Hyperproof provides a library of evidence tests that you can link to your Hypersyncs to automatically test proof as it is collected. For detailed information on how to link tests to a Hypersync, see Using the automated control test library.
Available tests are listed by Hypersync and proof type. If no records are returned in the collected proof, the test result is marked either Failed or Needs review.
ActiveCampaign
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank, and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Aha!
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented
| Checks that every user group has a name and flags groups without a description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value, and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that remain unresolved, revealing aging work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review.
|
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank, and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Ashby
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value, Job Title has a value, and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS
Asset Inventory
Test name | Test description | Test logic |
AWS - EC2 Instance Inventory Records Are Complete | Checks that every EC2 instance reported by Systems Manager inventory records an instance ID, host name, IP address, and operating system name and version. | Every record must satisfy: Instance ID has a value, Computer Name has a value, IP Address has a value, Platform has a value, and Platform Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - Systems Manager Managed Instances Report A Healthy Agent | Checks that every inventoried EC2 instance has a management agent installed, reporting a well-formed version, and has not lost its connection to the management service. | Every record must satisfy: Agent Type has a value and Agent Version matches the pattern "^[0-9]{1,6}(\.[0-9]{1,6}){2,3}$" and Instance Status does not equal "ConnectionLost". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Backup Jobs
Test name | Test description | Test logic |
RDS and DocumentDB daily backups enabled | Confirm backup Retention Period >= 1 and automated Backups Enabled = true | Every record must satisfy: Backup Job ID has a value and Status equals "COMPLETED". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Bucket Object Lock
Test name | Test description | Test logic |
AWS - S3 Bucket Object Lock Enabled With A Default Retention Period | Checks that every S3 bucket has Object Lock enabled with a default retention period configured. | Every record must satisfy: Bucket has a value, Object lock status equals "Enabled," and Retention Period has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Bucket Policy Status
Test name | Test description | Test logic |
S3 Bucket Policy Status confirms restricted access | Examine: Bucket policy JSON documents | Every record must satisfy: Bucket has a value, and Policy Type equals "Not Public". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cluster Backup Retention Period
Test name | Test description | Test logic |
AWS - Aurora Cluster Backup Retention Meets Minimum | Checks that every Amazon RDS/Aurora cluster in the evidence retains automated backups for at least seven days. | Every record must satisfy: Cluster Identifier has a value, and Cluster Backup Retention Period is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cluster Storage Encrypted
Test name | Test description | Test logic |
AWS - Aurora Cluster Storage Encrypted At Rest | Checks that storage encryption is enabled on every Amazon RDS/Aurora cluster listed in the evidence. | Every record must satisfy: Cluster Identifier has a value, and Cluster Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cross-Region Aggregation
Test name | Test description | Test logic |
AWS - Security Hub Aggregates Findings From Linked Regions | Confirms Security Hub cross-region finding aggregation is configured and that each linked region is recorded against an aggregation region. | Every record must satisfy: Home Region has a value, and Linked Region has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Findings
Test name | Test description | Test logic |
AWS - Security Hub Active Findings Have No Failed Compliance Checks | Flags active Security Hub findings whose compliance check failed and that have not been resolved or suppressed. | A record is marked failed when: Status equals "FAILED" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - Security Hub High And Critical Findings Remediated Within 30 Days | Flags active high and critical Security Hub findings that have gone unresolved for more than 30 days. | A record is marked failed when: Severity is one of "CRITICAL" or "HIGH" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 30. The test passes only if every record passes. |
Security Hub Low Findings Remediated Within 180 Days | Flags active LOW severity Security Hub findings older than 180 days that have not been resolved or suppressed. | A record is marked failed when: Severity equals "LOW" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 180. A record is marked failed when: Severity equals "LOW" and Record State equals "ACTIVE" and Workflow Status is empty and Age (Days) is greater than 180. The test passes only if every record passes. |
Security Hub Medium Findings Remediated Within 90 Days | Flags active MEDIUM severity Security Hub findings older than 90 days that have not been resolved or suppressed. | A record is marked failed when: Severity equals "MEDIUM" and Record State equals "ACTIVE" and Workflow Status is none of "RESOLVED" or "SUPPRESSED" and Age (Days) is greater than 90. A record is marked failed when: Severity equals "MEDIUM" and Record State equals "ACTIVE" and Workflow Status is empty and Age (Days) is greater than 90. The test passes only if every record passes. |
IAM Password Policy
Test name | Test description | Test logic |
AWS - IAM Account Password Policy Enforces A 14 Character Minimum | Checks that each AWS account enforces a custom IAM password policy with a strong minimum length. | Every record must satisfy: Policy equals "Custom password policy" and Minimum password length is 14 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - IAM Account Password Policy Prevents Reuse Of The Last 24 Passwords | Checks that each AWS account's IAM password policy prevents reuse of recent passwords. | Every record must satisfy: Policy equals "Custom password policy" and Count of passwords to remember to prevent reuse has a value and Count of passwords to remember to prevent reuse is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Instance Backup Retention Period
Test name | Test description | Test logic |
AWS - RDS Instance Backup Retention Meets Minimum | Checks that every Amazon RDS database instance in the evidence retains automated backups for at least seven days. | Every record must satisfy: Instance Identifier has a value and Instance Backup Retention Period is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Instance Storage Encrypted
Test name | Test description | Test logic |
AWS - RDS Instance Storage Encrypted At Rest | Checks that every Amazon RDS database instance in the proof has storage encryption enabled. | Every record must satisfy: Instance Identifier has a value, and Instance Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Integrations Providing Findings
Test name | Test description | Test logic |
AWS - Security Hub Findings Integrations Are Identified | Confirms the account has enabled product integrations feeding findings into Security Hub, and that each one is identified by product and vendor. | A record is sent for review when: Name is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Access Keys
Test name | Test description | Test logic |
AWS - IAM Active Access Keys Rotated Within 90 Days | Checks that active IAM user access keys have been rotated within the last 90 days. | A record is sent for review when: Creation Time is empty. A record is marked failed when: Status equals "Active" and Creation Time is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - IAM Active Access Keys Unused For 45 Days Are Disabled | Checks that active IAM user access keys which are unused or have never been used are not left enabled. | A record is marked failed when: Status equals "Active" and Last Used Date is more than 45 days in the past. A record is marked failed when: Status equals "Active" and Last Used Date is empty and Creation Time is more than 45 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of ACLs
Test name | Test description | Test logic |
AWS - WAF Web ACLs Are Associated With A Protected Resource | Highlights WAF web ACLs that are not associated with any protected resource, so unused or orphaned ACLs get reviewed. | A record is sent for review when: Resources is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - WAF Web ACLs Enforce A Block Default Action | Checks that each WAF web ACL blocks requests by default, so traffic reaches the protected application only by explicit rule. | Every record must satisfy: Default Action equals "Block". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Backup Plans
Test name | Test description | Test logic |
AWS - Backup Plans Have Executed At Least Once | Checks that every AWS Backup plan is named and has actually run at least once, so a defined plan is not silently producing no backups. | Every record must satisfy: Backup Plan Name has a value and Last Runtime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS Backup Plans Have Executed Within The Last 35 Days | Flags AWS Backup plans that have not run in the last 35 days, and routes plans that have never run to review. | A record is marked failed when: Last Runtime is more than 35 days in the past. A record is sent for review when: Last Runtime is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Client VPN Endpoints
Test name | Test description | Test logic |
AWS - Client VPN Endpoints Use Private Client CIDR Ranges | Checks that each AWS Client VPN endpoint assigns connecting clients addresses from a private, non-internet-routable IP range. | Every record must satisfy: Client CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Configurations
Test name | Test description | Test logic |
AWS - Lambda Functions Do Not Run On Deprecated Runtimes | Flags serverless functions running on a vendor-deprecated language runtime. | A record is marked failed when: Runtime matches the pattern "^(nodejs|nodejs4\.3(-edge)?|nodejs6\.10|nodejs8\.10|nodejs(10|12|14|16|18|20)\.x|python2\.7|python3\.[6-9]|ruby2\.[57]|ruby3\.2|java8|go1\.x|provided|provided\.al2|dotnetcore(1\.0|2\.0|2\.1|3\.1)|dotnet(5\.0|6|7))$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - Lambda Functions Have Been Updated Within The Last Year | Flags serverless functions whose code has not been redeployed within the last year. | A record is sent for review when: Last Modified is empty. A record is sent for review when: Last Modified is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Containers
Test name | Test description | Test logic |
AWS - ECS Container Instances Are Not Inactive Or Failed Registration | Checks that registered ECS container instances are in a usable, active state. | A record is marked failed when: Status is one of "INACTIVE" or "REGISTRATION_FAILED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - ECS Container Instances Report Host Identity And Docker Engine Version | Checks that registered ECS container instances report the host identity and container runtime details needed to attribute workloads. | Every record must satisfy: EC2 Instance ID has a value and Docker Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of EKS Clusters
Test name | Test description | Test logic |
AWS - EKS Clusters Are Healthy And Not Running An End Of Support Kubernetes Version | Checks that each EKS cluster reports status ACTIVE and a Kubernetes version that is still within vendor support. Only ACTIVE passes: a cluster in CREATING, DELETING, PENDING or UPDATING does not evidence a healthy running cluster and is flagged too. | Every record must satisfy: Name has a value and Status equals "ACTIVE" and Kubernetes version has a value and Kubernetes version does not match the pattern "^1\.([0-9]|1[0-9]|2[0-9]|30)([^0-9]|$)". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Groups
Test name | Test description | Test logic |
AWS - IAM Groups Avoid Inline Policies And Have Members | Checks that IAM groups grant permissions through managed policies rather than inline policies, and flags groups that have no members. | A record is marked failed when: Inline Policy is true. A record is sent for review when: Users equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM Roles
Test name | Test description | Test logic |
AWS - IAM Role Maximum Session Duration Is Not Excessive | Checks that IAM roles do not permit an excessive maximum session duration. | A record is marked failed when: Session Duration matches the pattern "^([89]|1[0-2]) hours". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - IAM Roles Do Not Trust Wildcard Principals | Checks that IAM role trust policies do not allow wildcard principals to assume the role. | A record is marked failed when: Trusted Entities contains "*". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM SAML Providers
Test name | Test description | Test logic |
AWS - IAM SAML Provider Metadata Is Not Expired Or Expiring | Checks that SAML identity provider metadata documents in IAM have a valid expiration date and are not expired or close to expiring. | A record is marked failed when: Expiration Time is less than 30 days in the future. A record is sent for review when: Expiration Time is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Images
Test name | Test description | Test logic |
AWS - EC2 AMIs Are Not Publicly Shared | Checks that no AWS EC2 machine image owned by the account is shared publicly with all other AWS accounts. | Every record must satisfy: Visibility equals "Private". The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
AWS - EC2 AMIs Use EBS-Backed Root Volumes | Checks that every AWS EC2 machine image boots from an EBS-backed root volume, which unlike ephemeral local disk can be encrypted at rest. | Every record must satisfy: Root Device Type equals "ebs". The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Instance IPs
Test name | Test description | Test logic |
AWS - EC2 Instances Stopped For More Than 90 Days | Flags EC2 instances that have been sitting in a stopped state for more than 90 days so dormant compute can be reviewed or decommissioned. | A record is sent for review when: State equals "stopped" and State Transition Time is empty. A record is marked failed when: State equals "stopped" and State Transition Time is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - Running EC2 Instances Do Not Expose Public IPv4 Addresses | Flags running EC2 instances that have a public IPv4 address so internet-reachable compute is reviewed and justified. | A record is marked failed when: State equals "running" and Public IP Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Running EC2 Instances Do Not Expose Public IPv6 Addresses | Flags running EC2 instances that carry a globally routable IPv6 address. | A record is marked failed when: State equals "running" and IPv6 Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Instances
Test name | Test description | Test logic |
AWS - Aurora Instances Are Attached To A VPC | Checks that Aurora database instances are attached to a VPC. | Every record must satisfy: Instance Identifier has a value and VPC has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - Aurora Instances Report An Available Status | Checks that Aurora database instances report an available operational status. | Every record must satisfy: Instance Identifier has a value and Status equals "Available". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - RDS Instance Inventory Complete And VPC-Attached | Checks that each Amazon RDS database instance record identifies its engine, size and VPC so the database inventory is complete. | Every record must satisfy: Instance Identifier has a value and Engine has a value and Size has a value and VPC has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - RDS Instances Configured For Multi-AZ | Checks that every Amazon RDS database instance in the evidence is deployed with Multi-AZ redundancy. | Every record must satisfy: Instance Identifier has a value and Multi-AZ is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Rule Groups
Test name | Test description | Test logic |
AWS - WAF Rule Groups Are Fully Identified In Inventory | Confirms every WAF rule group in the evidence carries a name, an identifier, and a well-formed ARN so the inventory is complete and traceable. | Every record must satisfy: Name has a value and Rule Group ID has a value and Rule Group ARN matches the pattern "^arn:aws[a-z-]*:wafv2:". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Running Instances
Test name | Test description | Test logic |
Inventory maintained for EC2, EKS, RDS, Lambda, and more | Examine: Inventory records for infrastructure components | Every record must satisfy: Instance ID has a value and Instance Type has a value and Availability Zone has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Security Groups
Test name | Test description | Test logic |
AWS - Default Security Group Denies All Inbound Traffic | Flags any default security group that still carries inbound rules, so unassigned resources cannot inherit permissive network access. | A record is marked failed when: Security Group Name equals "default" and Inbound Rules is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - Security Group Inventory Attributes Are Complete | Checks that every security group records an ID, name, owning account, parent network, and a description explaining its purpose. | Every record must satisfy: Security Group ID has a value and Security Group Name has a value and VPC ID has a value and Description has a value and Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Default Security Group Denies All Outbound Traffic | Flags a VPC default security group that still has outbound rules attached. | A record is marked failed when: Security Group Name equals "default" and Outbound Rules is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Snapshots
Test name | Test description | Test logic |
AWS - EBS Snapshots Are Encrypted At Rest | Checks that every block storage snapshot in the report is encrypted at rest and carries a snapshot identifier. | Every record must satisfy: Snapshot ID has a value and Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - EBS Snapshots Completed Successfully | Checks that every block storage snapshot in the report reached a completed state and records the time it was started. | Every record must satisfy: Snapshot ID has a value and Status equals "completed" and Started has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of SSO Users
Test name | Test description | Test logic |
AWS - Identity Center SSO Users Carry A User Name And User Id | Checks that every IAM Identity Center SSO user record carries both a user name and a unique user identifier so access reviews can be completed. | Every record must satisfy: User Name has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Subnets
Test name | Test description | Test logic |
CIDR ranges reviewed | Examine: CIDR assignments and VPC/subnet allocation documentation | Every record must satisfy: Subnet ID has a value and State equals "available" and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Public/private subnet separation enforced | Checks that every subnet returned carries a subnet id, its parent VPC id and an IPv4 CIDR block, so each subnet in the proof is identifiable and attributable to a VPC. Does not establish that every subnet in the account was collected. Does not determine whether a subnet is public or private: the proof does not expose mapPublicIpOnLaunch or route table associations. | Every record must satisfy: Subnet ID has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Routing tables reviewed | Examine: Route table configurations and change control documentation | Every record must satisfy: Subnet ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
VPC configurations documented per region | Checks that every subnet returned carries a subnet id, its parent VPC id and an IPv4 CIDR block across the collected regions. | Every record must satisfy: Subnet ID has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
AWS - IAM Users With Console Passwords Unused For 90 Days | Flags AWS IAM users whose console password has not been used in the last 90 days so dormant accounts can be reviewed, disabled, or removed. | A record is sent for review when: Password Last Used is empty. A record is marked failed when: Password Last Used is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users with MFA Devices
Test name | Test description | Test logic |
AWS - IAM Users Do Not Rely On SMS MFA | Flags AWS IAM users enrolled in SMS text-message MFA, which is weaker than app-based or hardware security key authenticators. | A record is marked failed when: MFA Devices contains "SMS". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS - IAM Users Have An MFA Device Enrolled | Checks that every AWS IAM user in the evidence has at least one multi-factor authentication device enrolled. | Every record must satisfy: MFA equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users with MFA Settings
Test name | Test description | Test logic |
MFA enabled for all users with console or privileged access | Confirm MFA is enforced via IAM policies or service control policies (SCPs) for all users with console or privileged access | Every record must satisfy: MFA contains "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Volumes
Test name | Test description | Test logic |
AWS - EBS Volumes Are Encrypted At Rest | Checks that every block storage volume in the report is encrypted at rest and records its identifier and lifecycle state. | Every record must satisfy: Volume ID has a value and State has a value and Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of VPCs
Test name | Test description | Test logic |
VPC flow logging enabled | Verify that flow logging is enabled for all VPCs and traffic is directed to a secure destination (e.g., CloudWatch, S3) | Every record must satisfy: VPC ID has a value and State equals "available". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Workloads
Test name | Test description | Test logic |
AWS - EKS Deployments Have Available Pods And No Unavailable Replicas | Checks that every deployed workload has at least one available pod and reports zero failed replicas at the time evidence was collected. | Every record must satisfy: Name has a value and Pod Count is greater than 0 and Status matches the pattern "(^|[^0-9])0 Failed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - EKS Workloads Are Not Deployed In The Default Namespace | Checks that every Kubernetes workload runs in a purpose-named namespace instead of the default namespace, so resources stay separated and policy can be scoped. | Every record must satisfy: Name has a value and Namespace has a value and Namespace does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Policies & Access Control
Test name | Test description | Test logic |
AWS - Lambda Deployment Packages Are Encrypted With A Customer Managed KMS Key | Checks that serverless function deployment packages are encrypted with a customer managed key. | Every record must satisfy: Encryption equals "Yes" and AWS KMS Key has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - Lambda Execution Roles Do Not Use Broadly Privileged Role Names | Flags serverless functions whose execution role name indicates broad or administrative privilege. | A record is sent for review when: IAM Role matches the pattern ":role/.*(Administrator|PowerUser|FullAccess)". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Restore Testing
Test name | Test description | Test logic |
AWS - Backup Restore Test Jobs Completed Successfully | Checks that every restore test job run during the reporting period finished in a completed state with a recorded completion time. | Every record must satisfy: Restore Job Id has a value and Status equals "COMPLETED" and Completion Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - Backup Restore Test Validation Did Not Fail | Checks that no restore test job reported a failed or timed-out validation result, so restored data is confirmed usable and not just recoverable. | A record is sent for review when: Validation Status equals "VALIDATING". Every record must satisfy: Restore Job Id has a value and Validation Status is none of "FAILED" or "TIMED_OUT". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Access Control List
Test name | Test description | Test logic |
S3 bucket ACLs are private or restrictive | Examine: S3 ACL configurations and AWS Config rules | Every record must satisfy: Grantee ID has a value and Grantee Type equals "CanonicalUser" and Permission has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Encryption
Test name | Test description | Test logic |
S3 buckets encrypted at rest using AWS-managed or customer-managed KMS keys | Verifies that S3 buckets are encrypted at rest using AWS-managed or customer-managed KMS keys. Verify that BucketEncryption is enabled and SSEAlgorithm is either aws:kms or AES256. | Every record must satisfy: Bucket has a value and Encryption Key Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Lifecycle Configuration
Test name | Test description | Test logic |
AWS - S3 Bucket Lifecycle Rules Are Enabled | Checks that every S3 bucket lifecycle rule in the proof is in an enabled state rather than disabled. | Every record must satisfy: Bucket has a value and Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS - S3 Lifecycle Rules Do Not Expire Current Objects Within 90 Days | Flags S3 lifecycle rules that expire current object versions in fewer than 90 days. | A record is marked failed when: Status equals "Enabled" and Action equals "Expire" and Applies to equals "Current Objects" and Days to Transition is less than 90. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
S3 Bucket Replication
Test name | Test description | Test logic |
If used for backup, S3 replication configuration supports contingency | Examine: S3 replication rules and target regions | Every record must satisfy: Bucket has a value and Replication Rule Name has a value and Status equals "Enabled" and Destination Bucket has a value. The test passes if at least 50% of records pass. If the proof contains no records, the test is marked failed. |
