800-53 Rev5 SI-2/RA-5). An Orca alert whose category (alertType field) is Vulnerabilities must not remain in the Open status (status field); such a row fails.

A record is marked failed when: Alert Type equals "Vulnerabilities" and Status equals "open". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of All Orca Users

Test name

Test description

Test logic

Orca Security - User Accounts Have an Assigned Role

Enforces role-based access management so no Orca console account exists without a defined role (NIST 800-53 Rev5 AC-2/AC-6). Each user must have at least one role (role field); an account with no role fails. Empty proof yields needsReview since at least one account is expected.

Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Assets

Test name

Test description

Test logic

No High Or Critical Risk Cloud Assets

Cloud security posture: no asset in the Orca inventory may carry a high or critical risk level; such assets must be risk-reduced. Checks riskLevel. Maps to NIST 800-53 Rev5 RA-5 (vulnerability monitoring & remediation) and ISO/IEC 27001:2022 Annex A 8.8 (management of technical vulnerabilities).

Every record must satisfy: Risk Level is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - Asset Inventory Records Are Complete

Validates completeness of the cloud asset inventory so every discovered resource is accountable (NIST 800-53 Rev5 CM-8). Each asset must record a name (assetName field), a type (assetType field), and its owning cloud account/subscription (subscriptionAccount field); a row missing any of these fails. Empty proof yields needsReview since no inventory was returned.

Every record must satisfy: Asset has a value and Asset Type has a value and Cloud Account has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - Assets Scanned Within 30 Days

Confirms vulnerability-scanning coverage and freshness across the cloud estate (NIST 800-53 Rev5 RA-5/SI-2). Each asset's last-scanned timestamp (lastScanned field) must be no more than 30 days old; assets not scanned within 30 days fail. Empty proof yields needsReview since no inventory was returned. Note: an asset with a blank lastScanned is treated as not-a-failure to avoid false negatives at threshold 1.0.

A record is sent for review when: Last Scanned is empty. A record is marked failed when: Last Scanned is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Orca Security - No Critical Risk-Level Assets

Surfaces cloud assets carrying unmitigated critical risk that require prioritized remediation (NIST 800-53 Rev5 RA-5/CM-6/CA-5). Any asset whose Orca risk level (riskLevel field) is Critical fails.

Every record must satisfy: Risk Level does not equal "critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Paylocity

List of Employee Details

Test name

Test description

Test logic

Paylocity Employees in Non-Active Employment Statuses Are Reviewed for Continued Access

Surfaces employees whose employment status is neither active nor terminated (leave, retired, transferred) so their system access can be re-verified.

A record is sent for review when: Employment Status is one of "Leave of Absence", "Retired", "Deceased" or "Transferred". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Paylocity Terminated Employees Have a Recorded Termination Date

Flags employees marked as terminated whose records carry no termination date, so offboarding and access-removal timelines can be evidenced.

A record is marked failed when: Employment Status equals "Terminated" and Termination Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Pinpoint

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Pipedrive

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Pipeliner

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Prisma Cloud

List of Assets

Test name

Test description

Test logic

Prisma Cloud - Cloud Asset Inventory Records Carry Required Identifying Fields

Checks that every cloud asset in your inventory has an identifier, asset type, and cloud provider recorded.

Every record must satisfy: ID is not blank and Asset Type has a value and Cloud Account Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Prisma Cloud Asset Inventory Records Include Type and Region

NIST SP 800-53 CM-8: the system component inventory must capture enough metadata to identify each component and its deployment location. Verifies every Prisma Cloud asset records an asset type and a cloud region.

Every record must satisfy: Asset Type has a value and Cloud Account Region has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Cloud Accounts

Test name

Test description

Test logic

Prisma Cloud - Cloud Account Connections Modified Within The Last Year

Flags connected cloud accounts whose configuration has not been modified in over a year, so long-untouched connections get reviewed.

A record is sent for review when: Last Modified is empty. A record is sent for review when: Last Modified is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud - Connected Cloud Accounts Have A Designated Owner

Flags connected cloud accounts that have no designated owner recorded.

A record is marked failed when: Account Owner is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud Accounts Have an Assigned Owner

NIST SP 800-53 AC-2 and CM-8: managed accounts and inventoried components must have an accountable owner. Verifies every Prisma Cloud cloud account records an account owner.

Every record must satisfy: Account Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Policies

Test name

Test description

Test logic

Prisma Cloud - Critical And High Severity Policies Are Enabled

Flags critical and high severity cloud security policies that are switched off, so gaps in automated detection coverage are visible.

A record is marked failed when: Severity equals "critical" and Enabled is false. A record is marked failed when: Severity equals "high" and Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud - Custom Policies Are Enabled

Flags organization-authored custom policies that are switched off, so tenant-specific detections are not left silently inactive.

A record is marked failed when: Mode equals "Custom" and Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud Security Policies Are Enabled

NIST SP 800-53 CM-6: configuration settings must be actively enforced. Verifies that every Prisma Cloud security policy returned in the proof is enabled. Collect the proof filtered to the policy types you require (for example Config policies) so that disabled policies surface as failures.

Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Security Vulnerabilities

Test name

Test description

Test logic

Prisma Cloud - No Exploitable Critical Or High Vulnerabilities

Flags reported vulnerabilities that have a known working exploit, so the highest-risk findings are surfaced for prompt remediation.

A record is marked failed when: Exploitable is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud Critical and High Vulnerabilities Are Not Exploitable

NIST SP 800-53 RA-5 and SI-2: vulnerabilities must be monitored and remediated, prioritizing those with known exploits. The Prisma Cloud vulnerabilities proof is restricted to Critical and High severities; this test fails if any returned vulnerability is flagged exploitable.

Every record must satisfy: Exploitable is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Prisma Cloud Vulnerability Records Include a Published Date

NIST SP 800-53 RA-5 and SI-2: remediation must be prioritized and aged against vulnerability disclosure. Verifies every Prisma Cloud vulnerability record carries a published date so remediation SLAs can be measured.

Every record must satisfy: Published Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Users

Test name

Test description

Test logic

Prisma Cloud - No Users Inactive For More Than 90 Days

Flags accounts with no sign-in in the last 90 days, plus accounts with no recorded sign-in at all, so unused access can be reviewed or removed.

A record is marked failed when: Last Login is more than 90 days in the past. A record is sent for review when: Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Prisma Cloud User Accounts Have an Identity and Role

NIST SP 800-53 AC-2 and AC-6(1): access reviews must identify the account and its assigned role to support recertification of access to security functions. Verifies every Prisma Cloud user account records a name and at least one role. Prisma Cloud exposes no access-review proof type, so this reads the user list.

Every record must satisfy: Name has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Prisma Cloud Users Have a Role Assignment

NIST SP 800-53 AC-2 and AC-6: accounts must have explicit role assignments to support least privilege and periodic access review. Verifies every Prisma Cloud user record has at least one assigned role.

Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Qualys

List of Assets

Test name

Test description

Test logic

Qualys - Asset Configuration Compliance Scan Recency (90-Day)

Verifies each Qualys-managed asset has had a Policy Compliance (configuration) scan within the last 90 days so configuration baselines are assessed on a recurring cadence. Checks the LAST_COMPLIANCE_SCAN_DATETIME field. Supports NIST SP 800-53 Rev. 5 CM-6 and RA-5, CMMC 2.0 / NIST 800-171 3.4.1, and ISO/IEC 27001:2022 Annex A A.8.9.

A record is marked failed when: Last Compliance Scan is empty. A record is marked failed when: Last Compliance Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys - Asset Vulnerability Scan Coverage And Recency (30-Day)

Flags any Qualys-managed asset that has never had a vulnerability scan or whose last vulnerability scan is older than 30 days, so scan coverage gaps and stale assets are remediated. Checks the LAST_VULN_SCAN_DATETIME field. Supports NIST SP 800-53 Rev. 5 RA-5 and SI-2, CMMC 2.0 / NIST 800-171 3.11.2, and ISO/IEC 27001:2022 Annex A A.8.8.

A record is marked failed when: Last Vulnerability Scan is empty. A record is marked failed when: Last Vulnerability Scan is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys Asset Inventory Records Are Fully Identified

NIST SP 800-53 Rev 5 CM-8 (System Component Inventory) and RA-5 asset coverage: every asset record must carry the identifying attributes needed for accountable inventory and scan attribution - hostname, IP address, and operating system. Fails any asset row missing HOSTNAME, IP, or OS. Fields checked: HOSTNAME (text), IP (text), OS (text).

Every record must satisfy: Asset has a value and IP Address has a value and Operating System has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Qualys Assets Have An Authenticated Vulnerability Scan Within 90 Days

NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): confirms each asset has a recorded authenticated vulnerability scan datetime no older than the quarterly (90-day) cadence. Fails any asset whose LAST_VULN_SCAN_DATETIME is empty or more than 90 days old. Fields checked: LAST_VULN_SCAN_DATETIME (date).

Every record must satisfy: Last Vulnerability Scan has a value. A record is marked failed when: Last Vulnerability Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys Assets Scanned For Vulnerabilities Within 30 Days

NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): verifies every managed asset in the Qualys inventory was covered by a VM scan recently, so scan coverage stays current and no host drifts out of the scanning cadence. Fails any asset whose LAST_VM_SCANNED_DATE is empty (never scanned) or is more than 30 days old. Fields checked: LAST_VM_SCANNED_DATE (date).

Every record must satisfy: Last VM Scan has a value. A record is marked failed when: Last VM Scan is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of PC Scans

Test name

Test description

Test logic

Qualys Policy Compliance Scans Completed Successfully

NIST SP 800-53 Rev 5 CM-6 (Configuration Settings) and RA-5: every Policy Compliance (PC) scan launched in the reporting period must have finished successfully so configuration-baseline compliance results are complete and trustworthy. Fails any scan whose STATE is not Finished. Text comparison is case-insensitive. Fields checked: STATE (text).

Every record must satisfy: Status equals "Finished". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Qualys - No Console Accounts Inactive More Than 90 Days

Identifies Qualys console user accounts that have not logged in within the last 90 days so stale or unused privileged accounts are reviewed, disabled, or removed. Checks the LAST_LOGIN_DATE field. Supports NIST SP 800-53 Rev. 5 AC-2 and AC-2(3), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18.

A record is sent for review when: Last Login Date is empty. A record is marked failed when: Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys Console Accounts Have No Stale Logins

NIST SP 800-53 Rev 5 AC-2 (Account Management, inactive account review): every Qualys console user account must have logged in within the last 90 days. Accounts that have never logged in (empty LAST_LOGIN_DATE) or have been inactive for more than 90 days are flagged for disablement/review. Fields checked: LAST_LOGIN_DATE (date).

Every record must satisfy: Last Login Date has a value. A record is marked failed when: Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of VM Scans

Test name

Test description

Test logic

Qualys - Vulnerability Scans Completed Without Error Or Cancellation

Flags any Qualys vulnerability (VM) scan in the reporting period that ended in an Error or Canceled state, so failed scan jobs are investigated and re-run rather than leaving blind spots in vulnerability coverage. Checks the scan STATE field. Supports NIST SP 800-53 Rev. 5 RA-5 and SI-2, CMMC 2.0 / NIST 800-171 3.11.2, and ISO/IEC 27001:2022 Annex A A.8.8.

A record is marked failed when: Status equals "Error". A record is marked failed when: Status equals "Canceled". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys VM Scans Completed Successfully

NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): every vulnerability (VM) scan launched in the reporting period must have finished successfully rather than erroring, canceling, or stalling, so scan results are complete and trustworthy. Fails any scan whose STATE is not Finished. Text comparison is case-insensitive. Fields checked: STATE (text).

Every record must satisfy: Status equals "Finished". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys VM Scans Launched Within The Monthly Cadence

NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning, scan frequency): confirms vulnerability scans in the reporting period were actually launched on the expected monthly cadence and none is stale. Fails any scan whose LAUNCH_DATETIME is empty or more than 35 days old. Fields checked: LAUNCH_DATETIME (date).

Every record must satisfy: Launch Date has a value. A record is marked failed when: Launch Date is more than 35 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

VM Remediation Tickets

Test name

Test description

Test logic

Qualys - High-Severity Vulnerabilities Remediated Within SLA

Enforces a severity-tiered remediation SLA: any high-severity Qualys remediation ticket (SEVERITY 4 or 5) that is past its due date fails the check, while lower-severity tickets are not flagged by this control. Checks the SEVERITY and overDue fields. Supports NIST SP 800-53 Rev. 5 RA-5(d) and SI-2, CMMC 2.0 / NIST 800-171 3.11.3, and ISO/IEC 27001:2022 Annex A A.8.8.

A record is marked failed when: Severity is 4 or more and Overdue is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Qualys VM Remediation Tickets Have Due Dates And Are Not Overdue

NIST SP 800-53 Rev 5 SI-2 (Flaw Remediation): every vulnerability remediation ticket must have a defined remediation deadline (DUE_DATETIME) and must not be past due (overDue). Flags remediation SLA breaches. Fails any ticket with an empty due date or overDue=true. Fields checked: DUE_DATETIME (date), overDue (boolean).

Every record must satisfy: Due date has a value. Every record must satisfy: Overdue is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

Rally

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rapid7

List of Asset Groups

Test name

Test description

Test logic

Rapid7 Asset Groups Contain Assets

Supports NIST 800-53 Rev5 CM-8 / RA-5 (asset inventory and scan scope completeness): every InsightVM asset group must contain at least one asset so scan scope and reporting groupings are not empty. Checks numberField.assets is 1 or more.

Every record must satisfy: Assets is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Assets

Test name

Test description

Test logic

Rapid7 Assets Assessed For Configuration Policies

Supports NIST 800-53 Rev5 CM-6 / RA-5 (configuration baseline assessment): every InsightVM asset must have been assessed against configuration policies so baseline drift is detected. Checks booleanField.assessedForPolicies is true.

Every record must satisfy: Assessed for Policies is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rapid7 Assets Assessed For Vulnerabilities

Supports NIST 800-53 Rev5 RA-5 (vulnerability scan coverage): every InsightVM asset in inventory must have been assessed for vulnerabilities. Checks booleanField.assessedForVulnerabilities is true.

Every record must satisfy: Assessed for Vulnerabilities is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rapid7 Assets Scanned Within the Last 45 Days

Supports NIST 800-53 Rev5 RA-5 (vulnerability scanning frequency): every InsightVM asset must have a non-empty lastScanned date that is within the last 45 days so vulnerability data stays current. Checks dateField.lastScanned.