S3 Bucket Versioning
Test name | Test description | Test logic |
S3 bucket versioning configuration documented | Examine: S3 configuration and versioning policy | Every record must satisfy: Bucket has a value and Bucket Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account)
Backup Plan Details
Test name | Test description | Test logic |
AWS (Single Account) - Backup Plan Rules Copy To A Secondary Vault | Checks that each backup plan rule copies backups to a secondary vault so a single vault is not the only copy. | Every record must satisfy: Destination Backup Vault ARN has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account) - Backup Plan Rules Target A Vault And Cover Resources | Checks that each backup plan rule names a destination vault and that the plan has at least one resource selection assigned. | Every record must satisfy: Backup Plan Name has a value and Rule Name has a value and Target Backup Vault Name has a value and Backup Selections does not equal "[]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
IAM Password Policy
Test name | Test description | Test logic |
AWS IAM Password Policy Enforces Character Complexity | Verifies the account password policy requires uppercase, lowercase, number, and symbol characters (NIST 800-53 Rev5 IA-5(1)). Checks booleanField.requireUppercase/requireLowercase/requireNumbers/requireSymbols. | Every record must satisfy: Require Uppercase is true and Require Lowercase is true and Require Numbers is true and Require Symbols is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS IAM Password Policy Prevents Reuse Of Last 24 Passwords | Verifies the account password policy prevents reuse of at least the previous 24 passwords (NIST 800-53 Rev5 IA-5(1); CIS AWS Foundations 1.9). Checks numberField.passwordReuseCount; an unset reuse count yields NeedsReview at threshold 1.0. | Every record must satisfy: Password Reuse Count is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS IAM Password Policy Requires 14+ Character Minimum Length | Verifies the account password policy enforces a minimum length of at least 14 characters (NIST 800-53 Rev5 IA-5(1); CIS AWS Foundations 1.8). Checks numberField.minPasswordLength. | Every record must satisfy: Minimum Password Length is 14 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
IAM Password Policy Enforces Complexity And Reuse Prevention | CIS AWS 1.9 / NIST 800-53 Rev5 IA-5(1): verify the IAM account password policy requires symbols, numbers, uppercase and lowercase characters, and prevents reuse of the last 24 passwords. Fields: requireSymbols, requireNumbers, requireUppercase, requireLowercase, passwordReuseCount. | Every record must satisfy: Require Symbols is true and Require Numbers is true and Require Uppercase is true and Require Lowercase is true and Password Reuse Count is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Instance Storage Encrypted
Test name | Test description | Test logic |
AWS RDS Instances Have Storage Encryption Enabled | Verifies every RDS database instance has storage encryption enabled at rest (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.3.1). | Every record must satisfy: Storage Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Backup Plans
Test name | Test description | Test logic |
AWS (Single Account) - Backup Plans Have Executed Within The Last 35 Days | Flags backup plans that have not run in more than 35 days, so gaps in backup coverage are caught before they matter. | A record is marked failed when: Last Execution Date is more than 35 days in the past. A record is sent for review when: Last Execution Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Client VPN Endpoints
Test name | Test description | Test logic |
AWS (Single Account) - Client VPN Endpoints Are Documented And Use Private Client CIDR Ranges | Checks that every Client VPN endpoint records a description of its purpose and issues client addresses from a private, non-internet-routable range. | A record is marked failed when: Description is empty. A record is marked failed when: Client CIDR does not match the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of EC2 Assets
Test name | Test description | Test logic |
AWS EC2 Instances Report An Active SSM Inventory Agent | Verifies every inventoried EC2 instance has an Active SSM agent so patch and configuration state can be managed and reported (NIST 800-53 Rev5 CM-8/SI-2). Checks textField.instanceStatus equals the display value 'Active'. | Every record must satisfy: Instance Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of EC2 Images
Test name | Test description | Test logic |
AWS (Single Account) - EC2 AMIs Are Not Publicly Shared | Verifies no EC2 Amazon Machine Image is shared publicly, which could expose baked-in secrets or data (NIST 800-53 Rev5 AC-3/SC-7). Checks textField.visibility equals the display value 'private'. | Every record must satisfy: Visibility equals "private". The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
AWS EC2 AMIs Rebuilt Within The Last Year | Flags AMIs that have not been rebuilt in the last year, since an image bakes in the patch level it was created with. | A record is sent for review when: Creation Date is empty. A record is marked failed when: Creation Date is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of EC2 Running Instances
Test name | Test description | Test logic |
AWS (Single Account) - Running EC2 Instances Do Not Expose Public IPv4 Addresses | Flags running EC2 instances that carry a public IPv4 address. | A record is marked failed when: IP Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS EC2 Instances Have Detailed Monitoring Enabled | Verifies each running EC2 instance has detailed CloudWatch monitoring enabled to support continuous monitoring and anomaly detection (NIST 800-53 Rev5 SI-4/AU-12). Checks textField.monitoring equals the display value 'enabled'. | Every record must satisfy: Monitoring equals "enabled". The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of EC2 Security Groups
Test name | Test description | Test logic |
EC2 Security Groups Are VPC Scoped And Documented | NIST 800-53 Rev5 CM-8 SC-7: verify every EC2 security group belongs to a VPC (no legacy EC2-Classic) and carries a non-empty description for inventory/attack-surface governance. Fields: vpcID, description. | Every record must satisfy: VPC ID has a value and Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of EC2 Snapshots
Test name | Test description | Test logic |
AWS EBS Snapshots Are Encrypted At Rest | Verifies every EBS snapshot is encrypted at rest (NIST 800-53 Rev5 SC-28). Checks booleanField.encryption is true. | Every record must satisfy: Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
AWS EBS Snapshots Completed Successfully | Flags EBS snapshots that did not reach the completed state. | A record is marked failed when: Status equals "error". A record is sent for review when: Status does not equal "completed". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of EC2 Volumes
Test name | Test description | Test logic |
AWS EBS Volumes Are Encrypted At Rest | Verifies every EBS volume is encrypted at rest (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.2.1). Checks booleanField.encryption is true. | Every record must satisfy: Encryption is true. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
EC2 EBS Volumes Encrypted At Rest | CIS AWS 2.2.1 / NIST 800-53 Rev5 SC-28: verify every EBS volume is encrypted at rest. Fields: encryption (boolean), id. | Every record must satisfy: Encryption is true and Volume Id has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of EKS Clusters
Test name | Test description | Test logic |
AWS (Single Account) - EKS Clusters Are Active And Not Running An End Of Life Kubernetes Version | Confirms each Kubernetes cluster is in an active state and is not running a release that has reached end of life. | Every record must satisfy: Status equals "ACTIVE" and Kubernetes Version has a value and Kubernetes Version does not match the pattern "^1\.([12][0-9]|30)$". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Groups
Test name | Test description | Test logic |
AWS IAM Groups Do Not Use Inline Policies | Verifies IAM groups attach managed policies rather than inline policies, supporting least-privilege review and reuse (NIST 800-53 Rev5 AC-6; CIS AWS Foundations 1.15). Checks booleanField.inlinePolicy is false. | Every record must satisfy: Inline Policy is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of IAM Roles
Test name | Test description | Test logic |
AWS (Single Account) - IAM Role Maximum Session Duration Is Not Excessive | Flags IAM roles whose maximum session duration is eight hours or longer. | A record is marked failed when: Session Duration matches the pattern "^([89]|1[0-2]) hours". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS (Single Account) - IAM Roles Do Not Trust Wildcard Principals | Flags IAM roles whose trust policy can be assumed by any principal, so overly open role access can be found and corrected. | A record is marked failed when: Trusted Entity contains "*". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM SAML Providers
Test name | Test description | Test logic |
AWS (Single Account) - IAM SAML Provider Federation Metadata Is Not Expired | Checks that each SAML identity provider used for federated sign-in has valid metadata that is not expired or expiring within 30 days. | A record is sent for review when: Expiration Time is empty. A record is marked failed when: Expiration Time is less than 30 days in the future. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM Users
Test name | Test description | Test logic |
AWS (Single Account) - IAM Console Credentials Unused For More Than 90 Days | Flags IAM users whose console password has not been used in more than 90 days so dormant credentials can be reviewed and disabled. | A record is sent for review when: Password Last Used is empty. A record is marked failed when: Password Last Used is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM Users MFA
Test name | Test description | Test logic |
AWS IAM Users Have MFA Enabled | Verifies every IAM user with console access has an MFA device enrolled (NIST 800-53 Rev5 IA-2(1); CIS AWS Foundations 1.10). Checks textField.mfa contains the display value 'MFA Enabled'. | Every record must satisfy: MFA contains "MFA Enabled". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of IAM Users MFA Devices
Test name | Test description | Test logic |
AWS (Single Account) - IAM Users Enrolled In Phishing-Resistant MFA | Checks that IAM users are protected by a FIDO security key rather than only SMS or authenticator-app multi-factor methods. | Every record must satisfy: MFA Devices contains "U2F". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account) - IAM Users Have An MFA Device Enrolled | Checks that every IAM user in the evidence has at least one multi-factor authentication device enrolled. | Every record must satisfy: MFA equals "MFA Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Integrations Providing Findings
Test name | Test description | Test logic |
AWS (Single Account) - Security Hub Finding Providers Are Enabled And Identified | Confirms Security Hub has at least one finding provider enabled for import and that each enabled provider is identified by product and vendor name. | Every record must satisfy: Product Name has a value and Company Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Network ACLs
Test name | Test description | Test logic |
AWS (Single Account) - Custom Network ACLs Do Not Allow Unrestricted Inbound Traffic | Flags customer-managed network ACL rules that allow inbound traffic from any IPv4 or IPv6 address. | A record is marked failed when: Default equals "No" and Rule Number contains "Inbound Rule:" and Action equals "allow" and Source/Destination matches the pattern "^(0\.0\.0\.0/0|::/0)$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS (Single Account) - Subnet-Associated Network ACLs Do Not Allow Unrestricted Outbound Traffic | Flags customer-managed network ACLs in use on a subnet that allow outbound traffic to any IPv4 or IPv6 destination. | A record is marked failed when: Default equals "No" and Associated With is 1 or more and Rule Number contains "Outbound Rule:" and Action equals "allow" and Source/Destination matches the pattern "^(0\.0\.0\.0/0|::/0)$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Security Hub Findings
Test name | Test description | Test logic |
Active Security Hub Findings Are Triaged | NIST 800-53 Rev5 IR-4 CA-7: verify no active Security Hub finding is left in the untriaged NEW workflow state. A row is a violation (Failed) when recordState is ACTIVE and workflowStatus is NEW. Fields: recordState, workflowStatus (WorkflowState). | A record is marked failed when: Record State equals "ACTIVE" and Workflow Status equals "NEW". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS Security Hub Has No Critical Or High Severity Findings | Verifies Security Hub reports no CRITICAL or HIGH severity findings, indicating vulnerabilities are remediated within SLA (NIST 800-53 Rev5 RA-5/SI-2). Checks textField.severity is neither 'CRITICAL' nor 'HIGH'. | Every record must satisfy: Severity is none of "CRITICAL" or "HIGH". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
No Active Failed Security Hub Findings | NIST 800-53 Rev5 RA-5 CA-7: verify no Security Hub finding is both an active record and a failed compliance check. A row is a violation (Failed) when recordState is ACTIVE and status is FAILED. Fields: status (Compliance.Status), recordState. | A record is marked failed when: Status equals "FAILED" and Record State equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of SSO Users
Test name | Test description | Test logic |
AWS (Single Account) - IAM Identity Center SSO Users Are Individually Identifiable | Flags single sign-on accounts that use a generic or shared name such as admin, root, or service instead of identifying an individual person. | A record is sent for review when: User Name is empty. A record is marked failed when: User Name matches the pattern "^([Aa][Dd][Mm][Ii][Nn]([Ii][Ss][Tt][Rr][Aa][Tt][Oo][Rr])?|[Rr][Oo][Oo][Tt]|[Gg][Uu][Ee][Ss][Tt]|[Ss][Hh][Aa][Rr][Ee][Dd]|[Ss][Vv][Cc]|[Ss][Ee][Rr][Vv][Ii][Cc][Ee]|[Tt][Ee][Ss][Tt])[-_.0-9]*(@[^@]*)?$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of VPC Subnets
Test name | Test description | Test logic |
AWS (Single Account) - Subnets Are Available And Mapped To A Parent VPC | Checks that every subnet is in the available state and records the subnet ID, parent VPC, and IPv4 CIDR block it belongs to. | Every record must satisfy: State equals "available" and Subnet Id has a value and VPC ID has a value and IPv4 CIDR has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account) - Subnets Use Private RFC 1918 IPv4 CIDR Ranges | Checks that every subnet is carved from a private, non-internet-routable IPv4 range rather than public address space. | Every record must satisfy: IPv4 CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of VPCs
Test name | Test description | Test logic |
AWS (Single Account) - Default VPC Does Not Exist | Checks that no virtual private cloud in the selected regions is the provider-created default VPC, so network boundaries rest on purpose-built, reviewed networks. DescribeVpcs reports only whether a VPC is the default; it says nothing about whether workloads use it. | Every record must satisfy: Default equals "No". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account) - VPC IPv4 CIDR Blocks Use Private Address Space | Checks that each virtual private cloud's primary IPv4 CIDR block falls within private, non-internet-routable address space. | Every record must satisfy: IPv4 CIDR matches the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|100\.(6[4-9]|[7-9][0-9]|1[01][0-9]|12[0-7])\.)". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Access Control List
Test name | Test description | Test logic |
AWS (Single Account) - S3 Bucket ACL Contains Only A Canonical-User FULL_CONTROL Grant | Checks that every entry in a bucket's access control list is a canonical-user FULL_CONTROL grant with no email grantee - the ACL shape left behind when Object Ownership is set to BucketOwnerEnforced. The grant rows carry no bucket-owner identity, so a cross-account canonical-user grant is not distinguishable here. | Every record must satisfy: Permission equals "FULL_CONTROL" and Grantee ID has a value and Grantee Email is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Encryption
Test name | Test description | Test logic |
AWS S3 Buckets Use Default Server-Side Encryption | Verifies each S3 bucket has default server-side encryption set to AES256, aws:kms, or aws:kms:dsse (NIST 800-53 Rev5 SC-28; CIS AWS Foundations 2.1.1). Checks textField.keyType against the valid SSE algorithms. | A record is marked failed when: SSE Algorithm is empty. A record is marked failed when: SSE Algorithm is none of "AES256", "aws:kms" or "aws:kms:dsse". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
S3 Buckets Encrypted With KMS Keys | NIST 800-53 Rev5 SC-28(1) / SC-12: verify S3 buckets use SSE-KMS (aws:kms) with a real KMS key managed for the bucket, rather than SSE-S3 only. Fields: keyType, kmsKey (kmsKey is 'NA' when no KMS key is bound). | Every record must satisfy: SSE Algorithm equals "aws:kms" and KMS Key ID does not equal "NA". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Lifecycle Configuration
Test name | Test description | Test logic |
AWS (Single Account) - S3 Lifecycle Actions Trigger On Object Age Not A Fixed Date | Confirms S3 lifecycle actions are triggered by how old an object is rather than a fixed calendar date, so the schedule keeps applying instead of firing once and stopping. | Every record must satisfy: Transition Date is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS (Single Account) - S3 Lifecycle Rules Are Named And Enabled | Confirms each S3 bucket lifecycle rule is named and in an enabled state, so the retention and cleanup schedule is actually being applied to objects in the bucket. | Every record must satisfy: Rule has a value and Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Object Lock Configuration
Test name | Test description | Test logic |
AWS S3 Buckets Have Object Lock Enabled | Verifies each S3 bucket has Object Lock enabled to provide write-once-read-many (WORM) immutability for retained data (NIST 800-53 Rev5 AU-9/CP-9). Checks textField.enabled equals the display value 'Enabled'. | Every record must satisfy: Enabled equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
AWS S3 Object Lock Is Enabled With A Default Retention Period | Flags buckets with Object Lock enabled but no default retention period configured. | A record is marked failed when: Enabled equals "Enabled" and Retention Period equals "NA". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
S3 Bucket Policy Status
Test name | Test description | Test logic |
AWS S3 Buckets Are Not Publicly Accessible | Verifies each S3 bucket's policy status is Private, not Public (NIST 800-53 Rev5 AC-3/SC-7; CIS AWS Foundations 2.1.5). Checks textField.policyType equals the display value 'Private'. | Every record must satisfy: Policy Type equals "Private". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Replication
Test name | Test description | Test logic |
AWS (Single Account) - S3 Bucket Replication Rule Is Enabled With A Destination Bucket | Confirms the bucket has a named replication rule that is enabled and points at a destination bucket, so a second copy of the data is being maintained. | Every record must satisfy: Replication Rule Name has a value and Status equals "Enabled" and Destination Bucket has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket Versioning
Test name | Test description | Test logic |
AWS S3 Buckets Have Versioning Enabled | Verifies each S3 bucket has object versioning enabled to protect against accidental or malicious deletion (NIST 800-53 Rev5 CP-9/SI-1; CIS AWS Foundations 2.1.2). Checks textField.status equals the display value 'Enabled'. | Every record must satisfy: Bucket Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
S3 Bucket MFA Delete Enabled | NIST 800-53 Rev5 CP-9 SC-28: verify MFA Delete is Enabled on versioned S3 buckets so object/version deletion requires MFA. Field: mfa (Enabled | Disabled | Never Enabled). | Every record must satisfy: Multifactor Authentication Delete equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Security Group Details
Test name | Test description | Test logic |
AWS (Single Account) - Default Security Group Does Not Permit Traffic | Flags any traffic rule configured on a default security group, which should not permit inbound or outbound traffic. | A record is marked failed when: Security Group Name equals "default" and Network Rules has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AWS (Single Account) - Security Group Inbound Rules Do Not Expose Non-Web Ports To The Internet | Flags security group inbound rules that are open to the entire internet on ports other than the standard web ports. | A record is marked failed when: Network Rules matches the pattern "^Inbound:.*"destination":"(0\.0\.0\.0/0|::/0)".*$" and Network Rules does not match the pattern "^Inbound:.*"portRange":"(80|443)".*$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure
Azure Activity Logs
Test name | Test description | Test logic |
Azure Activity Log Entries Are Within Retention Window | Verifies Azure activity-log entries are present and were recorded within the last 90 days, evidencing that management-plane logging is active and retained (NIST 800-53 Rev5 AU-2 / AU-11); checks timeStamp is not more than 90 days ago. | A record is sent for review when: Timestamp is empty. A record is marked failed when: Timestamp is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure Firewalls
Test name | Test description | Test logic |
Azure Firewall Boundary Devices Are Fully Identified in the Inventory | Checks that every row of the Azure Firewall evidence is a real firewall resource with a name and an owning resource group. | Every record must satisfy: Type equals "Microsoft.Network/azureFirewalls" and Name has a value and Resource Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Backup Configuration
Test name | Test description | Test logic |
Azure SQL Database Uses Geo-Redundant Backup Storage | Verifies Azure SQL databases use geo-redundant backup storage so backups survive a regional outage (NIST 800-53 Rev5 CP-6 / CP-9); checks backupStorageRedundancy contains Geo. | Every record must satisfy: Backup Storage Redundancy contains "Geo". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Backup Retention Days
Test name | Test description | Test logic |
Azure SQL Databases Retain Backups for at Least Seven Days | NIST SP 800-53 CP-9: conduct system backups and retain them to support recovery. Verifies every Azure SQL database short-term backup retention policy keeps backups for at least 7 days. | Every record must satisfy: Backup Retention Days is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure SQL Databases Retain Point-in-Time Backups for at Least 30 Days | NIST SP 800-53 CP-9: conduct and retain system backups sufficient for recovery. Verifies every Azure SQL database short-term (point-in-time restore) retention policy keeps backups for at least 30 days. | Every record must satisfy: Backup Retention Days is 30 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Firewall Policies
Test name | Test description | Test logic |
Azure Firewall Policies Enable Threat Intelligence Filtering | NIST SP 800-53 SC-7: monitor and control communications at external boundaries. Verifies every Azure Firewall policy enables threat intelligence-based filtering (threat intel mode is not Off). | Every record must satisfy: Threat Intel Mode does not equal "Off". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
IDPS Signatures
Test name | Test description | Test logic |
Azure Firewall IDPS Signatures Actively Block Traffic | Verifies Azure Firewall Premium IDPS signatures are set to block (deny) rather than alert-only so intrusions are prevented, not just logged (NIST 800-53 Rev5 SI-4 / SC-7); checks the alertOnly flag is false. | Every record must satisfy: Alert Only is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Alerts
Test name | Test description | Test logic |
Azure Defender Security Alerts Have Been Triaged | Verifies Microsoft Defender for Cloud security alerts are not left in an Active state (must be Resolved or Dismissed) evidencing incident handling (NIST 800-53 Rev5 IR-4 / SI-4); checks alert status. | A record is marked failed when: Status is none of "Resolved" or "Dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Application Configurations
Test name | Test description | Test logic |
Azure App Configuration Stores Are Located in United States Regions | Checks that every Azure App Configuration store is deployed in a United States region, which is where its configuration data resides. | Every record must satisfy: Location matches the pattern "^(eastus|westus|centralus|northcentralus|southcentralus|westcentralus|usgov|usdod|usnat|ussec)|(^| )US( |$|[0-9])|^United States". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure App Configuration Stores Use a SKU That Supports Private Link | Checks that every Azure App Configuration store runs on a pricing tier that supports private endpoints, so store traffic does not have to traverse a public endpoint. | Every record must satisfy: Pricing Tier does not equal "Free" and Pricing Tier has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Backup Jobs
Test name | Test description | Test logic |
Azure Backup Jobs Complete Successfully | NIST SP 800-53 CP-9: system backup. Verifies every Azure backup job in the proof period finished with a Completed status, confirming backups are running successfully. | Every record must satisfy: Status equals "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure Backup Jobs Did Not Fail | NIST SP 800-53 CP-9: ensure backups run reliably. Verifies no Azure backup job in the proof period ended in a Failed status (Completed, CompletedWithWarnings, and InProgress are acceptable), surfacing backup failures for follow-up. | Every record must satisfy: Status does not equal "Failed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Backup Policies
Test name | Test description | Test logic |
Azure Backup Policies Are Scheduled at Least Daily | Checks that every backup policy in the Recovery Services vault runs on a daily or hourly schedule rather than weekly or less often. | Every record must satisfy: Frequency is none of "Weekly" or "Monthly" and Frequency has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Backups
Test name | Test description | Test logic |
Azure MySQL Server Backup Completed Recently | Verifies each Azure MySQL server backup completed within the last 8 days so restore points stay current (NIST 800-53 Rev5 CP-9); checks completedTime is not more than 8 days ago. | Every record must satisfy: Time of Completion has a value. A record is marked failed when: Time of Completion is more than 8 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure PostgreSQL Flexible Server Backup Completed Recently | Verifies each Azure PostgreSQL flexible-server backup completed within the last 8 days so restore points stay current (NIST 800-53 Rev5 CP-9); checks completedTime is not more than 8 days ago. | Every record must satisfy: Time of Completion has a value. A record is marked failed when: Time of Completion is more than 8 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Databases
Test name | Test description | Test logic |
Azure MySQL Servers Run A Supported Major Version | Verifies Azure MySQL servers run a supported major version (8.x); 5.7 and earlier are end-of-life and unpatched (NIST 800-53 Rev5 SI-2 / CM-6); checks the version starts with 8. | Every record must satisfy: Version matches the pattern "^8\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure PostgreSQL Servers Run A Supported Major Version | Verifies Azure PostgreSQL flexible servers run a supported major version (13 or newer); versions 12 and earlier are end-of-life (NIST 800-53 Rev5 SI-2 / CM-6); checks the version major number. | Every record must satisfy: Version matches the pattern "^(1[3-9]|[2-9][0-9])". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure SQL Databases Enable Infrastructure Encryption | NIST SP 800-53 SC-28: protect the confidentiality and integrity of information at rest. Verifies every Azure SQL database has infrastructure (double) encryption enabled. | Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure SQL Databases Located Outside United States Regions | Flags Azure SQL databases located outside United States regions. | A record is marked failed when: Location has a value and Location does not match the pattern "^(eastus|westus|centralus|northcentralus|southcentralus|westcentralus|usgov|usdod|usnat|ussec)|(^| )US( |$|[0-9])|^United States". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure SQL Databases Run a Supported Engine Version | NIST SP 800-53 CM-2 / SI-2: maintain supported, patched software baselines. Verifies every Azure SQL database reports a v12.0 engine generation (the current supported Azure SQL Database version family). | Every record must satisfy: Version contains "v12.0". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Disk Encryption Details
Test name | Test description | Test logic |
Azure Managed Disks Are Encrypted With Customer-Managed Keys | NIST SP 800-53 SC-12 / SC-28(1): manage cryptographic keys under organizational control. Verifies every Azure managed disk uses a customer-managed key, either alone (EncryptionAtRestWithCustomerKey) or alongside the platform key (EncryptionAtRestWithPlatformAndCustomerKeys), rather than only a platform-managed key. | A record is marked failed when: Encryption Type is none of "EncryptionAtRestWithCustomerKey" or "EncryptionAtRestWithPlatformAndCustomerKeys". A record is marked failed when: Encryption Type is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure Managed Disks Report an Encryption Type | NIST SP 800-53 SC-28: protect the confidentiality and integrity of information at rest. Verifies every Azure managed disk reports a configured at-rest encryption type. | Every record must satisfy: Encryption Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure Managed Disks Use a Recognized At-Rest Encryption Type | NIST SP 800-53 SC-28: protect information at rest with approved encryption. Verifies every Azure managed disk reports a recognized server-side encryption type (platform-managed key, customer-managed key, or platform-and-customer key), confirming at-rest encryption is in a known-good configuration. | A record is marked failed when: Encryption Type is none of "EncryptionAtRestWithPlatformKey", "EncryptionAtRestWithCustomerKey" or "EncryptionAtRestWithPlatformAndCustomerKeys". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Disks
Test name | Test description | Test logic |
Azure Managed Disks Are Encrypted At Rest | Verifies every Azure managed disk has server-side encryption at rest enabled (NIST 800-53 Rev5 SC-28); checks the encryptionEnabled flag. | Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Locks
Test name | Test description | Test logic |
Azure Critical Resources Protected By Management Lock | Verifies resources carry a CanNotDelete or ReadOnly management lock to prevent accidental or unauthorized deletion/modification (NIST 800-53 Rev5 CM-3 / CP-9); checks the lock level (Delete / Read only). | A record is marked failed when: Lock Type is none of "Delete" or "Read only". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Network Security Groups
Test name | Test description | Test logic |
Network Security Groups Are Inventoried And Scoped To A Resource Group | Checks that the network security group inventory is not empty and that every group is attributed to the resource group that owns it. | Every record must satisfy: Resource Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Resource Groups
Test name | Test description | Test logic |
Resource Groups Located Outside United States Regions | Flags any resource group whose region falls outside the United States, so workloads placed in unintended geographies are surfaced. | A record is marked failed when: Location has a value and Location does not match the pattern "US|United States". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Resources
Test name | Test description | Test logic |
Retired Azure Classic Deployment Model Resources Are Not In Use | Flags Azure resources still using the retired classic deployment model, which modern access control and policy governance cannot manage. | A record is marked failed when: Resource has a value and Resource Type matches the pattern "^Microsoft\.Classic". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Role Assignments
Test name | Test description | Test logic |
Azure Owner Role Assignments Are Reviewed | Routes Azure RBAC assignments of the built-in Owner role to review as privileged access. | A record is sent for review when: Role equals "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure RBAC Assignments Resolve To A Known Principal | Verifies every Azure role assignment resolves to a known principal type (User, Group, ServicePrincipal, ForeignGroup, or Device) rather than an orphaned/Unknown identity left behind by a deleted account (NIST 800-53 Rev5 AC-2 / AC-3); checks principalType. | A record is marked failed when: Type is none of "User", "Group", "ServicePrincipal", "ForeignGroup" or "Device". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Virtual Machines
Test name | Test description | Test logic |
Azure Virtual Machines Have Secure Boot Enabled | Verifies each Azure VM has Secure Boot enabled to protect against boot-level rootkits and unsigned firmware (NIST 800-53 Rev5 SI-7 / CM-6); checks the secureBootEnabled field. | Every record must satisfy: Secure Boot Enabled equals "Yes". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Virtual Network Gateways
Test name | Test description | Test logic |
Azure VPN Gateways Use Route-Based Connections | Verifies virtual network gateways use the RouteBased VPN type, which supports modern IKEv2/strong ciphers unlike legacy PolicyBased gateways (NIST 800-53 Rev5 SC-7 / SC-8); checks the gateway type. | Every record must satisfy: Type contains "RouteBased". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Log Collection
Test name | Test description | Test logic |
Azure PostgreSQL Server Logs Are Recently Collected | Verifies Azure PostgreSQL server log files were collected within the last 30 days, evidencing that database logging is enabled and current (NIST 800-53 Rev5 AU-2 / AU-4); checks lastModified is not more than 30 days ago. | A record is sent for review when: Last Modified is empty. A record is marked failed when: Last Modified is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Minimum TLS Version
Test name | Test description | Test logic |
Azure MySQL Flexible Servers Enforce TLS 1.2 or Higher | NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for MySQL flexible server sets a minimum TLS version of 1.2 (the tls_version parameter does not permit TLS 1.0 or 1.1). | Every record must satisfy: Minimum TLS Version does not match the pattern "[Tt][Ll][Ss][Vv]?1(\.[01])?(,|$)|[Tt][Ll][Ss]1_[01](,|$)" and Minimum TLS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure PostgreSQL Flexible Servers Require Secure Transport | NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for PostgreSQL flexible server enforces encrypted (TLS) connections by setting require_secure_transport to ON. | Every record must satisfy: Require Secure Transport equals "True". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure PostgreSQL Flexible Servers Set Minimum TLS 1.2 | NIST SP 800-53 SC-8: protect the confidentiality and integrity of transmitted information. Verifies every Azure Database for PostgreSQL flexible server sets ssl_min_protocol_version to TLSv1.2 or TLSv1.3, disallowing the deprecated TLSv1 and TLSv1.1. | A record is marked failed when: Minimum TLS Version is none of "TLSv1.2" or "TLSv1.3". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Recommendations
Test name | Test description | Test logic |
Azure Defender for Cloud Recommendations Are Resolved | NIST SP 800-53 RA-5: monitor and scan for vulnerabilities and remediate findings. Verifies every Microsoft Defender for Cloud recommendation is in a completed (healthy) state. | Every record must satisfy: Status equals "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure DevOps
Deployment Approval Policy
Test name | Test description | Test logic |
Deployment Approval Policy Names Explicit Approvers | Segregation of duties / accountability: verifies the pre-deployment approval policy lists named approvers rather than an empty/automated approver set. Maps to NIST 800-53 Rev5 CM-5 (access restrictions for change) and AC-5, and ISO/IEC 27001:2022 Annex A A.5.3 (segregation of duties) and A.8.32. Checks textField.approvers is populated on the deploymentApprovalPolicy proof. | Every record must satisfy: Approvers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deployment Environment Requires Pre-Deployment Approval | Change control: verifies the release environment's pre-deployment approval gate is enabled (not fully automated). Maps to NIST 800-53 Rev5 CM-3 / CM-5, CMMC 2.0 / NIST 800-171 3.4.5, and ISO/IEC 27001:2022 Annex A A.8.32 (change management). Checks booleanField.enabled on the deploymentApprovalPolicy proof. | Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deployments In An Environment
Test name | Test description | Test logic |
Every Deployment Has A Recorded Approver | Change control evidence: verifies each release deployment carries a recorded approver, so no change reached the environment without approval. Maps to NIST 800-53 Rev5 CM-3 (configuration change control) and SA-11, and ISO/IEC 27001:2022 Annex A A.8.32 (change management). Checks textField.approvedBy is populated on each deployments row. | Every record must satisfy: Approved By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Every Deployment Is Attributable To An Identity | Accountability / audit trail: verifies each deployment records who initiated it so releases are traceable to an individual or trusted automation identity. Maps to NIST 800-53 Rev5 AU-12 and CM-3, CMMC 2.0 / NIST 800-171 3.3.2 (traceability to individual users), and ISO/IEC 27001:2022 Annex A A.8.15 (logging). Checks textField.deployedBy is populated on each deployments row. | Every record must satisfy: Deployed By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
No Organization User Account Is Inactive Beyond 90 Days | Inactive-account review: verifies every member has accessed the organization within the last 90 days, flagging dormant accounts that should be disabled. Maps to NIST 800-53 Rev5 AC-2(3) (disable inactive accounts), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18 (access rights review). Checks dateField.lastAccessed is not more than 90 days ago on each listOfUsers row. | A record is sent for review when: Last Accessed is empty. A record is marked failed when: Last Accessed is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Organization User Accounts Have An Identifiable Email | Account management: verifies every organization member has an email address on file, guarding against shared/anonymous accounts and supporting access recertification. Maps to NIST 800-53 Rev5 AC-2 (account management), CMMC 2.0 / NIST 800-171 3.5.1, and ISO/IEC 27001:2022 Annex A A.5.16 (identity management). Checks textField.email is populated on each listOfUsers row. | Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Members in Permission Group
Test name | Test description | Test logic |
Permission Group Members Are Attributed To A Group | Authorization records: verifies each user surfaced in the permission-group membership proof is attributed to at least one named group, giving auditors a clean least-privilege authorization record. Maps to NIST 800-53 Rev5 AC-2 / AC-6 (least privilege), CMMC 2.0 / NIST 800-171 3.1.5, and ISO/IEC 27001:2022 Annex A A.5.18 (access rights). Checks textField.memberOf is populated on each membersInPermissionGroup row. | Every record must satisfy: Member Of has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Azure Kubernetes Service
List of AKS Clusters
Test name | Test description | Test logic |
AKS API Server Is a Private Cluster | Verifies each AKS cluster is provisioned as a private cluster so the Kubernetes API server endpoint is not exposed to the public internet and is only reachable over the private network. Maps to CIS Kubernetes Benchmark / AKS hardening (restrict API server access), NIST 800-53 Rev5 SC-7 (boundary protection) and AC-17 (remote access), and ISO/IEC 27001:2022 Annex A.8.20 (networks security). Checks clustersList.enablePrivateCluster. | Every record must satisfy: Private cluster is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AKS Cluster Enforces a Network Policy Engine | Verifies each AKS cluster has a Kubernetes network policy engine (azure, calico, or cilium) configured so pod-to-pod traffic is restricted by policy rather than fully open. Maps to CIS Kubernetes Benchmark 5.3.2 (network policies), NIST 800-53 Rev5 SC-7 (boundary protection) / AC-4 (information flow enforcement), and ISO/IEC 27001:2022 Annex A.8.22 (segregation of networks). Checks clustersList.networkPolicy. | A record is marked failed when: Network Policy is none of "azure", "calico" or "cilium". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AKS Runs a Supported Kubernetes Version | Verifies each AKS cluster runs a current, vendor-supported Kubernetes minor version (1.26 or newer) so it continues to receive security patches, rather than an end-of-life version. Maps to NIST 800-53 Rev5 SI-2 (flaw remediation) and CM-8 (system component inventory), NIST 800-171 3.14.1, and ISO/IEC 27001:2022 Annex A.8.8 (management of technical vulnerabilities). Checks clustersList.kubernetesVersion with a regex on the major.minor prefix. | Every record must satisfy: Kubernetes version matches the pattern "^1\.(2[6-9]|[3-9][0-9])\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AKS Uses the Azure CNI Network Plugin | Verifies each AKS cluster uses the Azure CNI network plugin rather than kubenet, giving pods first-class VNet IPs so enterprise network controls (NSGs, route tables, network policy) apply directly to pod traffic. Maps to NIST 800-53 Rev5 CM-6 (configuration settings baseline) and SC-7 (boundary protection), and ISO/IEC 27001:2022 Annex A.8.20 (networks security). Checks clustersList.networkPlugin. | Every record must satisfy: Network type (plugin) equals "azure". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AKS Uses the Standard Load Balancer SKU | Verifies each AKS cluster uses the Standard load balancer SKU rather than the deprecated Basic SKU, which is the baseline required to support API-server authorized IP ranges, availability zones, and outbound rules. Maps to NIST 800-53 Rev5 CM-6 (configuration settings baseline) and CIS/SOC 2 CC7/CC8 (secure configuration). Checks clustersList.loadBalancerSku. | Every record must satisfy: Load balancer equals "standard". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Deployments
Test name | Test description | Test logic |
AKS Workloads Are Not Deployed to the Default Namespace | Verifies each AKS deployment runs in a purpose-named namespace rather than the shared default namespace, enabling namespace-scoped RBAC, network policy, and quota boundaries between workloads. Maps to CIS Kubernetes Benchmark 5.7.4 (the default namespace should not be used), NIST 800-53 Rev5 AC-6 (least privilege) / CM-6 (configuration settings), and NIST 800-171 3.1.5. Checks deploymentsList.namespace. | Every record must satisfy: Namespace does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
AKS Workloads Run With Redundant Replicas | Verifies each AKS deployment has at least two available replicas so a single pod or node failure does not take the workload offline, supporting availability and graceful failover. Maps to NIST 800-53 Rev5 CP-2 (contingency planning) / SC-6 (resource availability) and ISO/IEC 27001:2022 Annex A.8.14 (redundancy of information processing facilities). Checks deploymentsList.availableReplicas. | Every record must satisfy: Available is 2 or more. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Basecamp
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Bitbucket
List of Commits
Test name | Test description | Test logic |
Bitbucket - Commits Are Attributed to an Author | Enforces non-repudiation of code changes per NIST 800-53 Rev5 AU-3/SA-10: every commit must identify its author. Checks the author field. | Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Bitbucket - Commits Include a Change Message | Supports change documentation per NIST 800-53 Rev5 CM-3/SA-10: every commit must include a non-empty message describing the change. Checks the message field. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Pull Requests
Test name | Test description | Test logic |
Bitbucket - Merged Pull Requests Are Documented | Supports change documentation per NIST 800-53 Rev5 CM-3/SA-10: any pull request in the MERGED state must carry a non-empty description. Open or declined pull requests are not required to have one. Checks the state and description fields. | A record is marked failed when: Status equals "MERGED" and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Bitbucket - Pull Requests Are Attributed to an Author | Enforces change accountability and non-repudiation per NIST 800-53 Rev5 CM-3/AU-3: every pull request (change record) must identify its author. | Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Users
Test name | Test description | Test logic |
Bitbucket - Workspace Members Hold a Recognized Permission Level | Verifies configuration baseline for access grants per NIST 800-53 Rev5 CM-6/AC-3: every workspace member's permission field must be one of the approved values owner, collaborator, or member. | A record is marked failed when: Permission is none of "owner", "collaborator" or "member". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Bitbucket - Workspace Owner Access Is Reviewed | Routes Bitbucket workspace members holding owner permission to review as privileged access. | A record is sent for review when: Permission equals "owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Bitbucket Workspace Accounts Inactive Over 90 Days | Flags Bitbucket workspace user accounts that have not been accessed in the last 90 days. | A record is marked failed when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Breezy
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Capsule
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CATS
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Checkmarx CxOne
Create Report
Test name | Test description | Test logic |
Checkmarx One - No Critical or High Severity Findings in Scan Report | Verifies the Checkmarx One scan report contains no software-composition findings at Critical or High severity, evidencing that serious vulnerabilities are remediated. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Testing and Evaluation). Checks the 'severity' field from the Create Report proof. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Severity is none of "Critical" or "High". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Checkmarx One - Report Findings Are Severity-Classified and Categorized | Verifies every finding in the scan report is triaged with a severity and a category, so vulnerabilities can be risk-ranked and routed for remediation. Supports NIST SP 800-53 Rev 5 SA-11 (Developer Testing and Evaluation - flaw tracking) and RA-5 (analysis of scan results). Checks 'severity' and 'category' are non-empty. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Severity has a value and Category has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Checkmarx One - Scan Report Evidence Is Recent | Verifies each finding in the scan report carries a scan date that is present and not more than 90 days old, so the evidence reflects a current scan rather than a stale export. Supports NIST SP 800-53 Rev 5 RA-5 (scan frequency / currency of results). Two conditions per row: 'lastScan' must be non-empty and not older than 90 days. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Last Scan has a value. A record is marked failed when: Last Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List All Projects
Test name | Test description | Test logic |
Checkmarx One - No Projects at High or Critical Risk | Verifies that no project in the Checkmarx One inventory carries a Critical or High overall risk level, evidencing timely remediation of scanner findings. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Testing and Evaluation). Checks the 'riskLevel' field from the List All Projects proof; empty inventory fails because no coverage can be demonstrated. | Every record must satisfy: Risk Level is none of "Critical" or "High". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Checkmarx One - Project Inventory Records Are Complete | Verifies each project record in the scanning inventory identifies a project name and a project id, so the SAST asset inventory is complete and traceable. Supports NIST SP 800-53 Rev 5 CM-8 (System Component Inventory) and SA-11 (scoping of testing). Checks 'projectName' and 'projectId' are non-empty. Empty inventory fails because no assets are enrolled in scanning. | Every record must satisfy: Project Name has a value and Project Id has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Checkmarx One - Projects Scanned Within Last 90 Days | Verifies every project has been scanned recently (lastScanDate is present and not more than 90 days ago), demonstrating an operating scan cadence. Supports NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning - frequency). Two conditions per row: lastScanDate must be non-empty and must not be older than 90 days. Empty inventory fails because scan cadence cannot be demonstrated. | Every record must satisfy: Last Scan has a value. A record is marked failed when: Last Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Checkmarx SCA
List of Projects
Test name | Test description | Test logic |
No High-Severity Open Vulnerabilities In Scanned Projects | Verifies every scanned project's latest SCA risk report shows zero high-severity vulnerabilities, evidencing timely remediation of open findings. Maps to NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring and Scanning) and SA-11 (Developer Security Testing), CMMC 2.0 RA.L2-3.11.2 / SI.L2-3.14.1 (NIST 800-171 3.11.2), and ISO/IEC 27001:2022 A.8.8 (Management of technical vulnerabilities). Checks numberField.highVulnerabilityCount. | Every record must satisfy: High Vulnerabilities equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Scanned Projects Have An Assigned Owning Team | Verifies every scanned project is assigned to at least one team, establishing accountable ownership for remediating vulnerabilities against inventoried components. Maps to NIST 800-53 Rev5 CM-8 (System Component Inventory) and RA-5, and ISO/IEC 27001:2022 A.5.9 (Inventory of information and other associated assets) and A.8.8. Checks textField.assignedTeamNames. | Every record must satisfy: Team has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerability Scans Performed Within Last 30 Days | Verifies each project has a successful SCA scan within the last 30 days so vulnerability posture is monitored at a defined frequency rather than going stale. Maps to NIST 800-53 Rev5 RA-5(2) (Update Frequency) and SA-11, CMMC 2.0 RA.L2-3.11.2 (NIST 800-171 3.11.2), and ISO/IEC 27001:2022 A.8.8 (Management of technical vulnerabilities). Checks numberField.daysSinceLastSuccessfulScan. | Every record must satisfy: Days Since Last Successful Scan is 30 or less. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
No Dormant Active User Accounts | Flags any enabled account that has not logged in for more than 90 days, evidencing timely disabling of dormant credentials. An account fails only when it is active AND its last login is more than 90 days ago. Maps to NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts), CMMC 2.0 AC.L2-3.1.1, ISO/IEC 27001:2022 A.5.18 (Access rights review/removal), CIS Control 5.3 (Disable Dormant Accounts), and SOC 2 CC6.2/CC6.3. Checks booleanField.active and dateField.lastLoginDate. | A record is marked failed when: Active is true and Last Login Date is empty. A record is marked failed when: Active is true and Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Have An Assigned Role | Verifies every Checkmarx SCA account is assigned at least one role, evidencing role-based authorization so no account holds undefined or default access. Maps to NIST 800-53 Rev5 AC-2 (Account Management) and AC-6 (Least Privilege), CMMC 2.0 AC.L2-3.1.5 (NIST 800-171 3.1.5), ISO/IEC 27001:2022 A.5.15/A.5.18 (Access control / Access rights), and SOC 2 CC6.1/CC6.3. Checks textField.roleNames. | Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Clear Books