Every record must satisfy: Last Scanned has a value. A record is marked failed when: Last Scanned is more than 45 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Rapid7 InsightVM - Administrator Role Assignments Reviewed

Flags Rapid7 InsightVM accounts that hold an administrator role so you can confirm each one still needs privileged access.

A record is sent for review when: Role is empty. A record is sent for review when: Role contains "Administrator". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Rapid7 InsightVM - No Locked-Out User Accounts

Checks every Rapid7 InsightVM account for a locked state and flags locked accounts so the lockout can be investigated.

A record is sent for review when: Lockout is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerabilities by Asset

Test name

Test description

Test logic

Rapid7 Asset Vulnerabilities Below High CVSS Score

Supports NIST 800-53 Rev5 RA-5 (risk-based remediation prioritization): no vulnerability finding on the asset may have a CVSS severity score of 7.0 or higher (High/Critical). Checks numberField.severityScore is below 7.

Every record must satisfy: CVSS Severity is less than 7. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Rapid7 No Critical Vulnerabilities On Asset

Supports NIST 800-53 Rev5 RA-5 / SI-2 (flaw remediation): no vulnerability finding on the asset may carry a Critical severity rating. Checks textField.severity is not Critical.

Every record must satisfy: Severity does not equal "Critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerabilities by Site

Test name

Test description

Test logic

Rapid7 No Critical Or Severe Vulnerabilities At Site

Supports NIST 800-53 Rev5 RA-5 / SI-2 (flaw remediation): no vulnerability finding at the site may carry a Critical or Severe severity rating. Checks textField.severity is neither Critical nor Severe.

Every record must satisfy: Severity is none of "Critical" or "Severe". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Rapid7 Site Vulnerabilities Within Remediation SLA

Supports NIST 800-53 Rev5 SI-2 (flaw remediation timeliness): no open vulnerability finding at the site may have been first recorded more than 90 days ago, enforcing a 90-day remediation SLA. Checks dateField.firstRecorded.

Every record must satisfy: First Recorded has a value. A record is marked failed when: First Recorded is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Re:amaze

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Salesflare

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Salesforce

List of Permission Sets

Test name

Test description

Test logic

Salesforce Permission Sets Have A Description

Requires every custom permission set to carry a description so each grant of additional privileges is documented and justifiable during access reviews. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege) and CM-8, ISO/IEC 27001:2022 A.5.15 (Access Control) and A.8.2, and SOC 2 CC6.3. Field checked: description.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Profiles

Test name

Test description

Test logic

Full License Profiles Are Custom Built For Least Privilege

Surfaces profiles on the full user license that are standard rather than custom, since standard profiles cannot be tailored and often grant broader access than needed.

A record is sent for review when: User License equals "Salesforce" and Custom is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Salesforce Usernames Follow Email Identifier Standard

Enforces the organization's user-identifier standard by requiring every Salesforce username to be a well-formed email address, supporting unique, attributable identifiers. Maps to NIST 800-53 Rev5 IA-4 (Identifier Management), NIST 800-171 3.5.5/3.5.6 and ISO/IEC 27001:2022 A.5.16 (Identity Management). Field checked: username.

Every record must satisfy: Username is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Salesforce Users Are Not Assigned The System Administrator Profile

Surfaces every account assigned the highly privileged built-in System Administrator profile so privileged access can be justified and kept to a minimum during access reviews. Maps to NIST 800-53 Rev5 AC-6(5) (Privileged Accounts) and AC-2, NIST 800-171 3.1.5 (Least Privilege), ISO/IEC 27001:2022 A.8.2 (Privileged Access Rights) and SOC 2 CC6.3. Field checked: profile. Customize the profile name to your org's admin profile.

Every record must satisfy: Profile does not equal "System Administrator". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Salesforce Users Have Logged In Within 90 Days

Detects dormant/inactive Salesforce accounts by requiring each user's most recent login to be within the last 90 days. Maps to NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts), NIST 800-171 3.1.11, ISO/IEC 27001:2022 A.5.18 and SOC 2 CC6.2/CC6.3. Field checked: lastLoginDate.

A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Profile Details

Test name

Test description

Test logic

Salesforce Custom Profile Has Documented Justification

Requires any custom (non-standard) Salesforce profile to carry a description documenting its business justification; standard profiles pass automatically. Ensures tailored privilege sets are reviewed and justified. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege) and CM-8, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.5.15 and A.8.2, and SOC 2 CC6.3. Fields checked: isCustom, description.

A record is marked failed when: Custom is true and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Salesforce Service Cloud

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SentinelOne

List of Agents

Test name

Test description

Test logic

SentinelOne Agents Are Assigned to an Account and Group

Ensures every SentinelOne endpoint agent is enrolled under an account and a management group so that protection policy is inherited (NIST 800-53 Rev5 CM-8), by requiring non-empty computerName, accountName, and groupName.

Every record must satisfy: Endpoint Name has a value and Account has a value and Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SentinelOne Agents Completed a Recent Successful Scan

Confirms each SentinelOne endpoint agent has a last successful scan within the past 7 days (NIST 800-53 Rev5 SI-3), catching endpoints that are stale or have never scanned. Requires computerName and lastScanDate to be present; an empty lastScanDate (never scanned) fails.

Every record must satisfy: Endpoint Name has a value and Last Scan Date has a value. A record is marked failed when: Last Scan Date is more than 7 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SentinelOne Agents Scanned Within 30 Days

Verifies every SentinelOne endpoint agent completed a successful scan within the last 30 days (NIST 800-53 Rev5 SI-3, RA-5). Field: lastScanDate (from agents.lastSuccessfulScanDate). A stale or never-scanned agent is surfaced for review.

A record is sent for review when: Last Scan Date is empty. A record is marked failed when: Last Scan Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Alerts

Test name

Test description

Test logic

SentinelOne - Security Alerts Have Been Reported

Verifies that every SentinelOne cloud-detection alert carries a reported timestamp (reportedDate, from alertInfo.reportedAt), evidencing that detections were escalated/reported rather than left untracked. Supports incident reporting and response under NIST SP 800-53 Rev. 5 IR-6 and AU-6, ISO/IEC 27001:2022 Annex A A.5.25, and SOC 2 CC7.3.

Every record must satisfy: Reported Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Alerts Are Named and Reported

Confirms each SentinelOne alert has a rule name, an alert id, and a non-empty reportedDate, evidencing that detections were surfaced/triaged rather than left unreported (NIST 800-53 Rev5 SI-4 / IR-6).

Every record must satisfy: Name has a value and Alert ID has a value and Reported Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Alerts Carry a Valid Severity Classification

Verifies every SentinelOne alert is classified with a recognized severity of Low, Medium, High, or Critical so that responders can prioritize remediation (NIST 800-53 Rev5 SI-4). A proof with no rows is treated as needsReview: this template only flags violations, so a zero-row proof cannot distinguish a compliant state from evidence that was never collected.

A record is marked failed when: Severity has a value and Severity is none of "Low", "Medium", "High" or "Critical". A record is sent for review when: Severity is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Alerts Recorded With Identifier And Timestamp

Verifies every cloud-detection alert has a name, alert id, severity, and creation timestamp so the monitoring record is auditable (NIST 800-53 Rev5 AU-3, SI-4, IR-6). Fields: name, alertId, severity, createdDate.

Every record must satisfy: Name has a value and Alert ID has a value and Severity has a value and Created Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Device Control Rules

Test name

Test description

Test logic

SentinelOne Device Control Rules Are Enabled

Confirms each SentinelOne USB/peripheral device-control rule is Enabled (status = Enabled) and fully specified with a name and ruleType, enforcing removable-media restrictions (NIST 800-53 Rev5 MP-7 / SC-41). Empty proof needs review because it may indicate no device-control policy is configured.

Every record must satisfy: Status equals "Enabled" and Name has a value and Rule Type has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Groups

Test name

Test description

Test logic

SentinelOne Groups Are Named And Correctly Typed

Verifies every endpoint group has a name and id and a recognized membership type (static/dynamic/pinned) so grouping used for policy scoping is well-formed (NIST 800-53 Rev5 CM-8, AC-3). Fields: name, groupId, type (from groups.type).

Every record must satisfy: Name has a value and Group ID has a value. A record is marked failed when: Type is none of "static", "dynamic" or "pinned". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SentinelOne Groups Have An Accountable Creator

Verifies every group records a creator id and creation date so group configuration changes are attributable (NIST 800-53 Rev5 AU-2, CM-3). Fields: creatorId (from groups.creatorId), createdOn (from groups.createdAt).

Every record must satisfy: Creator ID has a value and Created On has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SentinelOne Policy Groups Are Governed and Attributable

Verifies each SentinelOne policy group is fully defined with a name, id, type, and a recorded creator so that endpoint policy baselines are attributable (NIST 800-53 Rev5 CM-2), by requiring non-empty name, groupId, type, and creatorId.

Every record must satisfy: Name has a value and Group ID has a value and Type has a value and Creator ID has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

SentinelOne - No Console Accounts Inactive Over 90 Days

Flags SentinelOne console accounts whose last login (lastLogin) is more than 90 days ago so dormant privileged accounts can be reviewed, disabled, or removed. Supports account management and inactivity review under NIST SP 800-53 Rev. 5 AC-2(3), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18.

A record is marked failed when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Console Users Are Named and Role-Assigned

Verifies each SentinelOne console account is attributable to a named individual with an assigned role (NIST 800-53 Rev5 AC-2 / AC-6) by requiring non-empty fullName, email, and roleId.

Every record must satisfy: Full Name has a value and Email has a value and Role ID has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Console Users Are Not Inactive

Flags SentinelOne console users whose last login is more than 90 days ago as candidates for disablement (NIST 800-53 Rev5 AC-2(3)). Users that have never logged in (empty lastLogin) are not flagged; each row must still carry an email of record.

A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SentinelOne Console Users Have MFA Enabled

Verifies every management-console user has two-factor authentication enabled (NIST 800-53 Rev5 IA-2(1), AC-2). Field: mfa (boolean, from users.twoFaEnabled).

Every record must satisfy: MFA is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow

List of Assets

Test name

Test description

Test logic

ServiceNow - Company Assets Have An Assigned Owner

Confirms each inventoried company asset (configuration item) has an assigned owner, supporting accountable asset inventory. Supports NIST SP 800-53 Rev. 5 CM-8 and PM-5. Fields: assignedTo (ast_assigned_to display value), name (ast_display_name display value).

Every record must satisfy: Asset Name has a value and Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow Asset Inventory Has Serial Numbers

The configuration item / asset inventory must uniquely and accurately identify each component (NIST 800-53 Rev5 CM-8 System Component Inventory). Flags assets whose serialNumber is empty so they can be reviewed. Note: intended for hardware CIs; non-serialized items (e.g. software) will surface for review at threshold 1.0.

Every record must satisfy: Model Number has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Catalog Tasks

Test name

Test description

Test logic

ServiceNow - Catalog Tasks Are Prioritized And Time-Stamped

Confirms each catalog fulfillment task carries a priority and a recorded open date, ensuring change/request work is triaged and traceable. Supports NIST SP 800-53 Rev. 5 CM-3 and SA-10. Fields: priority (priority.display_value), opened_at (opened_at.value).

Every record must satisfy: Priority has a value and Open Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow - Catalog Tasks Routed To A Fulfillment Group

Confirms each service catalog fulfillment task is assigned to an owning group so that provisioning/change work is tracked to an accountable team. Supports NIST SP 800-53 Rev. 5 CM-3 and SA-10. Field: assignment_group (assignment_group.display_value).

Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow Catalog Tasks Are Routed To An Assignment Group

Every catalog/fulfillment task must be assigned to a responsible team so change and service work is owned and actioned (NIST 800-53 Rev5 CM-3 Configuration Change Control / SA-5). Checks that assignment_group is populated on all catalog tasks.

Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

ServiceNow Closed Catalog Tasks Record A Completion Date

Completed change/fulfillment work must have an auditable completion timestamp (NIST 800-53 Rev5 CM-3 Configuration Change Control / AU-3). Implication: unless the state contains 'Closed' the row passes; any Closed catalog task must have closed_at populated. Uses !contains 'Closed' which matches the out-of-the-box Closed Complete/Incomplete/Skipped states.

A record is marked failed when: State contains "Closed" and Closed Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Groups

Test name

Test description

Test logic

ServiceNow Active Assignment Groups Document Their Purpose

Routes active ServiceNow assignment groups with no description to review.

A record is sent for review when: Active is true and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow Assignment Groups Have An Owner

Every assignment group must have a designated manager/owner accountable for its membership and work (NIST 800-53 Rev5 AC-2 Account Management / PS-2). Flags groups where the manager field is empty. Note: at threshold 1.0 any un-owned group fails, which is the intended finding.

Every record must satisfy: Manager has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Incidents

Test name

Test description

Test logic

ServiceNow - Closed Incidents Have An Accountable Assignee

Confirms that any incident with a closure timestamp was assigned to an individual owner, establishing accountability for resolved incidents. Open incidents (no closed_at) are not penalized. Supports NIST SP 800-53 Rev. 5 IR-5 and AU-3. Fields: closed_at (closed_at.value, empty when not closed), assigned_to (assigned_to.display_value).

A record is marked failed when: Closed has a value and Assigned To is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow - Incidents Retain An Update Audit Trail

Confirms every incident records who last modified it and when, preserving an audit trail for incident handling. Supports NIST SP 800-53 Rev. 5 AU-3 and IR-4. Fields: sys_updated_by (sys_updated_by.display_value), sys_updated_on (sys_updated_on.value).

Every record must satisfy: Updated By has a value and Updated has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow - Incidents Routed To An Assignment Group

Confirms every incident is routed to an owning assignment group so that response ownership is unambiguous. Supports NIST SP 800-53 Rev. 5 IR-4 and IR-5. Field: assignment_group (assignment_group.display_value).

Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

ServiceNow Critical Incidents Have An Assigned Owner

High-severity incidents must have a named individual accountable for resolution, not just a queue (NIST 800-53 Rev5 IR-4 Incident Handling). Implication: unless priority is the out-of-the-box '1 - Critical' value, the row passes; critical incidents must have assigned_to populated. Note: relies on the default ServiceNow priority label; if an org renames priority choices this check fails open (passes) for renamed values.

A record is marked failed when: Priority equals "1 - Critical" and Assigned To is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow Incident Record Completeness

Incident records must capture the minimum data needed to track and document an event (NIST 800-53 Rev5 IR-5 Incident Monitoring / IR-6 Reporting): an identifier (number), a reporter (caller_id), and a description (short_description). Flags incidents missing any of these required fields.