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Vendor and Customer Master Lists
Test name | Test description | Test logic |
Supplier Master Records Have A Tax Identification Number | Flags supplier records on the vendor master list that have no tax identification number on file. | A record is marked failed when: Entity Type contains "Supplier" and Tax ID is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vendor And Customer Master Records Are Named And Classified | Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified. | Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ClickUp
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Clockwork
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Close
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloudflare
Firewall Rules
Test name | Test description | Test logic |
Cloudflare Firewall Rules Are Documented | NIST SP 800-53 CM-6: configuration settings must be documented so their intent can be reviewed. Verifies every Cloudflare firewall rule includes a description. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloudflare Firewall Rules Are Enabled | NIST SP 800-53 SC-7: boundary protection requires that traffic-filtering rules at the network boundary are actively enforced. Verifies every Cloudflare firewall rule is enabled (not paused). | Every record must satisfy: Disabled is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloudflare Firewall Rules Enforce a Protective Action | NIST SP 800-53 SC-7: boundary protection must deny or challenge unwanted traffic, not merely observe it. Verifies every Cloudflare firewall rule takes a protective action (Block or a challenge) rather than only logging or allowing traffic. | Every record must satisfy: Action matches the pattern "^(Block|.*Challenge)$". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of WAF Managed Rules
Test name | Test description | Test logic |
Cloudflare WAF Managed Rules Are Documented | NIST SP 800-53 CM-6: configuration settings must be documented so their intent can be reviewed. Verifies every Cloudflare WAF managed rule includes a description. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloudflare WAF Managed Rules Are Enabled | NIST SP 800-53 SI-4: system monitoring requires that detection mechanisms are active. Verifies every Cloudflare WAF managed rule is enabled. | Every record must satisfy: Enabled equals "Yes". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloudflare WAF Managed Rules Enforce a Protective Action | NIST SP 800-53 SC-7: boundary protection must mitigate malicious traffic, not merely observe it. Verifies every Cloudflare WAF managed rule takes a protective action rather than only logging matching requests. | Every record must satisfy: Action does not equal "log". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Comeet
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Copper
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cornerstone TalentLink
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Coupa
List of Approvals
Test name | Test description | Test logic |
Coupa Approvals Are Approved With A Named Approver | NIST 800-53 Rev5 AC-6 / segregation-of-duties: approval records in scope must be in the approved state and attributable to a named approver, enforcing authorization accountability. Fields: status (text, raw Coupa value 'approved'), approverName (text). | Every record must satisfy: Status equals "approved" and Approval Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa Approvals Are In A Recognized Workflow State | Verifies every approval record is in one of Coupa's recognized workflow states (pending_approval, approved, rejected, cancelled) via a single OR condition on textField.status, confirming approval-workflow integrity and flagging records in unexpected states (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / CM-3 Configuration Change Control). Uses OR with '=' (never 'in') per the text evaluator. Checks the List of Approvals proof. | A record is marked failed when: Status is none of "pending_approval", "approved", "rejected" or "cancelled". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa Approvals Have A Named Approver | Verifies every approval record identifies the approver by name (textField.approverName non-empty), so each requisition/PO/invoice approval is attributable to an accountable individual (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / AU-2 Event Logging / segregation-of-duties evidence). Checks the List of Approvals proof. | Every record must satisfy: Approval Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Commodities
Test name | Test description | Test logic |
Coupa Commodity Records Carry An Identifier, Name And Creation Date | Confirms every commodity record carries a valid numeric identifier, a name, and a creation date so the spend taxonomy is complete and traceable. | Every record must satisfy: Commodity ID is greater than 0 and Commodity Name has a value and Created At has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Coupa Commodity Taxonomy Contains Only Active Entries | Flags commodities that are marked inactive, surfacing retired entries left enabled in the spend classification taxonomy. | Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Entities
Test name | Test description | Test logic |
Coupa Entities Have A Status And Type | Verifies each business entity (legal/spend hierarchy node) has a non-empty status (textField.status) and type (textField.type), enforcing organizational-structure governance so authorization boundaries and spend scopes are well-defined (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / AC-3). Checks the List of Entities proof. | Every record must satisfy: Status has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Items
Test name | Test description | Test logic |
Coupa Catalog Items Have A Number And Name | Verifies every catalog item has a non-empty item number (textField.itemNumber) and name (textField.name), enforcing catalog integrity so procurement is limited to identified, controlled items rather than untracked spend (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / CM-7 Least Functionality). Checks the List of Items proof. | Every record must satisfy: Item Number has a value and Item Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Risks
Test name | Test description | Test logic |
Coupa Risk Evaluations Are Completed And Rated | NIST 800-53 Rev5 RA-3 risk assessment: supplier/entity risk evaluations in scope must be Completed and carry a final risk rating, so no assessment is left unresolved. Fields: status (text, vlookup display 'Completed'), riskRating (text). | Every record must satisfy: Status equals "Completed" and Risk Rating has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa Supplier Risk Assessments Have A Rating And Score | Verifies each supplier risk assessment has a non-empty final rating (textField.riskRating) and a final score (numberField.riskScore), so third-party risk evaluations reach a scored, ratable conclusion; assessments left without a rating/score fail cleanly via !isEmpty and are surfaced for follow-up (NIST SP 800-53 Rev 5 RA-3 Risk Assessment / SR-6 Supplier Assessments and Reviews). Checks the List of Risks proof. | Every record must satisfy: Risk Rating has a value and Risk Score has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Suppliers
Test name | Test description | Test logic |
Coupa Suppliers Are Active | NIST 800-53 Rev5 SR-6 / PM-30 supply-chain and vendor management: suppliers in scope must be in an active status, so inactive or deprovisioned vendors are not transacting. Fields: status (text, raw Coupa value 'active'). | Every record must satisfy: Status equals "active". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa Suppliers Have A Defined Payment Method | Verifies every supplier has a defined payment method (textField.paymentMethod non-empty). A supplier with no payment method indicates incomplete onboarding and a disbursement-control gap; a blank value fails cleanly via !isEmpty (NIST SP 800-53 Rev 5 AC-3 Access Enforcement / SA-9 External System Services). Checks the List of Suppliers proof. | Every record must satisfy: Payment Method has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Coupa Suppliers Have A Supplier Number | Verifies every supplier record carries a non-empty supplier number (textField.number), enforcing vendor-master integrity so that payments and purchase orders trace to an onboarded, uniquely identified supplier (NIST SP 800-53 Rev 5 CM-8 System Component Inventory / AC-3). Checks the List of Suppliers proof. | Every record must satisfy: Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Coupa Suppliers Use An Approved Payment Method | NIST 800-53 Rev5 SR-6 / financial disbursement controls: every supplier must settle through an approved payment method (Coupa Pay or Invoice), preventing unsanctioned payment channels. Fields: paymentMethod (text, raw Coupa codes 'coupa_pay' / 'invoice'). | A record is marked failed when: Payment Method is none of "coupa_pay" or "invoice". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Coupa Active Users Have Assigned Roles | NIST 800-53 Rev5 AC-2 / AC-6: every active Coupa user account must have at least one role assigned, guarding against privilege-less or orphaned active accounts. Fields: active (boolean), role (text). | A record is marked failed when: Active is true and Role is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa User Accounts Have A Valid Email Identifier | Verifies every Coupa user account carries a non-empty email that contains '@', so each account maps to a real, addressable identity (NIST SP 800-53 Rev 5 AC-2 Account Management / IA-4 Identifier Management). Checks textField.email is present and well-formed on the List of Users proof. | Every record must satisfy: Email has a value and Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Coupa Users Have At Least One Role Assigned | Verifies every Coupa user account has at least one role assigned (textField.role non-empty) so access is provisioned deliberately rather than left undefined, supporting least-privilege and access-review controls (NIST SP 800-53 Rev 5 AC-6 Least Privilege / AC-2 Account Management). Role is the comma-joined list of the user's Coupa roles on the List of Users proof. | Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Crelate
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CrowdStrike
Device Control Policies
Test name | Test description | Test logic |
CrowdStrike Device Control Policies Assigned To Host Groups | Removable media protection enforcement (NIST 800-53 Rev5 MP-7): each device-control policy must be assigned to at least one host group so it actually enforces. Checks textField.groups is not empty. | Every record must satisfy: Groups has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CrowdStrike Device Control Policies Enabled | Removable media / port and I/O device control (NIST 800-53 Rev5 MP-7, SC-41): every USB device-control policy must be enabled. Checks booleanField.enabled isTrue. | Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Endpoint Detections
Test name | Test description | Test logic |
Automated Incident Response Triggering | Confirms that high-severity or critical CrowdStrike endpoint detections automatically trigger incident response procedures. | Every record must satisfy: Vulnerability has a value and Severity has a value and First Detected has a value and Status has a value and Hours to Resolution has a value and Hostname has a value and Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CrowdStrike Detections Are Triaged Within 30 Days | Flags CrowdStrike detections still in the new state more than 30 days after they were raised. | A record is sent for review when: First Detected is empty. A record is marked failed when: Status equals "new" and First Detected is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Detection Host Attribution | Confirms every CrowdStrike endpoint detection is attributed to a named host running a recognized platform so responders can locate and contain the endpoint (NIST 800-53 Rev5 IR-4, CM-8). Fields: hostName, displayName, platformName (mapped from device.platform_name; display values Windows/Mac/Linux). | Every record must satisfy: Hostname has a value and Vulnerability has a value. A record is marked failed when: Platform is none of "Windows", "Mac" or "Linux". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Detection Severity Classified | Ensures every CrowdStrike endpoint detection carries a recognized severity classification and is attributable (host + name + time) to support risk-based incident triage (NIST 800-53 Rev5 IR-4, IR-5, RA-5). Fields: displayName, hostName, detectTime, maxSeverityDisplay (mapped from severity_name; display values Critical/High/Medium/Low/Informational). | Every record must satisfy: Vulnerability has a value and Hostname has a value and First Detected has a value. A record is marked failed when: Severity is none of "Critical", "High", "Medium", "Low" or "Informational". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Endpoint Detection Coverage Verification | Ensures that all endpoints have CrowdStrike sensors actively deployed and monitoring to detect malicious code. | Every record must satisfy: Vulnerability has a value and Severity has a value and Status has a value and Hostname has a value and Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Host Groups
Test name | Test description | Test logic |
CrowdStrike Host Groups Are Documented | Asset inventory grouping (NIST 800-53 Rev5 CM-8): each host group must carry a description so the grouping rationale used to scope protection policies is recorded. Checks textField.description is not empty. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Hosts
Test name | Test description | Test logic |
CrowdStrike Endpoint Sensor Installed On All Hosts | Malicious code protection (NIST 800-53 Rev5 SI-3): verifies every managed host reports a Falcon sensor version so no endpoint is left unprotected. Checks textField.sensorVersion is not empty. | Every record must satisfy: Sensor Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CrowdStrike Hosts Checked In Within 30 Days | Asset inventory currency (NIST 800-53 Rev5 CM-8, AU-6): each host's last check-in (dateField.lastSeen) must be within 30 days so stale or abandoned endpoints are flagged. | A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
CrowdStrike Hosts Not Stuck In Pending Containment | Incident handling (NIST 800-53 Rev5 IR-4): no host may remain in a Containment Pending or Lift Containment Pending state, which indicates a stalled isolation action. Checks textField.status against both pending states. | Every record must satisfy: Containment Status is none of "Containment Pending" or "Lift Containment Pending". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
CrowdStrike Hosts Record An Operating System Baseline | Checks that each CrowdStrike host records its platform and operating system version. | Every record must satisfy: Platform has a value and OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
CrowdStrike Sensor Version Meets Minimum Baseline | Flaw remediation / version currency (NIST 800-53 Rev5 SI-2): the Falcon sensor major version must be 7 or newer so agents stay patched. Regex-matches textField.sensorVersion. | Every record must satisfy: Sensor Version matches the pattern "^(7|8|9|[1-9][0-9]+)\.". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Host Active And Monitored | Confirms each host has a sensor installed and has checked in within the last 30 days so monitoring is current and stale endpoints are surfaced (NIST 800-53 Rev5 SI-4, CM-8). Fields: sensorVersion (textField.sensorVersion), lastSeen (dateField.lastSeen, mapped from last_seen). | A record is sent for review when: Last Seen is empty. Every record must satisfy: Sensor Version has a value. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Host Sensor Deployed | Verifies every CrowdStrike-managed host reports an installed sensor agent version, evidencing endpoint protection coverage (NIST 800-53 Rev5 SI-3, CM-8). Fields: hostName (textField.hostName), sensorVersion (textField.sensorVersion, mapped from agent_version). | Every record must satisfy: Hostname has a value and Sensor Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
CrowdStrike Console Users Have Assigned Roles | Account management / least privilege (NIST 800-53 Rev5 AC-2, AC-6): every Falcon console user must have at least one explicitly assigned role. Checks textField.roles is not empty. | Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prevention Policies
Test name | Test description | Test logic |
Malicious Code Prevention Policy Enforcement | Ensures CrowdStrike prevention policies are enabled and actively enforced to prevent execution of malicious code across all applicable endpoints. Assessment Procedures: | Every record must satisfy: Enabled is true and Created On has a value. The test passes if at least 80% of records pass. If the proof contains no records, the test is marked failed. |
Prevention Policy Assigned To Host Groups | Confirms enabled CrowdStrike prevention policies are assigned to at least one host group so protection is actually enforced (NIST 800-53 Rev5 SI-3, CM-6). Fields: enabled (booleanField.enabled), groups (textField.groups). | Every record must satisfy: Enabled is true and Groups has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Prevention Policy Enabled With Settings | Verifies each CrowdStrike prevention policy is enabled and has at least one prevention setting configured (NIST 800-53 Rev5 SI-3). Fields: enabled (booleanField.enabled), details (textField.details), name (textField.name). | Every record must satisfy: Enabled is true and Policy Details has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Sensor Update Policies
Test name | Test description | Test logic |
Sensor Policy Version Pinned And Protected | Confirms enabled CrowdStrike sensor update policies pin an approved sensor version and do not disable uninstall protection (NIST 800-53 Rev5 SI-2, SI-3, CM-2). Fields: enabled (booleanField.enabled), sensor_version (textField.sensor_version), uninstall_protection (textField.uninstall_protection) whose disabled display value is Disabled. | Every record must satisfy: Enabled is true and Sensor Version has a value and Uninstall Protection does not equal "Disabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Sensor Uninstall Protection Enabled | Ensures enabled CrowdStrike sensor update policies enforce uninstall (tamper) protection so the agent cannot be removed by an attacker (NIST 800-53 Rev5 SI-3, SI-7, CM-5). Fields: enabled (booleanField.enabled), uninstall_protection (textField.uninstall_protection) which vlookups to the display value Enabled. | Every record must satisfy: Enabled is true and Uninstall Protection equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Sensor Update Policies | Verifies that CrowdStrike sensors installed on endpoints match the organization's approved sensor version and that sensor policies are actively enabled with uninstall protection enforced. | Every record must satisfy: Name has a value and Platform has a value and Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Datadog
Alert Configurations
Test name | Test description | Test logic |
Datadog Monitors Have Critical and Warning Alert Thresholds | Verifies each Datadog monitor defines both a warning and a critical alerting threshold so operators get graduated notification before a failure. Supports NIST 800-53 Rev5 SI-4(5) / AU-5 by checking the criticalThreshold and warningThreshold fields are populated. | Every record must satisfy: Critical Threshold has a value and Warning Threshold has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Active Users
Test name | Test description | Test logic |
Datadog Active Users Have Recorded Name and Email | Verifies every active Datadog account records both a name and an email so each account is attributable to a real identity for account management. Supports NIST 800-53 Rev5 AC-2 by checking the users' name and email fields are populated. | Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Hosts
Test name | Test description | Test logic |
Datadog Hosts Are Actively Reporting (Agent Up) | Verifies every host in the Datadog inventory has an ACTIVE status, confirming its monitoring agent is up and telemetry is flowing. Supports NIST 800-53 Rev5 SI-4 / CM-8 by checking the hosts' status field. | Every record must satisfy: Status equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Datadog Hosts Have a Recorded OS Platform | Verifies every host in the Datadog inventory records its OS platform, ensuring the asset inventory is complete enough to map hosts to configuration baselines. Supports NIST 800-53 Rev5 CM-8 by checking the hosts' platform field is populated. | Every record must satisfy: Platform has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Incidents
Test name | Test description | Test logic |
Datadog Incidents Are Resolved or Completed | Verifies each Datadog incident has reached a closed state (Resolved or Completed) rather than lingering Active/Stable, evidencing incident closure. Supports NIST 800-53 Rev5 IR-4 / IR-5 by checking the incidents' state field. | A record is marked failed when: State is none of "Resolved" or "Completed". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Datadog Incidents Have a Triaged Severity | Fails any Datadog incident whose severity is still UNKNOWN, confirming each incident was triaged and assigned a severity for prioritized response. Supports NIST 800-53 Rev5 IR-4 by checking the incidents' severity field. | Every record must satisfy: Severity does not equal "UNKNOWN". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Monitors
Test name | Test description | Test logic |
Datadog Monitors Are Actively Evaluating (No Data Gaps) | Fails any Datadog monitor in a 'No Data' state, which indicates the monitor is no longer receiving telemetry and monitoring coverage has silently broken. Supports NIST 800-53 Rev5 SI-4 / AU-6 by checking the monitors' status field. | Every record must satisfy: Status does not equal "No Data". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Datadog Monitors Have a Defined Alert Priority | Verifies every Datadog monitor has an assigned priority (not 'Not Defined') so alerts are ranked and routed for response. Supports NIST 800-53 Rev5 SI-4 / AU-6 by checking the monitors' priority field. | Every record must satisfy: Priority does not equal "Not Defined". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Dixa
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Elastic Cloud
Deployment Instances
Test name | Test description | Test logic |
Elastic Cloud Deployment Instances Have Availability Zone Assigned | Verifies every Elastic Cloud deployment instance is placed in a named availability zone (zone is not empty), evidence of a resilient multi-zone topology baseline. Supports NIST SP 800-53 Rev 5 CP-2 (Contingency Planning) and CM-6 (Configuration Settings). Checks the 'zone' field emitted by the deploymentInstances proof. | Every record must satisfy: Zone has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Deployments
Test name | Test description | Test logic |
Elastic Cloud Deployment Inventory Is Complete | Verifies each inventoried Elastic Cloud deployment record carries an identifying name and a resource kind (both non-empty), so the deployment inventory is complete and attributable. Supports NIST SP 800-53 Rev 5 CM-8 (System Component Inventory). Checks the 'name' and 'kind' fields emitted by the deployments proof. | Every record must satisfy: Name has a value and Applications has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elastic Cloud Deployment Inventory Record Is Complete | Confirms each deployment record carries a well-formed unique identifier and a name so it can be tracked in the system component inventory. | Every record must satisfy: Id has a value and Id matches the pattern "^[0-9a-fA-F]{32}$" and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Elastic Cloud Deployments Reside In US Regions | Verifies every Elastic Cloud deployment is hosted in a US cloud region (region name has a 'us-' segment at the start or after a provider prefix, e.g. us-east-1, aws-us-east-1, gcp-us-central1). Enforces data residency / data-location boundary requirements per NIST SP 800-53 Rev 5 SA-9 (External System Services) and AC-4 (Information Flow Enforcement). Uses a JS+.NET-compatible regex (no inline flags). Checks the 'region' field emitted by the deployments proof. | Every record must satisfy: Region matches the pattern "(^|-)us-". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Elastic Cloud Users Have An Organization Role Assigned | Verifies every Elastic Cloud organization user has at least one explicit role assignment (role is not empty), so no account has undefined or orphaned access. Supports least-privilege access governance per NIST SP 800-53 Rev 5 AC-2 (Account Management) and AC-6 (Least Privilege). Checks the 'role' field emitted by the userList proof. | Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elasticsearch
List of Users
Test name | Test description | Test logic |
Elasticsearch Accounts Are Active | Account lifecycle management: verifies each listed account is enabled (active), supporting review that no disabled or dormant account is unexpectedly retained with access. NIST 800-53 Rev5 AC-2, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.16. Field checked: enabled. | Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elasticsearch Accounts Do Not Hold The Superuser Role | Restrict privileged access: flags accounts granted the built-in superuser role, which confers unrestricted cluster-wide privileges, so privileged access can be justified and minimized. NIST 800-53 Rev5 AC-6(5), NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2. Field checked: roles. | Every record must satisfy: Roles does not contain "superuser". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elasticsearch Accounts Do Not Use Generic Or Shared Names | Unique identification / no shared accounts: flags accounts whose username is a generic or shared identifier (admin, root, test, guest, shared, service) so each account maps to a single accountable identity. NIST 800-53 Rev5 IA-4 and AC-2, NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16. Field checked: username. Case-explicit anchored regex, no inline flags. | Every record must satisfy: User Name is none of "admin", "root", "test", "guest", "shared" or "service" (ignoring case). The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elasticsearch Accounts Have A Contact Email | Accountability / traceability of accounts to an individual: verifies each account records a contact email so ownership and communication for access reviews and incident response are possible. NIST 800-53 Rev5 AC-2 and IA-2, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.16. Field checked: email. | Every record must satisfy: Email Address has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Elasticsearch Accounts Have An Assigned Role | Least-privilege authorization: verifies every Elasticsearch account has at least one security role assigned (roles field not empty) so access is granted only through defined roles. NIST 800-53 Rev5 AC-6, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2, SOC 2 CC6.3. Field checked: roles. | Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