Every record must satisfy: Number has a value and Short Description has a value and Caller has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow Incidents Are Not Left Open Beyond 90 Days

Flags ServiceNow incidents that remain open more than 90 days after they were raised. This is an ageing check on open incidents: an incident that took longer than 90 days but has since closed is not flagged.

A record is marked failed when: Opened is more than 90 days in the past and Closed is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow Incidents Are Routed To An Assignment Group

Every incident must be assigned to a responsible team so it is triaged and worked, not orphaned (NIST 800-53 Rev5 IR-4 Incident Handling / IR-5 Monitoring). Checks that the assignment_group field is populated on all incidents in the period.

Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed.

List of Users

Test name

Test description

Test logic

ServiceNow Active User Accounts Are Individually Identifiable

Flags active ServiceNow accounts that carry no username or no email address.

A record is marked failed when: Active is true and Username is empty. A record is marked failed when: Active is true and Email is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

ServiceNow Active Users Have MFA Enabled

Enforces multifactor authentication for the ServiceNow platform (NIST 800-53 Rev5 IA-2(1)/IA-2(2)). For every active user (active=true) the enable_multifactor_authn flag must be true; deactivated accounts are exempt. Implemented as an implication (not active OR mfa) so service/deactivated accounts do not cause false failures.

A record is marked failed when: Active is true and MFA Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Shortcut

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SmartRecruiters

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snowflake

List of Users

Test name

Test description

Test logic

Snowflake - MFA Enrolled for Active Users

Flags Snowflake user accounts that are still active but are not enrolled in multi-factor authentication.

A record is marked failed when: Disabled is false and MFA is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snowflake - No Active Users With 90-Day Inactivity

Flags Snowflake user accounts that are still active but have not signed in during the last 90 days.

A record is marked failed when: Disabled is false and Last login is more than 90 days in the past. A record is sent for review when: Disabled is false and Last login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users and Roles

Test name

Test description

Test logic

Snowflake - MFA Enabled For All Active Users

Flags Snowflake user accounts that can still log in but do not have multi-factor authentication enabled.

A record is marked failed when: Disabled is false and MFA is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snowflake - No Active Users With 90-Day Login Inactivity

Flags Snowflake user accounts that can still log in but have not signed in within the last 90 days.

A record is marked failed when: Disabled is false and Last login is empty. A record is marked failed when: Disabled is false and Last login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Time Travel Configuration by Database

Test name

Test description

Test logic

Snowflake - Time Travel Retention Enabled For Database Objects

Checks that every database, schema, and table in the selected Snowflake database keeps at least one day of Time Travel history so deleted or modified data can be recovered.

Every record must satisfy: Retention time in days is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Time Travel Configuration for Databases

Test name

Test description

Test logic

Snowflake - Time Travel Retention Enabled For All Databases

Checks that every Snowflake database retains at least one day of Time Travel history so deleted or modified data can be recovered.

Every record must satisfy: Retention time in days is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Snyk

List of Issues

Test name

Test description

Test logic

Snyk - No Open Critical-Severity Issues

Supports NIST 800-53 Rev5 RA-5 (vulnerability remediation): every open Snyk finding must be below Critical severity, so no unremediated Critical vulnerabilities remain. Checks the 'severity' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Severity does not equal "critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snyk - No Open High or Critical Issues

Supports NIST 800-53 Rev5 RA-5 (risk-based remediation SLA): every open Snyk finding must be below High severity, enforcing that both High and Critical vulnerabilities are remediated. Checks the 'severity' field is neither 'high' nor 'critical'. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Severity is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snyk - No Open IaC Configuration Findings

Supports NIST 800-53 Rev5 CM-6 (configuration settings / secure baseline): Snyk IaC configuration findings must be remediated, so no open finding has issueType 'Configuration'. Checks the 'issueType' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Issue Type does not equal "Configuration". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snyk - No Open SAST (Code) Findings

Supports NIST 800-53 Rev5 SA-11 (developer security testing / static analysis): all Snyk Code (SAST) findings must be resolved, so no open finding has issueType 'Code'. Checks the 'issueType' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Issue Type does not equal "Code". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Snyk - No Suppressed (Ignored) Issues

Supports NIST 800-53 Rev5 RA-5 (suppression governance / risk acceptance): open findings must not be silently suppressed, so no finding has status 'Ignored'. Checks the 'status' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected.

Every record must satisfy: Status does not equal "Ignored". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users by Org

Test name

Test description

Test logic

Snyk - Org Members Have Assigned Role and Email

Supports NIST 800-53 Rev5 AC-2 (account management): every Snyk organization member must have both an assigned role (privilege set) and an identifiable email, so no account is unattributed or missing an authorization role. Checks the 'role' and 'email' fields. Empty proof (no members returned) is inconclusive and flagged for review.

Every record must satisfy: Role has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Splunk

List of Alerts

Test name

Test description

Test logic

Splunk Alerts Shared At App Or Global Scope

Verifies each Splunk alert is shared at app or global scope (not private to a single user) so monitoring coverage persists and stays centrally visible when an individual account is removed. Maps to NIST 800-53 Rev5 SI-4/CM-6, ISO/IEC 27001:2022 A.8.16, SOC 2 CC7.2. Checks the alert sharing scope.

A record is marked failed when: Sharing is none of "GLOBAL" or "APP". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Splunk Security Alerts Are Enabled

Verifies configured Splunk alerts/saved-search alerts are enabled (not disabled) so security monitoring rules are actively evaluating events. Maps to NIST 800-53 Rev5 SI-4/AU-6, ISO/IEC 27001:2022 A.8.16, SOC 2 CC7.2. Checks the alert enabled/disabled status.

Every record must satisfy: Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Triggered Alerts

Test name

Test description

Test logic

Splunk Triggered Alerts Are Severity Classified

Verifies every triggered/fired Splunk alert carries a valid severity classification (Info, Low, Medium, High or Critical) so security events are categorized for triage and incident response. Maps to NIST 800-53 Rev5 IR-5/AU-6/SI-4, ISO/IEC 27001:2022 A.5.25, SOC 2 CC7.3. Checks the triggered-alert severity.

A record is marked failed when: Severity is none of "Info", "Low", "Medium", "High" or "Critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Splunk Accounts Use Centralized Authentication

Verifies Splunk user accounts authenticate through a centralized identity provider (LDAP or SAML) rather than local Splunk-native credentials, enforcing central identity management. Maps to NIST 800-53 Rev5 IA-2, NIST 800-171 3.5.1/3.5.2, ISO/IEC 27001:2022 A.5.16. Checks the account authentication type.

A record is marked failed when: Authentication system is none of "LDAP" or "SAML". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Splunk Dormant User Account Review

Flags Splunk user accounts with no successful login in the last 90 days so dormant/inactive accounts are disabled or reviewed (account management). Maps to NIST 800-53 Rev5 AC-2(3), NIST 800-171 3.1.11, ISO/IEC 27001:2022 A.5.18. Checks last_successful_login.

A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Splunk User Accounts Have Roles Assigned

Ensures every Splunk user account has at least one role assigned so authorization is explicit and there are no orphaned/role-less accounts (account provisioning and access enforcement). Maps to NIST 800-53 Rev5 AC-2/AC-6, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.18. Checks the roles field.

Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

SpotDraft

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

SugarCRM

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Taleez

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

TalentLyft

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Teamleader

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Teamtailor

Application Lifecycle Summary

Test name

Test description

Test logic

Job Application Records Identify The Candidate, Position, And Application Date

Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received.

Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Teamwork

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tellent Recruitee

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable

Access Group

Test name

Test description

Test logic

Access Group Entries Are Fully Provisioned

NIST 800-53 Rev5 AC-3 / AC-6: every access group principal entry must be fully defined (name, principalName, principalPermissions present) and the group build must be complete (status COMPLETED). Fields: name, principalName, principalPermissions, status.

Every record must satisfy: Name has a value and Principal Name has a value and Principal Permissions has a value and Status equals "COMPLETED". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Access Groups Do Not Grant To All Users

NIST 800-53 Rev5 AC-6 (Least Privilege): no access group entry may grant access to the broad all_users principal; each principalType must be a scoped user or group. Field: principalType (emitted values user, group, all_users).

Every record must satisfy: Principal Type does not equal "all_users". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable - Access Groups Reviewed/Updated Within 365 Days

Verifies each Tenable access group configuration has been reviewed or updated within the last 365 days, evidencing periodic access-control review (NIST 800-53 Rev5 AC-2, CM-3). Checks the lastUpdated date field and fails any access group not touched within the window.

A record is sent for review when: Last Updated is empty. A record is marked failed when: Last Updated is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Export Vulnerabilities

Test name

Test description

Test logic

Tenable Scans Report No Critical or High Vulnerabilities

NIST SP 800-53 RA-5 / SI-2: vulnerabilities discovered through scanning must be remediated. Verifies that no exported Tenable.io vulnerability finding has a severity of critical or high.

Every record must satisfy: Severity is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable Vulnerabilities Are Remediated Within 30 Days

NIST SP 800-53 SI-2: flaws must be remediated within an organization-defined timeframe. Flags any Tenable.io vulnerability whose first-found date is more than 30 days in the past.

A record is sent for review when: First Found is empty. A record is marked failed when: First Found is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerability Findings Have Triage Metadata

NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring): each exported vulnerability finding must carry the metadata required to triage and remediate it - the affected asset, the detecting plugin, and a severity. Fields: assetName, pluginName, severity.

Every record must satisfy: Asset Name has a value and Plugin Name has a value and Severity has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Access Control Permissions

Test name

Test description

Test logic

Access Control Permissions Are Fully Attributed

NIST 800-53 Rev5 AC-2 (Account Management): every access-control permission entry must be attributable for review - it must name the permission, the granted permissions, and the objects it applies to. Fields: name, permissions, objects.

Every record must satisfy: Name has a value and Permissions has a value and Objects has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Admin Impersonation Permissions Granted

NIST 800-53 Rev5 AC-6 (Least Privilege): access-control permission entries must not carry the privileged CanImpersonateAdmin action, which allows acting as an administrator. Field: permissions (comma-joined action display names, e.g. CanScan, CanView, CanImpersonateAdmin).

Every record must satisfy: Permissions does not contain "CanImpersonateAdmin". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable - Access Permissions Are Assigned to a User or Group

Verifies each Tenable access-control permission has at least one grantee (user or group) so no orphaned/unassigned permission entries exist (NIST 800-53 Rev5 AC-2, AC-6). Checks the users and groups text fields, which Tenable populates with 'No Users'/'No Groups' when a permission has no subjects.

A record is marked failed when: Users equals "No Users" and Groups equals "No Groups". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable - Access Permissions Are Scoped, Not Granted Over All Assets

Verifies each Tenable access-control permission is scoped to specific objects rather than the blanket All Assets scope, enforcing least privilege (NIST 800-53 Rev5 AC-6). Checks the objects text field (Tenable joins object names/types) and fails any permission whose scope includes AllAssets.

Every record must satisfy: Objects does not contain "AllAssets". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable - Access Permissions Define Explicit Actions

Verifies each Tenable access-control permission grants at least one explicit action rather than an empty/misconfigured grant, supporting deliberate least-privilege configuration (NIST 800-53 Rev5 AC-6, CM-6). Checks the permissions text field, which Tenable populates with 'No Actions' when a permission has no actions.

Every record must satisfy: Permissions does not equal "No Actions". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Assets

Test name

Test description

Test logic

Tenable Asset Inventory Records Are Complete

NIST SP 800-53 CM-8: system component inventory must record identifying attributes for each asset. Verifies every Tenable.io asset records a hostname, IP address, and operating system.

Every record must satisfy: Name has a value and IP Address has a value and Operating System has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable Assets Have Been Observed Within the Last 90 Days

NIST SP 800-53 CA-7 / RA-5: continuous monitoring and vulnerability scanning. Flags any Tenable asset whose last seen date is more than 90 days ago, indicating it is no longer being observed by the platform.

A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable Vulnerability Management - Assets Seen Within 30 Days

Checks that every Tenable asset has been seen by a scanner, agent, or connector within the last 30 days and flags stale inventory entries.

A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Attestations

Test name

Test description

Test logic

PCI ASV Attestations Are Passing

NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring) / PCI DSS ASV: each PCI ASV scan attestation must be in a passed state. Field: status (emitted value passed for a passing attestation).

Every record must satisfy: Status equals "passed". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Tenable - PCI ASV Attestation Scan Is Not Expired

Verifies each Tenable PCI ASV attestation still has a valid (non-expired) scan so vulnerability-scan coverage remains current (NIST 800-53 Rev5 RA-5). Checks the scan_expiration_date field and fails any attestation whose expiration date is in the past.

A record is sent for review when: Scan Expiration is empty. A record is marked failed when: Scan Expiration is more than 0 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable - PCI ASV Attestations Updated Within 90 Days

Verifies each Tenable PCI ASV attestation has been updated within the last 90 days, evidencing the required quarterly ASV scan cadence (NIST 800-53 Rev5 RA-5(2), CA-2). Checks the updated_at date field and fails any attestation not refreshed within the window.

A record is sent for review when: Updated On is empty. A record is marked failed when: Updated On is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable PCI ASV Attestation Records Are Complete

NIST SP 800-53 CA-2 / RA-5: assessment and scan results must be documented and tracked. Verifies every Tenable.io PCI ASV attestation record includes a name, identifier, and status.

Every record must satisfy: Name has a value and Id has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Users

Test name

Test description

Test logic

Tenable Enabled Users Are Not Locked Out

NIST SP 800-53 AC-7: locked-out accounts indicate repeated failed authentication that requires review. Verifies that every enabled Tenable.io user account is not in a locked-out state.

A record is sent for review when: Enabled is empty. A record is sent for review when: Lockout is empty. A record is marked failed when: Enabled is true and Lockout is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Tenable User Records Include Name, Username, and Email

NIST SP 800-53 AC-2: account management requires complete, identifiable account records. Verifies every Tenable.io user record includes a display name, username, and email address.

Every record must satisfy: Name has a value and Username has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

User Accounts Show Recent Login Activity

NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts): every user account must have logged in within the last 90 days; accounts idle longer than 90 days are flagged for review or disablement. Field: lastLogin (ISO date).

A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

UAR Application

Test name

Test description

Test logic

Tenable User Access Review Records Are Complete

NIST SP 800-53 AC-2 and AC-6: periodic access reviews require complete records of access and assigned role. Verifies every Tenable.io user access review record includes an owner, username, email, and role.

Every record must satisfy: Owner has a value and Username has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Traffit

User Account Lifecycle

Test name

Test description

Test logic

Deleted ATS Accounts Are Deactivated

Flags user accounts that the source system reports as deleted but that are still marked active.

A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Trello

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

vtiger

List of Users

Test name

Test description

Test logic

CRM User Accounts Are Attributable To A Named Individual

Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Wallarm

List of Users

Test name

Test description

Test logic

Wallarm No Stale Or Dormant User Logins

Detects dormant/stale Wallarm console accounts: every user must have a last_login_time that is present and within the last 180 days. Accounts that have never logged in (empty last_login_time) or have not logged in for more than 180 days are flagged for disable/removal review. NIST SP 800-53 Rev 5 AC-2(3) Disable Accounts / AC-2 Account Management. Fields checked: last_login_time (userList).

A record is marked failed when: Last Login is more than 180 days in the past. Every record must satisfy: Last Login has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wallarm Users Have Valid Email Identity

Identity assurance: every Wallarm user account must be tied to a well-formed email address ([email protected]) so access maps to a real, attributable identity rather than a shared/orphaned login. NIST SP 800-53 Rev 5 IA-4 Identifier Management / AC-2 Account Management. Regex is JS+.NET safe and case-explicit. Fields checked: email (userList).

Every record must satisfy: Email Address is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Scanner State

Test name

Test description

Test logic

Wallarm Scanner Active And Next Scan Scheduled

Active monitoring, not just deployed: the scanner must not be administratively disabled (state present and not 'disabled') and must have an upcoming scan scheduled within the next 30 days (next_scan_time present and less than 30 days from now). A disabled scanner or an indefinitely-deferred next scan means protection is effectively off. NIST SP 800-53 Rev 5 SI-4 System Monitoring / SC-7 Boundary Protection. Fields checked: state, next_scan_time (scannerState).

Every record must satisfy: State has a value. Every record must satisfy: State does not equal "disabled". Every record must satisfy: NextScanTime is less than 30 days in the future. Every record must satisfy: NextScanTime has a value. A record is marked failed when: NextScanTime is more than 0 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Wallarm Scanner Completed A Recent Scan

Continuous monitoring cadence: the Wallarm scanner must have completed a scan within the last 7 days (last_scan_time present and not more than 7 days ago). A stale or absent last scan means external attack-surface discovery has lapsed. NIST SP 800-53 Rev 5 CA-7 Continuous Monitoring / SI-4 System Monitoring / RA-5 Vulnerability Scanning. Fields checked: last_scan_time (scannerState).

A record is marked failed when: LastScanTime is more than 7 days in the past. Every record must satisfy: LastScanTime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Wallarm Scanner Vulnerability Detection Is Current

Vulnerability scanning frequency: the Wallarm scanner's last vulnerability detection run (last_vuln_time) must be present and within the last 30 days, proving the vulnerability engine is actively running on the defined schedule. NIST SP 800-53 Rev 5 RA-5 Vulnerability Monitoring and Scanning / SI-4 System Monitoring. Fields checked: last_vuln_time (scannerState).

A record is marked failed when: LastVulnTime is more than 30 days in the past. Every record must satisfy: LastVulnTime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Wave Financial

Chart of Accounts

Test name

Test description

Test logic

Chart Of Accounts Contains No Suspense Or Uncategorized Accounts

Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity.

Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Chart Of Accounts Entries Have An Account Number And Name

Confirms every account in the chart of accounts has both an account number and an account name.

Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Vendor and Customer Master Lists

Test name

Test description

Test logic

Vendor And Customer Master Records Are Named And Classified

Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified.

Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Wiz

List of Users

Test name

Test description

Test logic

Wiz Console Accounts With No Sign-In In 90 Days

Flags non-suspended Wiz console accounts that have not signed in within the last 90 days.

A record is marked failed when: Is Suspended is false and Last Login is more than 90 days in the past. A record is sent for review when: Is Suspended is false and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wiz User Accounts Have Identity Attributes

NIST 800-53 Rev5 IA-4 / AC-2: identifier management requires every account to have the attributes needed to attribute it to a person or service. Verifies name and email are populated on each Wiz user. Fields: name, email (emitted directly by the users GraphQL query / proof spec).

Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wiz User Accounts Have Name and Email Identifiers

NIST 800-53 Rev5 AC-2 / IA-4 (account management and identifier assignment): fails any Wiz console user account missing a display name or a valid email address (must contain '@'), so every account maps to an identifiable, contactable owner.

Every record must satisfy: Name has a value and Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wiz User Email Is Well-Formed

NIST 800-53 Rev5 IA-4 / AC-2: account identifiers must be valid so notifications and access reviews reach the correct owner. Verifies each user's email matches a basic [email protected] structure. Regex uses no letters or inline flags so it is case-agnostic and parses in both.NET and JS. Field: email (emitted directly by the users GraphQL query / proof spec).

Every record must satisfy: Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Vulnerabilities

Test name

Test description

Test logic

No Critical Vulnerabilities Marked as Rejected

NIST 800-53 Rev5 RA-5 / CA-5 (risk acceptance requires review): fails any finding whose cvssSeverity is CRITICAL while its findingStatus is REJECTED, surfacing critical findings that were dismissed/risk-accepted without going through a documented POA&M review.

A record is marked failed when: CVSS Severity equals "CRITICAL" and Finding Status equals "REJECTED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

No Open Critical Vulnerabilities

NIST 800-53 Rev5 RA-5 (vulnerability remediation): fails any finding whose cvssSeverity is CRITICAL while its findingStatus is still OPEN, so unremediated critical vulnerabilities are surfaced. Resolved criticals and lower-severity findings pass.

A record is marked failed when: CVSS Severity equals "CRITICAL" and Finding Status equals "OPEN". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

No Open High-Severity Vulnerabilities

NIST 800-53 Rev5 RA-5 (remediate within severity-based SLA): fails any finding whose cvssSeverity is HIGH while its findingStatus is still OPEN, tracking the high-severity remediation queue separately from criticals. Resolved highs and other severities pass.

A record is marked failed when: CVSS Severity equals "HIGH" and Finding Status equals "OPEN". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Resolved Vulnerabilities Record a Resolution Date

NIST 800-53 Rev5 RA-5 / CA-5 (remediation is documented): fails any finding whose findingStatus is RESOLVED but has no resolvedAt date, so remediation of a closed finding is evidenced with a resolution timestamp. Open/in-progress findings are not required to have a resolution date and pass.

A record is marked failed when: Finding Status equals "RESOLVED" and Resolved At is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerability Findings Are Attributed to an Asset and Subscription

NIST 800-53 Rev5 CM-8 / RA-5 (component inventory and remediation ownership): fails any finding missing an assetName or subscriptionName, so every vulnerability is tied to an identifiable asset and cloud subscription accountable for remediation.

Every record must satisfy: Asset Name has a value and Subscription has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerability Findings Carry a Valid Severity Rating

NIST 800-53 Rev5 RA-5 / RA-3 (findings categorized by risk): fails any finding whose cvssSeverity is not one of the recognized ratings CRITICAL/HIGH/MEDIUM/LOW/NONE, catching blank or unclassified findings that would escape severity-based triage.