EngageATS
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Eploy
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Fountain
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
FreeAgent
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
FreshBooks
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Vendor and Customer Master Lists
Test name | Test description | Test logic |
Supplier Master Records Have A Tax Identification Number | Flags supplier records on the vendor master list that have no tax identification number on file. | A record is marked failed when: Entity Type contains "Supplier" and Tax ID is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vendor And Customer Master Records Are Named And Classified | Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified. | Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Freshdesk
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Freshservice
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Front
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Gem
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitHub
Branch Protection
Test name | Test description | Test logic |
GitHub Branch Protection Enabled | Confirms every monitored branch has a branch protection rule in effect (protectionEnabled=true). Unprotected branches allow direct pushes and force-pushes that bypass change control. Supports NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and SI-10 (Information Input Validation) / FedRAMP 20x. Field checked: booleanField.protectionEnabled. | Every record must satisfy: Branch Protection Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitHub Enforce Branch Protection For Administrators | Verifies branch protection rules also apply to repository administrators (enforceAdmins=true) so privileged users cannot bypass required reviews and status checks. Closes the common least-privilege gap where admins push directly to protected branches. Supports NIST SP 800-53 Rev 5 AC-6(1) (Authorize Access to Security Functions), CM-5 (Access Restrictions for Change), and CM-3. Field checked: booleanField.enforceAdmins. | Every record must satisfy: Include administrators is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitHub Require Code Owner Review And Dismiss Stale Approvals | Verifies protected branches require review from designated code owners and automatically dismiss stale approvals when new commits are pushed (requireCodeOwnerReview=true AND dismissStaleReviews=true). Prevents merging unreviewed changes slipped in after approval. Supports NIST SP 800-53 Rev 5 AC-5 (Separation of Duties), CM-3 (Configuration Change Control), and SA-11. Fields checked: booleanField.requireCodeOwnerReview, booleanField.dismissStaleReviews. | Every record must satisfy: Require review from Code Owners is true and Dismiss Stale Reviews is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitHub Require Pull Request Reviews Before Merging | Verifies each protected branch requires a pull request review with at least one approving reviewer before merge (requireReview=true AND requireApprovals>=1). Enforces peer review / separation of duties on code changes. Supports NIST SP 800-53 Rev 5 AC-5 (Separation of Duties), SA-11 (Developer Testing and Evaluation), and CM-3. Fields checked: booleanField.requireReview, numberField.requireApprovals. | Every record must satisfy: Require a pull request before merging is true and Required number of approvals is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitHub Require Status Checks Before Merging | Verifies protected branches require status checks (CI build, tests, security scans) to pass before a pull request can be merged (requiresStatusChecks=true). Prevents merging code that fails automated integrity and security gates. Supports NIST SP 800-53 Rev 5 SI-7 (Software, Firmware, and Information Integrity), SA-11 (Developer Testing and Evaluation), and CM-3. Field checked: booleanField.requiresStatusChecks. | Every record must satisfy: Require status checks to pass before merging is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
External Repository Members
Test name | Test description | Test logic |
GitHub External Collaborators Read Only Access | Enforces least privilege for outside (external) repository collaborators: each must be limited to read-level access (permissions is 'Read' or 'Triage'), never Write/Maintain/Admin. The connector emits the display permission value, so operands match the rendered labels. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege), AC-3 (Access Enforcement), and AC-2 (Account Management). Field checked: textField.permissions. | Every record must satisfy: Permissions has a value. A record is marked failed when: Permissions is none of "Read" or "Triage". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Issues
Test name | Test description | Test logic |
Open Issues Are Remediated Within 90 Days | Fails when an issue is still open more than 90 days after it was created, evidencing that tracked remediation items are closed within the expected window. | A record is sent for review when: Created is empty. A record is marked failed when: State equals "Open" and Created is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Open Issues Have An Assigned Owner | Fails when an open issue has no assignee, so every in-flight tracked item has a named person accountable for closing it. | A record is marked failed when: State equals "Open" and Assignee is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Member Repository Access
Test name | Test description | Test logic |
GitHub Restrict Member Repository Admin Access | Enforces least privilege on a monitored member's repository access: the member must not hold admin permission on any repository (permissions != 'admin'). GitHub's collaborator permission API returns lowercase values (admin/maintain/write/triage/read/none). Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and AC-6(1). Field checked: textField.permissions. | Every record must satisfy: Permissions does not equal "admin". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Organization Members
Test name | Test description | Test logic |
Check Deprovisioned Accounts | Validate that GitHub accounts are deprovisioned when personnel leave the organization. | Every record must satisfy: Username has a value and Name has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Validate Organization Member Roles | Verify that organization members have appropriate roles assigned. | Every record must satisfy: Username has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Repository Admins
Test name | Test description | Test logic |
Validate Repository Admin Authorization | Confirm that only authorized personnel have administrative rights to repositories. | Every record must satisfy: Repository has a value and Access has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Repository Workflows
Test name | Test description | Test logic |
GitHub Actions Workflows Active | Verifies each CI/CD GitHub Actions workflow is in the 'active' state (not disabled_manually or disabled_inactivity). Disabled security or build workflows silently stop enforcing automated tests, scans, and gates. The connector emits GitHub's lowercase workflow state value. Supports NIST SP 800-53 Rev 5 CM-6 (Configuration Settings), SI-7 (Software, Firmware, and Information Integrity), and SI-4. Field checked: textField.state. | Every record must satisfy: State equals "active". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Team Members
Test name | Test description | Test logic |
Team Maintainer Privileges Are Reviewed | Surfaces every team member holding maintainer privileges so the reviewer can confirm each elevated role is still justified. | A record is sent for review when: Role equals "Maintainer". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab
Branch Protection
Test name | Test description | Test logic |
GitLab Branch Protection Enabled | Verifies that every branch-protection rule returned for the repository actually has protection enabled. Missing or disabled protection on default/release branches allows unreviewed changes. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and AC-3 (Access Enforcement). Checks booleanField.protectionEnabled from the GitLab Branch Protection proof. | Every record must satisfy: Branch Protection Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitLab Protected Branch Force Push Disabled | Verifies that force push is not allowed on any protected branch. Force push can rewrite history and bypass the reviewed commit trail, undermining change integrity. Maps to NIST SP 800-53 Rev 5 CM-5 (Access Restrictions for Change) and SI-7 (Software, Firmware, and Information Integrity). Checks booleanField.allowForcePush from the GitLab Branch Protection proof. | Every record must satisfy: Allow force push is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitLab Protected Branch Push Access Restricted | Verifies that direct push to protected branches is not open to everyone. The connector emits the display string 'All' for the allowed-to-push level only when the branch is unprotected/unrestricted; a restricted branch reports a role list (e.g. 'Maintainers'). Enforces least privilege for change promotion. Maps to NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and CM-5 (Access Restrictions for Change). Checks textField.allowedToPush from the GitLab Branch Protection proof. | Every record must satisfy: Allowed to Push does not equal "All" and Allowed to Push does not contain "Developers". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Commits
Test name | Test description | Test logic |
GitLab Commits Are Attributed To An Author | Checks that every GitLab commit records an author name. | Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Members
Test name | Test description | Test logic |
GitLab Project Members Least Privilege | Access-review control: verifies no member on the reviewed group/project list holds the Owner role, which grants full administrative control (member management, deletion, protected-branch bypass). Owner assignments should be tightly scoped and reviewed. The connector maps GitLab access level 50 to the display string 'Owner' in maxRole. Maps to NIST SP 800-53 Rev 5 AC-6 (Least Privilege), AC-6(5) (Privileged Accounts) and AC-2 (Account Management). Checks textField.maxRole from the GitLab Members proof. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Max Role does not equal "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Merge Request Settings
Test name | Test description | Test logic |
GitLab MR Approvals Reset On New Commits | Verifies the project requires new merge-request approvals when new commits are pushed after approval. Without this, an approved MR can be silently altered before merge, defeating change review. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and CM-5 (Access Restrictions for Change). Checks booleanField.approvalsOnPush from the GitLab Merge Request Settings proof. | Every record must satisfy: Require new approvals when new commits are added to an MR is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
GitLab MR Self Approval Prevented | Verifies separation of duties on merge-request approvals: the author cannot approve their own MR and users who committed to the MR cannot approve it. Enforces independent review of code changes. Maps to NIST SP 800-53 Rev 5 AC-5 (Separation of Duties) and CM-3 (Configuration Change Control). Checks booleanField.authorApproval (true = author approval prevented) and booleanField.disableCommittersApproval from the GitLab Merge Request Settings proof. | Every record must satisfy: Prevent MR approvals by the author is true and Prevent MR approvals from users who make commits to the MR is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Merge Requests
Test name | Test description | Test logic |
GitLab Merged Requests Peer Approved | Verifies that every merge request merged into the target branch during the period carries at least one recorded approver. The connector emits the display string 'Approvers not available' when an MR was merged with no approval. Provides evidence of change review. Maps to NIST SP 800-53 Rev 5 CM-3 (Configuration Change Control) and AC-5 (Separation of Duties). Checks textField.approvedBy from the GitLab Merge Requests proof. Empty proof (no merges in period) is routed to Needs Review for human confirmation. | Every record must satisfy: Approved By has a value and Approved By does not equal "Approvers not available". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab Merged Requests Record Merger | Verifies that every merged merge request records the user who performed the merge, establishing accountability and a complete change-approval audit trail. The connector emits an empty string for mergedBy when no merger is recorded. Maps to NIST SP 800-53 Rev 5 AU-2 (Event Logging), AU-3 (Content of Audit Records) and CM-3 (Configuration Change Control). Checks textField.mergedBy from the GitLab Merge Requests proof. Empty proof (no merges in period) is routed to Needs Review. | Every record must satisfy: Merged By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab Self-Managed
Commits
Test name | Test description | Test logic |
GitLab Commits Record Author Attribution | Change traceability / audit record generation: every commit in the branch history records an author name, supporting accountability and non-repudiation for code changes (NIST 800-53 Rev5 AU-3 / CM-3, ISO/IEC 27001:2022 A.8.15, CIS Control 8). Checks textField.authorName is not empty on the commitHistory proof. | Every record must satisfy: Author has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Members
Test name | Test description | Test logic |
GitLab Members Have Identifiable Email On Record | Account accountability / unique identification: each member account maps to a known email rather than the emitted placeholder 'N/A', so every access grant is attributable to an identifiable person (NIST 800-53 Rev5 AC-2 / IA-4, NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16). Checks textField.email is not empty and not 'N/A' on the listMembers proof. | Every record must satisfy: Email has a value and Email does not equal "N/A". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab Members Have Time-Bound Access Expiration | Access provisioning lifecycle: every group/project membership carries an expiration date so access is time-bound and forced through periodic re-certification (NIST 800-53 Rev5 AC-2(3), NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.18). Checks dateField.expiration is not empty on the listMembers proof. | Every record must satisfy: Access expires has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab Members Not Granted Owner Access | Least privilege / restriction of privileged access: no group or project member holds the Owner role, which grants full administrative control over the namespace (NIST 800-53 Rev5 AC-6(5), NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.8.2). Checks textField.maxRole is not the emitted label 'Owner' on the listMembers proof. | Every record must satisfy: Max Role does not equal "Owner". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Merge Requests
Test name | Test description | Test logic |
GitLab Merged Requests Have Documented Approvers | Change control / peer review and segregation of duties: every merged request records at least one approver instead of the emitted placeholder 'Approvers not available', evidencing that code changes were independently reviewed before merge (NIST 800-53 Rev5 CM-3 / SA-11, ISO/IEC 27001:2022 A.8.32, SOC 2 CC8.1). Checks textField.approvedBy is not empty and not 'Approvers not available' on the mergeRequests proof. | Every record must satisfy: Approved By has a value and Approved By does not equal "Approvers not available". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GitLab Merged Requests Record The Merging User | Change accountability: every merged request records the user who performed the merge, ensuring traceability of who introduced changes into the target branch (NIST 800-53 Rev5 CM-5 / AU-3, ISO/IEC 27001:2022 A.8.32). Checks textField.mergedBy is not empty on the mergeRequests proof. | Every record must satisfy: Merged By has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Gladly
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Cloud Platform
Cloud Storage: Bucket Encryption
Test name | Test description | Test logic |
GCP Cloud Storage Buckets Use Customer-Managed Encryption Keys | Verifies every Cloud Storage bucket is encrypted with a customer-managed key (CMEK) rather than the default Google-managed key. The connector emits encryptionType as the display value 'Customer-managed key' or 'Google-managed key'; test asserts textField.encryptionType = 'Customer-managed key'. Supports NIST SP 800-53 Rev 5 SC-12 / SC-28 (key management, protection at rest) and CIS GCP 3.7. Field checked: encryptionType. | Every record must satisfy: Encryption Type equals "Customer-managed key". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Cloud Storage: Bucket Lifecycle Rules
Test name | Test description | Test logic |
Bucket Age-Based Lifecycle Delete Rules Retain Objects For At Least 30 Days | Flags storage lifecycle rules that permanently delete objects less than 30 days old, so data is not purged before its retention window elapses. | A record is marked failed when: Action contains "Delete" and Age is less than 30. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Bucket Lifecycle Rules Specify A Recognized Lifecycle Action | Checks that every storage bucket in scope has at least one lifecycle rule and that each rule names a recognized delete, storage-class transition, or abort-upload action. | Every record must satisfy: Bucket has a value and Action has a value and Action matches the pattern "(Delete|Set Storage Class|Abort Incomplete Multipart Upload)". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloud Storage: Bucket Replication
Test name | Test description | Test logic |
Google Cloud Storage Buckets Use A Geo-Redundant Location Type | Checks that each Cloud Storage bucket is placed in a dual-region or multi-region location so object data is replicated across separate sites. | Every record must satisfy: Location Type has a value and Bucket Name has a value and Location has a value and Location Type does not equal "region". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloud Storage: Bucket Retention Settings
Test name | Test description | Test logic |
Google Cloud Storage Buckets Enforce A Locked Retention Policy | Checks that each Cloud Storage bucket has a retention policy in place and that the policy is locked so objects cannot be deleted early. | Every record must satisfy: Bucket Name has a value and Retention Period does not equal "No Policy" and Effective Time has a value and Locked is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Cloud Storage: Bucket Settings
Test name | Test description | Test logic |
GCP Cloud Storage Bucket Hardening Baseline | Baseline configuration check across every Cloud Storage bucket: object versioning enabled (textField.versioning = 'Enabled') AND customer-managed encryption (textField.encryptionType = 'Customer-managed key'). Both roll up as fail-fast AND per bucket. Supports NIST SP 800-53 Rev 5 CM-6 (configuration settings), SC-28 (protection at rest), CP-9 (backup) and CIS GCP 3.x storage hardening. Fields checked: versioning, encryptionType. | Every record must satisfy: Versioning equals "Enabled". Every record must satisfy: Encryption Type equals "Customer-managed key". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Cloud Storage: Bucket Versioning
Test name | Test description | Test logic |
GCP Cloud Storage Object Versioning Enabled | Verifies object versioning is enabled on every Cloud Storage bucket so overwritten or deleted objects can be recovered. The connector emits versioning as the display value 'Enabled' or 'Disabled'; test asserts textField.versioning = 'Enabled'. Supports NIST SP 800-53 Rev 5 CP-9 (backup) / SI-12 (information handling and retention) and data-protection hardening. Field checked: versioning. | Every record must satisfy: Versioning equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Compute Engine: Firewall Rules
Test name | Test description | Test logic |
GCP VPC Firewall Rule Logging Enabled | Verifies Firewall Rules Logging is enabled on every VPC firewall rule (booleanField.logConfig isTrue) so allowed/denied connections are auditable. Supports NIST SP 800-53 Rev 5 AU-2 / AU-12 (audit events, audit record generation) and CIS GCP 3.9. Field checked: logConfig (log configuration enable flag). Note: rules with no log configuration emit an empty logConfig, which correctly fails isTrue at threshold 1.0. | Every record must satisfy: Log Config is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Compute Engine: List of Disk Encryption Settings
Test name | Test description | Test logic |
GCP Compute Disks Use Customer-Managed Encryption Keys | Verifies every Compute Engine persistent disk is encrypted with a customer-supplied or customer-managed key (booleanField.isCustomerManaged isTrue) instead of relying solely on Google default encryption. Supports NIST SP 800-53 Rev 5 SC-12 / SC-28 (key management, protection at rest) and CIS GCP 4.7. Field checked: isCustomerManaged. | Every record must satisfy: Customer-managed key is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Compute Engine: List of Images
Test name | Test description | Test logic |
Google Cloud Custom Images Carry Inventory Labels And A Storage Location | Confirms every Compute Engine custom image carries inventory labels and a recorded storage location, so it can be attributed to an owner and purpose and located. Machine images are a separate resource and are not covered. | Every record must satisfy: Name has a value and Location has a value and Labels has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Cloud Custom Images Rebuilt Within The Last Year | Confirms every Compute Engine custom image in the project was rebuilt within the last year, so images do not drift far behind current patches. Machine images are a separate resource and are not covered. | A record is sent for review when: Creation Time is empty. A record is marked failed when: Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Compute Engine: List of Instance Groups
Test name | Test description | Test logic |
Managed Instance Groups Deploy From An Instance Template | Checks that every managed instance group is backed by an instance template so all of its replicas launch from a governed baseline configuration. | A record is sent for review when: Template is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Managed Instance Groups Have Autoscaling Enabled | Confirms each managed instance group has an autoscaler attached so capacity adjusts to demand instead of remaining at a fixed size. | Every record must satisfy: Name has a value and Autoscaling is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Compute Engine: List of Instance Templates
Test name | Test description | Test logic |
Instance Templates Are Refreshed Within The Last Year | Surfaces virtual machine templates created more than a year ago, which still pin their original base image because templates cannot be edited after creation. | A record is sent for review when: Creation Time is empty. A record is sent for review when: Creation Time has a value and Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Instance Templates Do Not Reference End Of Life Operating System Images | Flags virtual machine templates whose boot image is a Linux or Windows release that has reached end of life and no longer receives vendor security patches. | Every record must satisfy: Image has a value and Image does not match the pattern "(debian-(8|9|10)|ubuntu-(1204|1404|1604|1804)|centos-(6|7|8)|centos-stream-8|rhel-(6|7)|windows-(server-)?(2008|2012))". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Compute Engine: List of Snapshots
Test name | Test description | Test logic |
GCP Snapshots Are Stored In United States Locations | Checks that every disk snapshot reports a United States storage location and flags any stored elsewhere or with no location reported. | A record is marked failed when: Location has a value and Location does not match the pattern "^us(-|$)". A record is sent for review when: Location is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GCP Snapshots Older Than One Year Are Reviewed For Retention | Surfaces disk snapshots created more than a year ago so they can be checked against your backup retention policy. | A record is sent for review when: Creation Time is empty. A record is sent for review when: Creation Time is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Compute Engine: Minimum TLS Version
Test name | Test description | Test logic |
GCP SSL Policies Enforce TLS 1.2 Minimum | Verifies every Compute SSL policy enforces a minimum TLS version of at least 1.2 (textField.minTlsVersion is one of 'TLS_1_2' or 'TLS_1_3', matched via a single OR condition with '=' arguments — never the illegal 'in' operator on text). Supports NIST SP 800-53 Rev 5 SC-8 / SC-23 (transmission confidentiality, session authenticity) and CIS GCP TLS hardening. Field checked: minTlsVersion (raw GCP enum e.g. TLS_1_0/TLS_1_1/TLS_1_2). | A record is marked failed when: Minimum TLS version is none of "TLS_1_2" or "TLS_1_3". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
IAM: Custom Project Roles