A record is marked failed when: CVSS Severity is empty. A record is marked failed when: CVSS Severity is none of "CRITICAL", "HIGH", "MEDIUM", "LOW" or "NONE". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Vulnerability Findings Have a Valid Remediation Status

NIST 800-53 Rev5 RA-5 (track findings to remediation): fails any finding whose findingStatus is not one of the defined workflow states OPEN/IN_PROGRESS/RESOLVED/REJECTED, ensuring every finding is in a tracked remediation state rather than a blank or unknown status.

A record is marked failed when: Finding Status is empty. A record is marked failed when: Finding Status is none of "OPEN", "IN_PROGRESS", "RESOLVED" or "REJECTED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wiz Vulnerability Findings Have Required Identity

NIST 800-53 Rev5 RA-5 / CM-8: every vulnerability finding must carry the identifying metadata needed to triage and track remediation. Verifies id, name, and cvssSeverity are populated on each finding. Fields: id, name, cvssSeverity (all always emitted by the vulnerabilities transform).

Every record must satisfy: ID has a value and Name has a value and CVSS Severity has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Workable

Application Lifecycle Summary

Test name

Test description

Test logic

Rejected Job Applications Record A Reject Reason

Flags job applications that were rejected without a documented reason for the rejection.

A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Account Lifecycle

Test name

Test description

Test logic

ATS User Records Attributable And Role Assigned

Checks that every user record has a name, email, unique identifier, and an assigned access role.

Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Workday

List of Employees

Test name

Test description

Test logic

Employee Department Assignment Present

Organizational placement for access grouping and data ownership: every worker on the Workday roster is assigned to a department, supporting role/group-based access and asset ownership attribution. Checks textField.department is non-empty. Maps to NIST 800-53 Rev5 AC-2 (organizational account grouping) and ISO/IEC 27001:2022 Annex A A.5.9 (inventory of associated assets/owners).

Every record must satisfy: Department has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Employee Onboarding Start Date Recorded

Joiner-lifecycle record-keeping: every worker on the Workday roster has a recorded employment start date, establishing the authoritative provisioning/onboarding date used to time access grants. Checks dateField.startDate is non-empty. Maps to ISO/IEC 27001:2022 Annex A A.5.16 (identity lifecycle) and A.6.1 (screening/onboarding), and GDPR Art.30 (records of processing for HR data).

Every record must satisfy: Start Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Employee Roster Identity Completeness

Access-governance completeness: every worker on the Workday employee roster has both a name and an email so each account can be uniquely identified and reconciled during access reviews. Checks textField.name and textField.email are non-empty. Maps to NIST 800-53 Rev5 AC-2 (account management / identification), ISO/IEC 27001:2022 Annex A A.5.16 (identity management), and SOC 2 CC6.1.

Every record must satisfy: Name is not blank and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Employees with Status Change

Test name

Test description

Test logic

Active Employee Status Termination Integrity

Account-status data integrity for joiner/mover/leaver events: no worker is simultaneously flagged active while carrying a termination (end) date, which would indicate a stale or contradictory account state that could leave access provisioned after departure. A row fails when the worker's status is ACTIVE and an end date is nonetheless recorded. Maps to NIST 800-53 Rev5 AC-2 (account management integrity) and SOC 2 CC6.2.

A record is marked failed when: Status equals "ACTIVE" and End Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Terminated Employee Offboarding Date Recorded

Leaver-lifecycle control: any worker in the personnel-status-change proof who is no longer active must have a recorded end date, evidencing that a termination/offboarding date exists to drive timely deprovisioning. A row fails when the worker's status is INACTIVE and no end date is recorded. Maps to NIST 800-53 Rev5 AC-2(3) (disable/remove accounts), ISO/IEC 27001:2022 Annex A A.6.5 (responsibilities after termination), and SOC 2 CC6.2/CC6.3.

A record is marked failed when: Status equals "INACTIVE" and End Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Wrike

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Zendesk

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Zendesk Groups Contain No Deleted Entries

Access review hygiene: deleted Zendesk groups must not linger in the membership/role listing, since stale groups obscure who has access to what. Checks listOfGroups deleted boolean. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.18 (Access rights), SOC 2 CC6.2/CC6.3.

Every record must satisfy: Deleted is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Zendesk Groups Have A Documented Purpose

Access governance: each Zendesk group (used to scope agent access) must carry a description documenting its purpose so access-rights reviews are meaningful. Checks listOfGroups description. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.18 (Access rights), SOC 2 CC6.3.

Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Organizations

Test name

Test description

Test logic

Zendesk Organizations Have Verified Domain Names

Account provenance / asset inventory: each customer Organization record must declare its domain name(s) so end-user accounts are correctly and automatically mapped to a known organization (prevents mis-scoped access). Checks listOfOrganizations domain_names. Maps to NIST 800-53 Rev5 AC-2 (Account Management), ISO/IEC 27001:2022 Annex A A.5.9 (Inventory of information and associated assets), SOC 2 CC6.1.

Every record must satisfy: Domain Names has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Zendesk Administrator Accounts Flagged For Least-Privilege Review

Least-privilege access review: flags any account holding the elevated 'admin' role so reviewers can confirm each administrator is still justified (agent/end-user roles pass). Requires the 'All roles' List of Users proof variant, which emits the role column. Checks listOfUsers role. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege), CMMC 2.0 / NIST 800-171 3.1.5, ISO/IEC 27001:2022 Annex A A.5.15/A.8.2 (Access control / Privileged access), SOC 2 CC6.3.

Every record must satisfy: Role does not equal "admin". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Zendesk User Accounts Have Complete Identity Attributes

Access review support: every Zendesk user/agent account must have a display name and an email so accounts are attributable to a real identity (no anonymous/orphan accounts). Checks listOfUsers name and email. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.16 (Identity management), SOC 2 CC6.1/CC6.2.

Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Zendesk User Accounts Use Managed Email Domains

Identity governance / least privilege: Zendesk accounts should authenticate with managed corporate email, not personal free-mail providers (gmail/yahoo/hotmail/outlook/icloud/protonmail), which cannot be centrally deprovisioned. Regex-checks listOfUsers email. Maps to NIST 800-53 Rev5 AC-2, CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.16 (Identity management), SOC 2 CC6.1.

Every record must satisfy: Email does not match the pattern "@([Gg][Mm][Aa][Ii][Ll]|[Yy][Aa][Hh][Oo][Oo]|[Hh][Oo][Tt][Mm][Aa][Ii][Ll]|[Oo][Uu][Tt][Ll][Oo][Oo][Kk]|[Ii][Cc][Ll][Oo][Uu][Dd]|[Pp][Rr][Oo][Tt][Oo][Nn][Mm][Aa][Ii][Ll])\.[Cc][Oo][Mm]$". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Zoho BugTracker

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Zoho Desk

List of Groups

Test name

Test description

Test logic

User Groups Are Named And Their Purpose Is Documented

Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed.

Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

List of Issues

Test name

Test description

Test logic

Issues Are Identified And Have A Tracked Status

Checks that every ticket in the list has a name and a current status so the work item can be tracked.

Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

No Unresolved Issues Older Than 90 Days

Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work.

A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

List of Users

Test name

Test description

Test logic

Active Ticketing User Accounts Have An Assigned Role

Flags active ticketing user accounts that carry no assigned role.

A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.

Active User Accounts Do Not Use Shared Or Generic Identities

Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account.

A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review.

User Accounts Are Attributable To A Named Individual

Checks that every user account has a name and a valid email address, so each account can be traced back to a real person.

Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed.

Did this answer your question?