Test name | Test description | Test logic |
Google Cloud Custom Project Roles Are Documented | Flags custom project roles that are missing a title or a description, so every custom role can be reviewed for appropriate privilege. | A record is marked failed when: Description is empty. A record is marked failed when: Title is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kubernetes Engine: List of Pod Security Policies
Test name | Test description | Test logic |
GKE Pods Declare A Pod-Level Security Context | Surfaces Kubernetes pods that declare no pod-level user or non-root setting, so their runtime privilege level can be reviewed. | A record is sent for review when: Run As Non Root is empty and Run As User is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GKE Pods Do Not Run As The Root User Or Group | Flags Kubernetes pods whose pod-level security context explicitly requests root: non-root disabled, user ID 0, or group ID 0. | A record is marked failed when: Run As Non Root is false. A record is marked failed when: Run As User equals 0. A record is marked failed when: Run As Group equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kubernetes Engine: List of Workloads
Test name | Test description | Test logic |
GKE Workloads Are Not Deployed To The Default Namespace | Flags Kubernetes deployments running in the default namespace instead of a purpose-built namespace. | A record is marked failed when: Namespace equals "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GKE Workloads Report Available Pods And A Healthy Condition | Flags Kubernetes deployments that have no available pods, or whose most recent status condition is not healthy. | A record is marked failed when: Pods matches the pattern "^0/[1-9]". A record is marked failed when: Status has a value and Status does not equal "OK". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SQL: Backup Configuration
Test name | Test description | Test logic |
GCP Cloud SQL Automated Backups Enabled | Verifies every Cloud SQL instance has automated backups enabled (booleanField.enabled isTrue). Supports contingency planning / backup requirements: NIST SP 800-53 Rev 5 CP-9 (System Backup) and CIS GCP Foundations 6.7. Field checked: enabled (Backup Enabled). | Every record must satisfy: Backup Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GCP Cloud SQL Point-in-Time Recovery And Backup Retention | Verifies each Cloud SQL instance enables point-in-time recovery (booleanField.pointInTimeRecoveryEnabled isTrue) and retains at least 7 automated backups (numberField.retainedBackups >= 7). Both conditions roll up as fail-fast AND per instance. Supports NIST SP 800-53 Rev 5 CP-9 / CP-10 (recovery) and CIS GCP 6.7. Fields checked: pointInTimeRecoveryEnabled, retainedBackups. | Every record must satisfy: Point In Time Recovery is true. Every record must satisfy: Retained Backups is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SQL: Backup Runs
Test name | Test description | Test logic |
GCP Cloud SQL Backup Runs Completed Successfully | Verifies every recorded Cloud SQL backup run completed successfully (textField.status = 'SUCCESSFUL', the GCP backup-run status enum) so backup evidence is proven, not just configured. Supports NIST SP 800-53 Rev 5 CP-9 (System Backup) / CP-10 (recovery) and CIS GCP 6.7. Field checked: status (raw GCP enum e.g. SUCCESSFUL/FAILED/SKIPPED). | Every record must satisfy: Status equals "SUCCESSFUL". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
VPC: List of Networks
Test name | Test description | Test logic |
Default VPC Network Is Not Present | Checks that the automatically created default virtual network has been removed from each project so workloads run only on deliberately designed networks. | Every record must satisfy: ID has a value and Name does not equal "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
VPC Networks Use Custom Subnet Mode | Verifies each virtual network is in custom subnet mode rather than automatically creating a subnet in every region with predetermined address ranges. | Every record must satisfy: Name has a value and Mode equals "Custom". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
VPC: List of Subnets
Test name | Test description | Test logic |
GCP Subnets Do Not Belong To The Default VPC Network | Flags VPC subnets that belong to the auto-created default network rather than a purpose-built VPC. | A record is marked failed when: Network equals "default". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
GCP Subnets Use Private IPv4 Address Space | Flags VPC subnets whose IPv4 range falls outside private (RFC 1918 / RFC 6598) address space. | A record is marked failed when: IPv4 CIDR has a value and IPv4 CIDR does not match the pattern "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|100\.(6[4-9]|[7-9][0-9]|1[01][0-9]|12[0-7])\.)". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Google Workspace
Admin Audit Log
Test name | Test description | Test logic |
Google Workspace - Admin Audit Log Freshness (30-Day) | Verifies that the Google Workspace administrative audit log is being collected and is current within the last 30 days. Supports NIST SP 800-53 Rev. 5 AU-2 and AU-6 and FedRAMP 20x KSI-MLA-RVL and KSI-CMT-LMC. | A record is sent for review when: Date is empty. A record is marked failed when: Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Group Membership
Test name | Test description | Test logic |
Groups Do Not Grant Whole-Domain Membership | Flags groups that grant membership to the entire organization instead of to named users or groups. | A record is marked failed when: Type equals "CUSTOMER". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Chrome Devices
Test name | Test description | Test logic |
Enrolled Chrome Devices Record User And Serial Number | Checks that every enrolled Chrome device records an assigned user and a serial number. | Every record must satisfy: User has a value and Serial Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Workspace Chrome Devices Record An Operating System Version | Checks that each enrolled Chrome device records its operating system version. | Every record must satisfy: OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Groups
Test name | Test description | Test logic |
Google Workspace Groups Do Not Permit Domain-Wide Open Access | Checks that no Google Workspace group is configured so that anyone in the domain can join it, view its membership, and post to it. | Every record must satisfy: Access Type has a value and Access Type does not equal "Public". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Inbound SAML SSO Profiles
Test name | Test description | Test logic |
Google Workspace - SSO SAML Profile Configured | Verifies that the Google Workspace organization has at least one inbound SAML single sign-on profile configured with an identity-provider entity ID. Supports NIST SP 800-53 Rev. 5 IA-2, IA-8, and AC-17(1) and FedRAMP 20x KSI-IAM-AAM. Note: confirms SSO is configured, not enforced for every user. | Every record must satisfy: IDP Entity ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Google Workspace - MFA Enforced for All Users | Verifies that 2-Step Verification (multi-factor authentication) is enforced (not merely available) for every Google Workspace user account. Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA. | Every record must satisfy: MFA Enforced is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Workspace - MFA Enrolled for All Users | Verifies that every Google Workspace user account is enrolled in 2-Step Verification (multi-factor authentication). Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA. | Every record must satisfy: MFA Enrolled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Workspace - No Users With 90-Day Inactivity | Identifies Google Workspace accounts that have not signed in within the last 90 days so that stale or unused accounts can be reviewed, disabled, or removed. Supports NIST SP 800-53 Rev. 5 AC-2(3) and FedRAMP 20x KSI-IAM-SUS. | A record is sent for review when: Last Sign In is empty. A record is marked failed when: Last Sign In is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Login Audit Log
Test name | Test description | Test logic |
Google Workspace - Login Audit Log Freshness (30-Day) | Verifies that the Google Workspace login (authentication) audit log is being collected and is current within the last 30 days. Supports NIST SP 800-53 Rev. 5 AU-2 and AU-6 and FedRAMP 20x KSI-MLA-LET. | A record is sent for review when: Date is empty. A record is marked failed when: Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Security Report
Test name | Test description | Test logic |
Google Workspace - Less Secure App Access Disabled for All Users | Verifies that 'less secure app' (legacy/basic-auth) access is disabled for every Google Workspace user account, closing a password-only sign-in path that bypasses 2-Step Verification. Supports NIST SP 800-53 Rev. 5 AC-6(5) and CM-7 and FedRAMP 20x KSI-IAM-ELP. | Every record must satisfy: Less Secure Apps Access is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Google Workspace - Security Keys Enrolled for All Users | Verifies that every Google Workspace user account has at least one hardware security key enrolled for phishing-resistant multi-factor authentication. Supports NIST SP 800-53 Rev. 5 IA-2(1)(2) and FedRAMP 20x KSI-IAM-MFA. Note: requiring hardware security keys is a phishing-resistant posture that exceeds the FedRAMP Moderate baseline. | Every record must satisfy: Security Keys Enrolled is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Gorgias
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Greenhouse
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Help Scout
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Hive
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Homerun
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
HubSpot
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
HubSpot Ticketing
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Infinite BrassRing
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Insightly
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Intercom
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Ironclad
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Jamf
List of Computer Groups
Test name | Test description | Test logic |
Automate verification that macOS devices are correctly assigned to authorized computer groups. | Checks if macOS devices are assigned to authorized computer groups. | Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Computer Groups Record Id Name And Smart Static Classification | Confirms every computer group records a stable id, a name, and its smart/static classification so policy scoping targets are well defined. Supports NIST 800-53 Rev5 CM-8 (System Component Inventory) and CM-2 (Baseline Configuration). Fields: id, name, isSmart. | Every record must satisfy: ID has a value and Name has a value and Is Smart has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Computers
Test name | Test description | Test logic |
Validate asset details including hostname, serial numbers, OS versions, hardware configurations, and inventory updates. | Validate asset details including hostname, serial numbers, OS versions, hardware configurations, and inventory updates. | Every record must satisfy: Name has a value and Username has a value and Model has a value and Operating System has a value and OS Version has a value and FileVault 2 Partition Encryption State has a value. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed. |
Verify FileVault Disk Encryption Is Enabled On All Managed macOS Computers | Confirms managed Macs report their boot partition as ENCRYPTED (FileVault). Supports NIST 800-53 Rev5 SC-28 (Protection of Information at Rest). Fields: fileVault2EncryptionState, managed. | Every record must satisfy: FileVault 2 Partition Encryption State equals "ENCRYPTED" and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Jamf accurately records and maintains the current inventory of all managed macOS computers. | Verify Jamf accurately records and maintains the current inventory of all managed macOS computers. | Every record must satisfy: Operating System matches the pattern "[Mm][Aa][Cc] ?[Oo][Ss]" and Managed is true. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed. |
Verify Operating System Name And Version Are Recorded For Managed Computers | Confirms managed Macs report both OS name and OS version so patch level and vulnerability exposure can be assessed. Supports NIST 800-53 Rev5 SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring). Fields: operatingSystem, operatingSystemVersion, managed. | Every record must satisfy: Operating System has a value and OS Version has a value and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify The Host Firewall Is Enabled On All Managed macOS Computers | Confirms managed Macs report the built-in application firewall as enabled. Supports NIST 800-53 Rev5 SC-7 (Boundary Protection). Fields: firewallEnabled, managed. | Every record must satisfy: Firewall Enabled is true and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Mobile Devices
Test name | Test description | Test logic |
Verify accurate inventory of enrolled iOS and iPadOS devices in Jamf | Verify accurate inventory of enrolled iOS and iPadOS devices in Jamf | Every record must satisfy: Device Name has a value and Model has a value and Username has a value and Managed is true. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed. |
Verify Enrolled Mobile Devices Are Managed And Inventoried | Confirms every enrolled iOS/iPadOS device is Jamf-managed and carries an inventory id and model. Supports NIST 800-53 Rev5 CM-8 (System Component Inventory) and AC-19 (Access Control for Mobile Devices). Fields: managed, model, id. | Every record must satisfy: Managed is true and Model has a value and ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Managed Mobile Devices Have An Assigned User | Confirms each managed mobile device records an assigned user for accountability and ownership tracking. Supports NIST 800-53 Rev5 AC-19 (Access Control for Mobile Devices) and CM-8 (component ownership). Fields: username, managed. | Every record must satisfy: Username has a value and Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of OSX Configuration Profiles
Test name | Test description | Test logic |
Automate regular validation of enforced configuration profiles to maintain macOS security integrity. | Checks that every macOS configuration profile returned by Jamf carries an identifier and a name, so the enforced profile set is enumerable and attributable. Does not evaluate individual profile payload settings such as screen lock timeout or login window, which this proof type does not expose. | Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Automate validation of macOS profile enforcement, including screen lock timeout and login window settings | Checks that every macOS configuration profile returned by Jamf carries an identifier and a name. Does not evaluate screen lock timeout or login window settings: the profile list proof exposes only the profile identifier and name, not payload contents. | Every record must satisfy: ID has a value and Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Policies
Test name | Test description | Test logic |
Automate checks that all Jamf policies enforce approved baseline configurations. | Automate checks that all Jamf policies enforce approved baseline configurations. | Every record must satisfy: Name has a value and Enabled is true and Triggers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Automate verification of scheduled maintenance tasks, including updates and patching policies. | Checks if scheduled macOS maintenance and patching policies run as intended. | Every record must satisfy: Name has a value and Enabled is true and Triggers has a value. The test passes if at least 95% of records pass. If the proof contains no records, the test is marked failed. |
Validate policy deployment status and ensure no unauthorized changes occur without proper approvals | Checks if deployed Jamf policies match approved baselines. | Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Enabled Policies Have A Defined Execution Frequency | Confirms enabled Jamf policies specify an execution frequency so maintenance and patch automation runs on a defined cadence. Supports NIST 800-53 Rev5 SI-2 (Flaw Remediation) and CM-6 (Configuration Settings). Fields: enabled, executionFrequency, name. | A record is marked failed when: Enabled is true and Execution Frequency is empty. A record is marked failed when: Enabled is true and Name is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Verify Every Policy Has A Stable Identifier Name And Trigger | Confirms each policy records a stable id, a name, and a trigger so configuration changes are traceable and reviewable. Supports NIST 800-53 Rev5 CM-2 (Baseline Configuration) and CM-3 (Configuration Change Control). Fields: policyId, name, trigger. | Every record must satisfy: ID has a value and Name has a value and Triggers has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Restricted Software
Test name | Test description | Test logic |
Restricted Software Rules Notify On Detection | Checks that each restricted software rule raises a notification when it triggers, so attempts to run prohibited software are surfaced to administrators. | Every record must satisfy: Name has a value and Send Notification is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Restricted Software Rules Terminate Prohibited Processes | Checks that each restricted software rule names a target process and is set to terminate it, so prohibited applications are actually blocked rather than just recorded. | Every record must satisfy: Process Name has a value and Kill Process is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
OSX Configuration Profile
Test name | Test description | Test logic |
Configuration Profile Is Auto Installed And Not User Removable | Confirms the selected macOS configuration profile installs automatically and cannot be removed by the end user, so its settings stay enforced on the device. | Every record must satisfy: Distribution Method equals "Install Automatically" and User Removable is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Configuration Profile Is Scoped To The Computer Level | Confirms the selected macOS configuration profile applies at the computer level so its settings cover every user of the device, not just one account. | Every record must satisfy: Name has a value and Level contains "computer". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JazzHR
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Jira Cloud (OAuth)
List of Issues
Test name | Test description | Test logic |
Incident Management Tasks Completed | Checks that each issue in the Jira issue list records an issue type and a status. | Every record must satisfy: Issue Type has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Incident Resolution Tasks Completed | Ensure that all incident issues have a resolution date. | Every record must satisfy: Issue Type has a value and Resolution has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
P0 Security Issues Resolved | Ensure that all P0 (highest priority) security issues are resolved. | Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes if at least 70% of records pass. If the proof contains no records, the test is marked failed. |
P1 Security Issues Resolved | Ensure that all P1 security issues are resolved. | Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Records of Security Issues Being Assigned to Owners | Verify that all security issues are assigned to an owner. | Every record must satisfy: Issue Type has a value and Assignee has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Jira Cloud (Token Auth)
List of Groups
Test name | Test description | Test logic |
Jira Groups Have At Least One Member | Checks that every group in the Jira site has at least one member, flagging empty groups that linger with permissions still attached. | Every record must satisfy: Name has a value and Members is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Approval Verification | Verify all change issues are approved before work. | Every record must satisfy: Issue Type has a value and Assignee has a value. A record is marked failed when: Status is none of "Awaiting Approval" or "Approved". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Incident Resolution Timeliness | Validate timely resolution of incident issues. | Every record must satisfy: Issue Type has a value and Status has a value and Priority has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Jira Cloud - No Deactivated Accounts in User Access List | Flags deactivated Jira Cloud accounts that still appear in the user access list so their access and group membership can be removed. | Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Jira Server
List of Groups
Test name | Test description | Test logic |
Jira Access Groups Contain At Least One Member | Access-construct hygiene / stale-entitlement cleanup: every Jira Server group must have at least one member so that empty, dormant, or abandoned access groups are identified and removed as part of periodic access review. Maps to NIST 800-53 Rev5 AC-2 (account/group management) and AC-6, NIST 800-171 3.1.5, and ISO/IEC 27001:2022 A.5.18 (access rights review). Checks groupList field members is greater than 0. | Every record must satisfy: Members is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Issues
Test name | Test description | Test logic |
Incident Management Tasks Completed | Checks that each issue in the Jira issue list records an issue type and a status. | Every record must satisfy: Issue Type has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Incident Resolution Tasks Completed | Ensure that all incident issues have a resolution date. | Every record must satisfy: Issue Type has a value and Resolution has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
P0 Security Issues Resolved | Ensure that all P0 (highest priority) security issues are resolved. | Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes if at least 70% of records pass. If the proof contains no records, the test is marked failed. |
P1 Security Issues Resolved | Ensure that all P1 security issues are resolved. | Every record must satisfy: Issue Type has a value and Priority has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Records of Security Issues Being Assigned to Owners | Verify that all security issues are assigned to an owner. | Every record must satisfy: Issue Type has a value and Assignee has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Jira User Accounts Are Assigned To At Least One Access Group | Least-privilege / role-based access hygiene: every Jira Server user account must belong to at least one group so that access is governed through defined group-based authorization rather than ad hoc or orphaned accounts. Maps to NIST 800-53 Rev5 AC-6 (least privilege) and AC-2, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.5.18 (access rights), and SOC 2 CC6.1/CC6.3. Checks userList field groupNames is non-empty. | Every record must satisfy: Group has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Jira User Accounts Have Complete Identity Attributes | Access accountability / unique user identification: every Jira Server account in the user list must have a display name and an email address on file so that access can be attributed to a real, identifiable person. Maps to NIST 800-53 Rev5 AC-2 (account management) and IA-4 (identifier management), NIST 800-171 3.5.1, ISO/IEC 27001:2022 A.5.16 (identity management), and SOC 2 CC6.1. Checks userList fields displayName and emailAddress are non-empty. | Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JobAdder
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JobDiva
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JobScore
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Jobvite
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud
Directory Events
Test name | Test description | Test logic |
JumpCloud - Audit Records Capture Event Type and Source IP | NIST 800-53 Rev5 AU-3: audit records must establish what type of event occurred and its source. Checks each Directory Insights record carries a non-empty eventType and clientIp. An empty result is reported as needing review rather than failing: AU-3 governs what an audit record contains, and a window that produced no records is indistinguishable from a collection that did not run, so it is put in front of a person instead of judged. | Every record must satisfy: Event Type has a value and Client IP has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JumpCloud - Directory Insights Audit Events Carry A Timestamp | Checks that each Directory Insights audit event carries a timestamp. Empty proof is routed to review because absent events mean nothing was collected rather than nothing happened. | A record is sent for review when: Timestamp is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JumpCloud Audit Records Identify The Initiating Account | Routes Directory Insights audit records that carry no initiating account to review. | A record is sent for review when: Initiator is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Devices
Test name | Test description | Test logic |
JumpCloud Device Inventory Records Are Complete | NIST SP 800-53 CM-8: system component inventory. Verifies every JumpCloud managed device records a device name, operating system, and serial number. | Every record must satisfy: Device Name has a value and OS has a value and Serial Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Devices Have Checked In Recently | NIST SP 800-53 CM-8/SI-4: managed devices must remain actively monitored. Verifies every JumpCloud managed device last contacted the directory within the past 30 days, flagging stale or abandoned endpoints. Field: lastContact (date). | A record is sent for review when: Last Contact is empty. A record is marked failed when: Last Contact is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JumpCloud Devices Record Operating System Baseline | NIST SP 800-53 CM-8/CM-2: component inventory must capture the software baseline. Verifies every JumpCloud managed device records its operating system, OS family, and OS version. Fields: os, osFamily, version. | Every record must satisfy: OS has a value and OS Family has a value and OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Managed Devices Are Active | NIST SP 800-53 CM-8: maintain an accurate inventory of active system components. Verifies every JumpCloud managed device reports an Active status so decommissioned or disconnected devices are surfaced. Field: status (vlookup display value Active/Inactive). | Every record must satisfy: Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
JumpCloud User Passwords Are Active and Not Expired | NIST SP 800-53 IA-5: authenticator management. Verifies every JumpCloud user account has an active password state (not expired or pending), confirming credentials are managed and current. | Every record must satisfy: Password State equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud User Passwords Are Not Expired | NIST SP 800-53 IA-5: authenticator management. Verifies no JumpCloud user account is left with an expired password, which would indicate a stale credential still present on the directory. Field: passwordState (vlookup display value Active/Pending/Expired). | Every record must satisfy: Password State does not equal "Expired". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud User Records Identify an Account Owner | NIST SP 800-53 AC-2: account records must identify the individual owner. Verifies every JumpCloud user account records a first and last name so accounts are attributable. Fields: firstname, lastname. | Every record must satisfy: First Name has a value and Last Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud User Records Include Username and Email | NIST SP 800-53 AC-2: account management requires identifiable account records. Verifies every JumpCloud user has a username and email address. | Every record must satisfy: User Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Users Are Enrolled in Multi-Factor Authentication | NIST SP 800-53 IA-2(1): multi-factor authentication for network access. Verifies every JumpCloud user account is enrolled in MFA. | Every record must satisfy: MFA Enrollment equals "Enrolled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Password Policy
Test name | Test description | Test logic |
JumpCloud Password Policy Enforces a Minimum Length | NIST SP 800-53 IA-5(1): password-based authenticators must meet a minimum length. Verifies the JumpCloud password policy requires at least 12 characters. | Every record must satisfy: Minimum length in characters is 12 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Enforces Account Lockout | NIST SP 800-53 AC-7: limit consecutive invalid logon attempts. Verifies the JumpCloud password policy enables lockout and locks accounts after at most 5 failed attempts. | Every record must satisfy: Enable failed password + TOTP MFA attempts until lockout is true and Failed password + TOTP MFA attempts until lockout is 5 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Enforces Failed-Attempt Counter Reset Window | NIST SP 800-53 AC-7(a): enforce a limit of consecutive invalid attempts over a time window. Verifies the JumpCloud password policy enables the reset-lockout counter and uses a window of at least 15 minutes so failed attempts are counted across a meaningful period. Fields: enableResetLockoutCounter, resetLockoutCounterMinutes. | Every record must satisfy: Enable failed password attempts counter is true and Minutes until failed password attempts counter is automatically reset is 15 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Enforces Lockout Duration | NIST SP 800-53 AC-7(b): automatically lock a locked-out account for a defined duration. Verifies the JumpCloud password policy enables a lockout time and holds the account for at least 900 seconds (15 minutes). Fields: enableLockoutTimeInSeconds, lockoutTimeInSeconds. | Every record must satisfy: Enable time until lockout is automatically unlocked is true and Seconds until lockout is automatically unlocked is 900 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Enforces Password Expiration | NIST SP 800-53 IA-5(1): enforce a maximum password lifetime. Verifies the JumpCloud password policy enables password expiration and forces rotation within at most 90 days. Fields: enablePasswordExpirationInDays, passwordExpirationInDays. | Every record must satisfy: Enable days until password expiration is true and Days until password expiration is 90 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Enforces Password Reuse History | NIST SP 800-53 IA-5(1): prevent reuse of previous passwords. Verifies the JumpCloud password policy enables password history and retains at least 24 prior passwords. | Every record must satisfy: Enable most recent passwords cannot match is true and Most recent passwords that cannot match is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Prohibits Username in Password | NIST SP 800-53 IA-5: passwords must not contain the account username. Verifies the JumpCloud password policy disallows the username as a password substring. | Every record must satisfy: Allow username within password is false. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JumpCloud Password Policy Requires Mixed Case, Number, and Symbol | NIST SP 800-53 IA-5(1): password complexity. Verifies the JumpCloud password policy requires lowercase, uppercase, numeric, and symbol characters. | Every record must satisfy: Must include a lowercase letter is true and Must include an uppercase letter is true and Must include a number is true and Must include a special character is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Policy Results
Test name | Test description | Test logic |
JumpCloud - Configuration Policy Applied Successfully to All Systems | NIST 800-53 Rev5 CM-6: the configuration baseline (JumpCloud policy) must be enforced on every targeted system. Checks the per-system policy result 'state' equals 'success'. Empty result returns needsReview because no systems reported a status. | Every record must satisfy: Status equals "success". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JumpCloud - Policy Results Identify Target System and OS | NIST 800-53 Rev5 CM-8: systems under a configuration policy must be inventoried and identifiable. Checks that each policy result row carries a non-empty systemName and os so the enforced baseline maps to a known managed component. Empty result returns needsReview. | Every record must satisfy: System Name has a value and OS has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Group Membership List
Test name | Test description | Test logic |
JumpCloud - No Suspended Users Retain Group Membership | Checks that no suspended JumpCloud user retains group membership. Empty proof is routed to review because zero rows means nothing was collected, not that nothing is wrong. | Every record must satisfy: User State does not equal "Suspended". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JumpCloud - User Group Members Are Enrolled in MFA | NIST 800-53 Rev5 IA-2(1): every member of the reviewed JumpCloud user group must have multi-factor authentication enrolled. Checks the mfaEnrollment display field equals 'Enrolled'. Empty group returns needsReview because enrollment cannot be asserted with no members. | Every record must satisfy: MFA Enrollment equals "Enrolled". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JupiterOne
List of Alerts
Test name | Test description | Test logic |
JupiterOne Alerts Have Known Severity Rating | Verifies every JupiterOne alert finding carries a recognized severity rating (CRITICAL, HIGH, MEDIUM, LOW, or INFO) so findings can be triaged and prioritized (NIST SP 800-53 Rev 5 CA-7, RA-5). Uses one OR condition of equality checks on textField.severity (avoids the illegal text 'in' operator). | A record is marked failed when: Severity is none of "CRITICAL", "HIGH", "MEDIUM", "LOW" or "INFO". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JupiterOne No Critical Severity Alerts | Verifies no JupiterOne alert finding is classified CRITICAL severity, evidencing timely remediation of the most severe risks (NIST SP 800-53 Rev 5 RA-5, SI-2). Checks textField.severity. | Every record must satisfy: Severity does not equal "CRITICAL". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JupiterOne No High Or Critical Severity Alerts | Verifies no JupiterOne alert finding is HIGH or CRITICAL severity, evidencing that high-risk security findings are remediated within SLA (NIST SP 800-53 Rev 5 RA-5, SI-2). Single condition ANDs two inequality checks on textField.severity so both must hold per row. | Every record must satisfy: Severity is none of "CRITICAL" or "HIGH". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Assets
Test name | Test description | Test logic |
JupiterOne Asset Inventory Records Complete | Verifies every discovered asset in the JupiterOne graph has both a name and a resource type populated, evidencing a complete and identifiable system component inventory (NIST SP 800-53 Rev 5 CM-8). Single condition ANDs textField.name !isEmpty and textField.type !isEmpty. Empty proof fails because an empty asset inventory is itself a control gap. | Every record must satisfy: Name has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
JupiterOne Assets Classified In Graph | Verifies every asset carries at least one graph class (e.g. DataStore, Host, Bucket) so assets are categorized for control mapping and risk assessment (NIST SP 800-53 Rev 5 CM-8, RA-2). Checks textField.class !isEmpty (the class column is a comma-joined list of entity classes). Empty proof fails because an empty inventory cannot evidence classification. | Every record must satisfy: Class has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
JupiterOne Active Accounts With No Sign-In In 90 Days | Flags active JupiterOne accounts that have not signed in within the last 90 days. | A record is marked failed when: Active is true and Last Login is more than 90 days in the past. A record is sent for review when: Active is true and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JupiterOne No Inactive User Accounts | Verifies every JupiterOne user account is active, evidencing that disabled or deprovisioned accounts have been removed rather than lingering (NIST SP 800-53 Rev 5 AC-2, AC-2(3)). Checks booleanField.isActive isTrue (operand omitted). | Every record must satisfy: Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
JupiterOne User Accounts Have Email Identifier | Verifies every JupiterOne user account has an email address so each account maps to an identifiable individual for access reviews and accountability (NIST SP 800-53 Rev 5 AC-2, IA-2). Checks textField.email !isEmpty. | Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji
List of Device Details
Test name | Test description | Test logic |
Kandji - Device Enrollment Timestamps Recorded | Verifies that every managed device records both a first-enrollment and last-enrollment timestamp, evidencing that MDM enrollment lifecycle data is complete for each asset. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory) and CM-8(3) (Automated Unauthorized Component Detection). Fields: firstEnrollment, lastEnrollment. | Every record must satisfy: First Enrollment has a value and Last Enrollment has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Kandji - Device OS Version Recorded in Valid Format | Verifies that every managed device reports a non-empty OS version in a valid numeric dotted-version format (e.g. 18.3, 14.7.1), which is a prerequisite for flaw-remediation/patch-level assessment across the fleet. Supports NIST SP 800-53 Rev. 5 SI-2 (Flaw Remediation) and CM-8. Field: osVersion. | Every record must satisfy: OS Version has a value and OS Version matches the pattern "^[0-9]+(\.[0-9]+)*$". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Kandji - Managed Devices Run a Supported Apple Platform | Verifies that every device in Kandji device details reports a supported, MDM-managed Apple platform (Mac, iPad, or iPhone), so no unexpected/unmanaged platform is present in the enrolled fleet. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory). Field: platform. | A record is marked failed when: Platform is none of "Mac", "iPad" or "iPhone". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji Devices Are Enrolled In MDM | CM-2/CM-8: every device in the details report must carry an MDM enrollment timestamp, evidencing it is under managed configuration control. Checks firstEnrollment is non-empty on hp_listDeviceDetails. | Every record must satisfy: First Enrollment has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji Devices Belong To An Approved Platform Type | CM-6/CM-8: only approved Apple device platforms (Mac, iPhone, iPad, Apple TV) may be enrolled per the configuration baseline. On hp_listDeviceDetails, platform must regex-match the approved set; any other value fails. | Every record must satisfy: Platform is one of "Mac", "iPhone", "iPad" or "AppleTV". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji Devices Report An OS Version | SI-2: an OS version must be recorded for every managed device so patch level and flaw-remediation status can be assessed. Checks osVersion is non-empty on hp_listDeviceDetails. | Every record must satisfy: OS Version has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji macOS Devices Run A Supported OS Version | SI-2/CM-6: macOS devices must run a vendor-supported major version (macOS 14 Sonoma or later) to remain eligible for security updates. On hp_listDeviceDetails, a row passes if it is not a Mac or its osVersion begins with major version 14+. | A record is marked failed when: Platform equals "Mac" and OS Version has a value and OS Version does not match the pattern "^(1[4-9]|[2-9][0-9])\.". A record is sent for review when: Platform equals "Mac" and OS Version is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Devices
Test name | Test description | Test logic |
Kandji - Device Inventory Hardware Identifiers Populated | Verifies that every enrolled device inventory record has a device name, serial number, and hardware model populated, so each asset is uniquely and completely identified in the inventory. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory). Fields: deviceName, serialNumber, model. | Every record must satisfy: Device Name has a value and Serial Number has a value and Model has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Kandji - Device Serial Numbers Well-Formed | Verifies that every device inventory record carries a non-empty serial number matching the expected uppercase-alphanumeric hardware serial format, supporting reliable unique asset identification and anti-tamper tracking. Supports NIST SP 800-53 Rev. 5 CM-8 (System Component Inventory) and CM-8(1). Field: serialNumber. | Every record must satisfy: Serial Number has a value and Serial Number matches the pattern "^[A-Z0-9]{8,14}$". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Kandji Devices Have An Asset Tag Assigned | CM-8: each managed device must be labeled with an organizational asset tag for property accountability. Checks assetTag is non-empty on hp_listDevices. Asset tag is an optional Kandji field, so devices without a tag will fail at threshold 1.0 (the intended finding). | Every record must satisfy: Asset Tag has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Kandji Active User Roster Excludes Archived Accounts | AC-2: archived (offboarded) accounts must not remain in the active user roster. Checks the archived flag is false for every row on hp_users; an archived account present fails. | Every record must satisfy: Archived is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Kandji Users Have An Email Identifier | IA-4/AC-2: each directory user must have a unique email identifier for account management and attribution. Checks email is non-empty on hp_users. | Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Keap
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
KnowBe4
List of Acknowledgments
Test name | Test description | Test logic |
KnowBe4 - Assigned Policies Are Acknowledged and Completed | Verifies that every assigned policy has been acknowledged by the user and carries a completion date, so acknowledgment is evidenced per person. | Every record must satisfy: Policy Ack. Status equals "Acknowledged" and Completed On has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
KnowBe4 - No Past Due Policy or Training Assignments | Flags policy and training assignments the platform has marked past due, identifying users who have missed their required completion date. | A record is marked failed when: Status equals "Past Due". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Groups
Test name | Test description | Test logic |
KnowBe4 - Active Groups Have Assigned Members | Flags active groups that have no members, since group membership drives training and policy campaign enrollment and an empty group enrolls no one. | A record is sent for review when: Member Count equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
KnowBe4 - User Risk Scores Within Tolerance | Checks that no active user carries a risk score above the acceptable threshold, so high-risk individuals can be given targeted follow-up. | Every record must satisfy: Email has a value and Risk Score is 50 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
KnowBe4 Accounts With No Sign-In In 90 Days | Flags KnowBe4 user accounts that have not signed in within the last 90 days. | A record is marked failed when: Last Login is more than 90 days in the past. A record is sent for review when: Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Phishing Security Tests
Test name | Test description | Test logic |
Phishing Simulation Campaign Executed and Delivered | Verify each simulated phishing security test is a named, dated campaign that actually delivered messages to targets, evidencing a practical social-engineering exercise (NIST 800-53 Rev5 AT-2(1)). Fields: name, status, started_at, delivered_count. | Every record must satisfy: Campaign Name has a value and Status has a value and Start Date has a value and Delivered Count is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Phishing Simulation Outcome Metrics Tracked | Confirm every phishing security test records the full set of outcome metrics (delivered, opened, clicked, reported) so program effectiveness can be measured and reported (NIST 800-53 Rev5 PM-14, AT-2(1)). Requires delivered messages plus non-empty opened/clicked/reported counters. | Every record must satisfy: Delivered Count is greater than 0 and Opened Count has a value and Clicked Count has a value and Reported Count has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Phishing Simulation Run Window Adequate | Ensure each phishing security test ran for a meaningful window (duration of at least one day) and reached recipients, so results reflect a genuine exercise rather than a mis-configured or immediately-closed campaign (NIST 800-53 Rev5 AT-2(1)). Fields: duration, delivered_count. | Every record must satisfy: Duration Days is 1 or more and Delivered Count is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Training Activity
Test name | Test description | Test logic |
All Assigned Training Completed | Verify every training enrollment has been completed - a recorded completion date and a computed completion duration - so no learner in the campaign is left with outstanding required training (NIST 800-53 Rev5 AT-2). Fields: completion_date, days_until_complete. | Every record must satisfy: Completion Date has a value and Days Until Complete has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Initial Security Awareness Training Completion | Verify that all users complete initial security awareness training within 30 days of enrollment (KnowBe4 status Passed or Completed and days_until_complete of 30 or fewer). | Every record must satisfy: Name has a value and Email has a value and Module Name has a value and Enrollment Date has a value and Days Until Complete is 30 or less. A record is marked failed when: Status is none of "Passed" or "Completed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Role-Based Training Assignment | Confirm that users with specific roles (e.g., administrators, developers) are assigned appropriate role-based training modules | Every record must satisfy: Name has a value and Module Name has a value and Status has a value and Enrollment Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Security Awareness Training Completed On Time | Verify every training enrollment was completed within 30 days of enrollment, evidencing timely security awareness training (NIST 800-53 Rev5 AT-2). Requires a non-empty completion_date and days_until_complete <= 30. | Every record must satisfy: Completion Date has a value and Days Until Complete is 30 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Training Enrollment Record Completeness | Confirm each training enrollment record identifies the learner (name, email), the assigned module, and the enrollment date, so training records are complete and auditable (NIST 800-53 Rev5 AT-4). Fields: name, email, module_name, enrollment_date. | Every record must satisfy: Name has a value and Email has a value and Module Name has a value and Enrollment Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Training Campaigns
Test name | Test description | Test logic |
KnowBe4 - Training Campaign Completion Rate | Checks that every security awareness training campaign has reached the required completion percentage across the groups it was assigned to. | A record is marked failed when: Campaign Name is empty. A record is marked failed when: Status is empty. A record is sent for review when: Completion Percentage is empty. A record is sent for review when: Completion Percentage equals -1. A record is sent for review when: Status equals "Cancelled". A record is marked failed when: Status equals "Completed" and Completion Percentage does not equal -1 and Completion Percentage is less than 95. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
KnowBe4 - Training Campaigns Auto-Enroll New Group Members | Checks that training campaigns automatically enroll people added to their target groups, so new joiners are covered without manual assignment. | Every record must satisfy: Campaign Name has a value and Groups has a value and Start Date has a value and Auto Enroll is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Kustomer
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Lacework
List of Users
Test name | Test description | Test logic |
Lacework No Guest Or External Group Accounts | Fails if any Lacework user is assigned to a group whose name indicates guest or external access, enforcing least privilege by keeping unmanaged external identities out of the security console. Supports NIST SP 800-53 Rev 5 AC-6 (Least Privilege) and AC-2 (Account Management). Field checked: role (join of user group names; case-explicit regex, no inline flags). | Every record must satisfy: Role does not match the pattern "[Gg][Uu][Ee][Ss][Tt]" and Role does not match the pattern "[Ee][Xx][Tt][Ee][Rr][Nn][Aa][Ll]". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Lacework No Personal Email Domain Accounts | Fails if any Lacework user account is registered under a personal/consumer email domain (gmail, yahoo, hotmail, outlook, aol, icloud, protonmail) instead of a managed corporate identity. Enforces provisioning from centrally governed accounts. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management) and IA-2 (Identification and Authentication). Field checked: email (case-explicit regex, no inline flags). | Every record must satisfy: Email does not match the pattern "@(?:[Gg][Mm][Aa][Ii][Ll]|[Yy][Aa][Hh][Oo][Oo]|[Hh][Oo][Tt][Mm][Aa][Ii][Ll]|[Oo][Uu][Tt][Ll][Oo][Oo][Kk]|[Aa][Oo][Ll]|[Ii][Cc][Ll][Oo][Uu][Dd]|[Pp][Rr][Oo][Tt][Oo][Nn][Mm][Aa][Ii][Ll])\.". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Lacework No Shared Or Generic Named Accounts | Fails if any Lacework user's name is a generic/shared identifier (admin, test, shared, service, guest, root) rather than an individual, enforcing individual accountability and non-repudiation for actions in the security console. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Field checked: name (anchored, case-explicit regex, no inline flags). | Every record must satisfy: Name does not match the pattern "^(?:[Aa][Dd][Mm][Ii][Nn]|[Tt][Ee][Ss][Tt]|[Ss][Hh][Aa][Rr][Ee][Dd]|[Ss][Ee][Rr][Vv][Ii][Cc][Ee]|[Gg][Uu][Ee][Ss][Tt]|[Rr][Oo][Oo][Tt])$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Lacework User Account Inventory Completeness | Verifies every Lacework team user record is fully attributed - name, email, and role (group membership) are all populated - so account management has complete, accountable identity records. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Fields checked: name, email, role. | Every record must satisfy: Name has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Lacework User Email Address Format Validity | Fails if any Lacework user's email is malformed (missing local part, @, or a dotted domain), ensuring account records carry a resolvable identifier for notifications, de-provisioning, and access reviews. Supports NIST SP 800-53 Rev 5 AC-2 (Account Management). Field checked: email (regex valid in both JS RegExp and.NET, case-explicit, no inline flags). | Every record must satisfy: Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Lever
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Linear
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Microsoft Defender for Endpoint
List of Vulnerabilities
Test name | Test description | Test logic |
Microsoft Defender High and Critical Vulnerabilities Are Remediated Within 30 Days | Flags high and critical severity vulnerabilities first detected more than 30 days ago and still open, indicating remediation past its due date. | A record is sent for review when: Severity is one of "Critical" or "High" and First Detected is empty. A record is marked failed when: Severity is one of "Critical" or "High" and First Detected is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Microsoft Defender Vulnerabilities With Publicly Available Exploit Code Are Remediated | Flags open vulnerabilities that have publicly available exploit code, so the most readily weaponized findings are prioritized for remediation. | A record is marked failed when: Exploitable is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Microsoft Dynamics 365 Sales
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Microsoft Entra ID
Assigned Licenses
Test name | Test description | Test logic |
Group License Assignments Resolve To A Product And Grant At Least One Service Plan | Checks that each license assigned to the group names a known product and still grants at least one enabled service plan to its members. | Every record must satisfy: Product Name has a value and Licenses does not equal "No Licenses". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Conditional Access Policies
Test name | Test description | Test logic |
Conditional Access Policies Are Enabled and Enforced | Verifies each Azure AD Conditional Access policy is in the enabled (enforced) state rather than disabled or report-only, supporting NIST 800-53 Rev5 AC-17 and IA-2 by ensuring access controls are actually enforced. Checks textField.state. | Every record must satisfy: State equals "enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Conditional Access Policies Require Multifactor Authentication | Verifies enabled Conditional Access policies include the MFA grant control, supporting NIST 800-53 Rev5 IA-2(1) multifactor authentication for privileged and network access. Checks textField.builtInControls contains 'mfa' on enabled policies. | Every record must satisfy: State equals "enabled" and Built-in Controls contains "mfa". The test passes if any record passes. If the proof contains no records, the test is marked failed. |
Enabled Conditional Access Policies With User Exclusions Are Reviewed | Routes enabled Conditional Access policies that exclude specific users to review, since exclusions are the standard path around an enforced control. | A record is sent for review when: State equals "enabled" and Users Excluded does not equal "No users". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Verify Conditional Access Policies Enforce A Grant Control | Fails any conditional access policy that enforces no built-in grant control, catching misconfigured or empty policies. NIST 800-53 Rev5 AC-17. Fields: displayName, builtInControls. | Every record must satisfy: Name has a value and Built-in Controls does not equal "No Built-in Controls". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Conditional Access Policies Require Multifactor Authentication | Confirms each conditional access policy includes MFA among its built-in grant controls, verifying multifactor enforcement. NIST 800-53 Rev5 IA-2(1). Fields: builtInControls. | Every record must satisfy: Built-in Controls contains "mfa". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Group Membership List
Test name | Test description | Test logic |
Group Membership Contains Only Named Individual User Accounts | Checks that every member of the group is a named individual user account, with no nested groups, devices, or other non-human principals. | Every record must satisfy: Name has a value and Type equals "User". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Applications
Test name | Test description | Test logic |
Every Application Registration Is Identifiable And Has An Assigned Owner | Checks that every application registration in the directory is named, uniquely identifiable, and has at least one assigned owner. | Every record must satisfy: Application Name has a value and Application ID has a value and Owners has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Directory Role Permissions
Test name | Test description | Test logic |
Verify Directory Roles Are Classified As Built-in Or Custom | Confirms every directory role carries a recognized type classification (Built-in or Custom) so custom privileged roles are distinguishable during least-privilege review. NIST 800-53 Rev5 AC-6. Fields: roleType. | A record is marked failed when: Type is none of "Built-in" or "Custom". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Verify Every Directory Role Has A Documented Permission | Fails any directory role definition that expands to an empty allowed-resource-action, ensuring each role's privileges are documented for least-privilege review. NIST 800-53 Rev5 AC-6. Fields: roleName, permission. | Every record must satisfy: Name has a value and Permission has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Domains
Test name | Test description | Test logic |
Azure AD Domains Are Administratively Managed | Verifies each directory domain is administratively managed by the organization, supporting NIST 800-53 Rev5 CM-6 baseline configuration ownership over identity domains. Checks booleanField.isAdminManaged is true. | Every record must satisfy: Admin Managed is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Azure AD Domains Are Verified | Verifies every directory domain has completed domain-ownership verification, supporting NIST 800-53 Rev5 IA-5 and CM-6 by preventing use of unverified domains vulnerable to takeover. Checks booleanField.isVerified is true. | Every record must satisfy: Verified is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Groups
Test name | Test description | Test logic |
Generate a list of all security and Microsoft 365 groups in Azure AD. | Generate a list of all security and Microsoft 365 groups in Azure AD to maintain an accurate inventory for access control. | Every record must satisfy: Name has a value and Group Type has a value and Object ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Verify Mail-Enabled Groups Have A Populated Email Address | Confirms every Office 365 and Distribution group (mail-enabled group types) carries a populated email address, supporting an accurate, addressable group inventory. Security groups are exempt since they are not mail-enabled. NIST 800-53 Rev5 AC-2. Fields: groupType, email. | A record is marked failed when: Group Type does not equal "Security" and E-mail Address is empty. A record is marked failed when: Group Type is empty and E-mail Address is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Role Assignments
Test name | Test description | Test logic |
Verify Every App Role Assignment Identifies Its Principal | Confirms each service-principal app role assignment records the assigned principal's name so privileged access is attributable. NIST 800-53 Rev5 AC-2. Fields: principalName. | Every record must satisfy: Service Principal Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Service Principals
Test name | Test description | Test logic |
No Legacy Service Principals in Azure AD | Flags service principals of the deprecated Legacy type, which lack modern app-registration controls, supporting NIST 800-53 Rev5 CM-7 least functionality and AC-6. Checks textField.servicePrincipalType. Empty proof yields Needs Review since a tenant may legitimately have no service principals. | A record is marked failed when: Type equals "Legacy". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Subscriptions
Test name | Test description | Test logic |
Azure AD Directory Subscriptions Have Provisioned Licenses | Verifies each directory subscription reports at least one provisioned license so licensed security capabilities are actually available, supporting NIST 800-53 Rev5 CM-8 component inventory accuracy. Checks numberField.totalLicenses is greater than 0. Empty proof yields Needs Review. | Every record must satisfy: Total Licenses is greater than 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Azure AD Users Have Strong Password Enforcement Enabled | Verifies no user account has strong-password enforcement disabled (passwordPolicies must not include DisableStrongPassword), supporting NIST 800-53 Rev5 IA-5(1) password-based authentication strength. Checks textField.passwordPolicies. | Every record must satisfy: Password Policy does not contain "DisableStrongPassword". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Flag User Accounts With Passwords Older Than 365 Days | Fails any user whose password was last changed more than 365 days ago, enforcing periodic authenticator rotation. NIST 800-53 Rev5 IA-5. Fields: lastPasswordChangeDateTime. | A record is sent for review when: Password Last Changed is empty. A record is marked failed when: Password Last Changed is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Microsoft Entra ID Accounts With No Sign-In In 90 Days | Flags Entra ID directory accounts that have not signed in within the last 90 days, and routes accounts that have never signed in to review. | A record is sent for review when: Status equals "Active" and Last Login is more than 90 days in the past. A record is sent for review when: Status equals "Active" and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
No Unreviewed External Guest Accounts in Azure AD | Flags any directory account whose userType is Guest so external guest access is reviewed and justified, supporting NIST 800-53 Rev5 AC-2 account management and AC-6 least privilege. Checks textField.userType. | A record is marked failed when: User Type equals "Guest". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Verify Every User Has A Display Name And Principal Name | Confirms every directory user carries both a display name and a user principal name so identities are uniquely attributable. NIST 800-53 Rev5 IA-4. Fields: displayName, principalName. | Every record must satisfy: Name has a value and User Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Password Protection
Test name | Test description | Test logic |
Azure AD Account Lockout Threshold Is Configured | Verifies the tenant password-protection lockout threshold is enabled (greater than 0) and set to no more than 10 failed attempts, supporting NIST 800-53 Rev5 AC-7 unsuccessful logon attempt limits. Checks numberField.lockoutThreshold. | Every record must satisfy: Lockout Threshold is greater than 0 and Lockout Threshold is 10 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Microsoft Intune
Devices without a Compliance Policy
Test name | Test description | Test logic |
Microsoft Intune - Devices Without An Assigned Compliance Policy | Fails when any managed device is not covered by a compliance policy, since those devices are outside automated configuration enforcement. | A record is marked failed when: Device has a value. A record is sent for review when: Device is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Configuration Policies
Test name | Test description | Test logic |
Microsoft Intune - Configuration Policies Are Assigned To A Group | Fails any device configuration policy that is not assigned to a group, since an unassigned policy enforces no settings on any device. | A record is marked failed when: Assigned is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Devices
Test name | Test description | Test logic |
Inventory Granularity Verification | Examine documented system inventory to determine if it includes all required components at the necessary granularity for tracking. | Every record must satisfy: Device name has a value and Managed by has a value and Ownership has a value and Compliance has a value and OS has a value and OS version has a value and Last check-in has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Managed Devices
Test name | Test description | Test logic |
Managed Devices Have Checked In Within 30 Days | Flags managed devices that have not checked in with the device management service in the last 30 days. | A record is marked failed when: Last check-in is empty. A record is marked failed when: Last check-in is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Managed Devices Report A Compliant State | Checks that every managed device in the device inventory reports a compliant state. | Every record must satisfy: Compliance equals "Compliant". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Microsoft Intune Managed Devices Record An Operating System Baseline | Checks that each Intune managed device records its operating system and version. | Every record must satisfy: OS has a value and OS version has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Microsoft Intune - External Guest Accounts Require Review | Surfaces external guest accounts in the user list so each one is justified or removed, while internal member accounts pass. | A record is sent for review when: Username contains "#EXT#". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Microsoft Intune - User Accounts Are Attributable And Have An Account Manager | Checks that every directory account has a name, username, unique ID, and an assigned manager so each account has an accountable owner. | Every record must satisfy: Name has a value and Username has a value and User ID has a value and Manager has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Moneybird
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
MongoDB Atlas
Backup Compliance Policies
Test name | Test description | Test logic |
MongoDB Atlas Backup Compliance Policy Active With Authorized Approver | Verify the Atlas backup compliance policy is in the ACTIVE state and designates an authorized approver email (authorizedEmail is present and contains @). Ensures the backup protection controls are actually enforced and an accountable point of contact governs changes. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and AC-6 (Least Privilege / accountability). Fields checked: state, authorizedEmail. Missing policy is non-compliant. | Every record must satisfy: State equals "ACTIVE" and Authorized Email has a value and Authorized Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
MongoDB Atlas Backup Encryption At Rest Enabled | Verify the Atlas backup compliance policy enforces encryption at rest for backup snapshots (encryptionAtRestEnabled is true). Maps to NIST SP 800-53 Rev 5 SC-28 (Protection of Information at Rest). No backup compliance policy configured is treated as non-compliant. | Every record must satisfy: Encrypted is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
MongoDB Atlas Backup Immutable Copy Protection Enabled | Verify the Atlas backup compliance policy enables copy protection (copyProtectionEnabled is true), preventing deletion/modification of backup snapshots by project owners so backups remain recoverable after account compromise or ransomware. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and SI-7. Missing policy is non-compliant. | Every record must satisfy: Copy Protection is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
MongoDB Atlas Backup Restore Window Meets Minimum | Verify the Atlas backup compliance policy enforces a point-in-time restore window of at least 7 days (restoreWindowDays >= 7), ensuring sufficient recovery coverage for data corruption or ransomware discovered after the fact. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup) and CP-10 (Recovery and Reconstitution). Field checked: restoreWindowDays. Missing policy is non-compliant. | Every record must satisfy: Restore Window Days is 7 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
MongoDB Atlas Backup Snapshot Retention Configured | Verify every scheduled backup policy item retains snapshots for a positive period (retentionValue >= 1 and retentionUnit is present, e.g. days/weeks/months). Guards against schedule items that back up data but retain it for zero duration. Maps to NIST SP 800-53 Rev 5 CP-9 (System Backup). Fields checked: retentionValue, retentionUnit. Each row is one scheduled policy item; missing policy is non-compliant. | Every record must satisfy: Retention Value is 1 or more and Retention Unit has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
MongoDB Atlas Users Have Valid Email And Assigned Role | Verify every Atlas organization/project user account maps to a valid corporate identity (username present, emailAddress present and contains @) and carries an explicit RBAC role assignment (roleName present). Supports account-management completeness and role-based least privilege. Maps to NIST SP 800-53 Rev 5 AC-2 (Account Management) and AC-6 (Least Privilege). Fields checked: username, emailAddress, roleName. Each row is one user-role pairing; an empty user list warrants manual review. | Every record must satisfy: Username has a value and Email has a value and Email contains "@" and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
NetSuite
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Employees with Change in Employment Status
Test name | Test description | Test logic |
Deactivated Employees Retain An Employee Number | Flags employees deactivated during the period whose employee number is missing, which breaks traceability when verifying offboarding. | A record is marked failed when: Status equals "INACTIVE" and Employee Number is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Employee Status Change Records Include A Modification Date | Flags employee status changes with no recorded modification date, which makes it impossible to confirm the change was processed on time. | A record is marked failed when: Last Modified is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Employees
Test name | Test description | Test logic |
Accounting Employee Records Have A Name And Employee Number | Confirms every employee record in the accounting system carries a name and an employee number so it can be matched during access reviews. | Every record must satisfy: Name has a value and Employee Number has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Active Accounting Employees Have An Email Address On File | Flags active employees that have no email address recorded, which prevents matching them to their system accounts. | A record is marked failed when: Status equals "ACTIVE" and Email is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vendor and Customer Master Lists
Test name | Test description | Test logic |
Vendor And Customer Master Records Are Named And Classified | Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified. | Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Nutshell
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Occupop
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta
Global Session Policies
Test name | Test description | Test logic |
Okta Global Session Idle Timeout Bounded | NIST 800-53 Rev5 AC-11/AC-12: global session sign-on rules enforce an idle timeout of at most 2 hours. Field: idleTimeoutHours. | Every record must satisfy: Idle timeout (hours) is 2 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta Global Session Rules Enforce A Maximum Session Lifetime | Flags active global session sign-on rules that place no upper bound on how long a session can remain active. | A record is marked failed when: Status equals "ACTIVE" and Max session lifetime (hours) equals 0. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Group Membership List
Test name | Test description | Test logic |
Detect Inactive Users in Group | identify users within the group who are not in an active status, which may indicate deprovisioned or suspended accounts. | Every record must satisfy: Status equals "Active". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Ensure Timely Removal of Deactivated Users from Groups | Verify that users who have been deactivated are promptly removed from group memberships to prevent unauthorized access. | Every record must satisfy: Status does not equal "Deprovisioned". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Group Membership Accuracy | Checks that every Okta group membership record identifies the person and their username. Does not evaluate whether the membership itself is appropriate, which the proof cannot express. | Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Retrieve All Group Members | Checks that every Okta group membership record returned for the selected groups identifies the person and their username. | Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Validate Group Membership Based on User Attributes | Checks that every Okta group membership record identifies the person and their username. Does not compare membership against user attributes such as department or role; the proof carries no attribute to compare against. | Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Admins
Test name | Test description | Test logic |
Okta Administrator Identity Completeness | NIST 800-53 Rev5 AC-6: every privileged (admin) assignment identifies the person, email and role. Fields: name, email, role. | Every record must satisfy: Name has a value and Email has a value and Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of API Tokens
Test name | Test description | Test logic |
API Token Validity and Assignment | Ensure that API tokens are valid, assigned to active users, and have appropriate scopes. | Every record must satisfy: ID has a value and Name has a value and Expiration Date has a value and Creation Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta API Token Bounded Lifetime | NIST 800-53 Rev5 AC-2/SC-12: each API token expires within one year. Field: expiresAt. | Every record must satisfy: Expiration Date is less than 365 days in the future. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Deactivated Users
Test name | Test description | Test logic |
Deactivated User Access | Confirm that deactivated users do not have active sessions or access to resources. | Every record must satisfy: Person has a value and Username has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Devices
Test name | Test description | Test logic |
Device Compliance Status | Checks that each managed device reports an identifier and a device name. | Every record must satisfy: ID has a value and Device Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta Devices In Active State | NIST 800-53 Rev5 CM-8: enrolled devices are in the ACTIVE lifecycle state (raw Okta device status). Field: status (raw ACTIVE/SUSPENDED/DEACTIVATED/CREATED). | Every record must satisfy: Status equals "ACTIVE". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Groups
Test name | Test description | Test logic |
Group Definition Completeness | Ensure that all groups have defined purposes and associated access permissions | Every record must satisfy: Group ID has a value and Name has a value and Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of User Login Events
Test name | Test description | Test logic |
Okta Login Event Audit Completeness | NIST 800-53 Rev5 AU-3: each login/system-log record has actor, timestamp and outcome. Fields: userId, loginDate, status (outcome.result). | Every record must satisfy: User ID has a value and Login Date has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Automate provisioning and deprovisioning processes. | Checks that every account carries a recognized Okta lifecycle status, so provisioning and deprovisioning transitions are auditable. | Every record must satisfy: Status is one of "Active", "Provisioned", "Deprovisioned", "Suspended", "Staged", "Recovery", "Locked out" or "Password expired". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Find users with no status assigned. | Flags user records that carry a username and email address but no assigned status. | A record is marked failed when: Username has a value and Primary Email has a value and Status is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Okta Active Users With No Sign-In In 90 Days | Flags active Okta directory accounts that have not signed in within the last 90 days, and routes accounts that have never signed in to review. | A record is marked failed when: Status equals "Active" and Last Login is more than 90 days in the past. A record is sent for review when: Status equals "Active" and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Okta User Identity Completeness | NIST 800-53 Rev5 IA-4: every user record carries a unique, complete identity (person, username, primaryEmail, userId). Fields: person, username, primaryEmail, userId. | Every record must satisfy: Person has a value and Username has a value and Primary Email has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Retrieve All Users | Ensure that all users in the Okta organization are retrievable, including those with various statuses. | Every record must satisfy: Person has a value and Username has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Unique User Identification | Verify that each user has a unique identifier, ensuring no duplicate usernames exist. | Every record must satisfy: Username has a value and User ID has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users for a Given Application
Test name | Test description | Test logic |
Application Access Review | Review and validate user access to applications, ensuring alignment with role-based access controls. | Every record must satisfy: ID has a value and Email has a value and Status has a value and Scope has a value. The test passes if at least 50% of records pass. If the proof contains no records, the test is marked failed. |
Application User Assignments | Verify that users assigned to applications have appropriate access rights. | Every record must satisfy: ID has a value and Status has a value and Scope has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users with MFA Settings
Test name | Test description | Test logic |
MFA Enrollment Verification | Verify that all users are enrolled in Multi-Factor Authentication (MFA) | Every record must satisfy: MFA equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta No Users Without MFA | NIST 800-53 Rev5 IA-2: no user is left with MFA explicitly None. Field: mfa (vlookup Enabled/None). | Every record must satisfy: MFA does not equal "None". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Password Policies
Test name | Test description | Test logic |
Ensures that users cannot reuse previous passwords. | Checks that the password policy prevents reuse of the previous 24 passwords. | Every record must satisfy: Enforce password history is 24 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Exclude First Name From Password | Checks that the password policy forbids using the user's first name in a password. | Every record must satisfy: Does not contain first name is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Exclude Username From Password | Checks that the password policy forbids using the username in a password. | Every record must satisfy: Does not contain part of username is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Minimum Password Length | Checks that the password policy requires a minimum length of at least 12 characters. | Every record must satisfy: Minimum length is 12 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta Password Complexity Character Classes | NIST 800-53 Rev5 IA-5(1): password policy requires lower, upper, number and symbol character classes. Fields: lowerCase, upperCase, number, symbol. | Every record must satisfy: Lower case letter is true and Upper case letter is true and Number (0-9) is true and Symbol (e.g., !@#$%^&*) is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta Password Lockout Threshold Configured | NIST 800-53 Rev5 AC-7: an account lockout threshold is set between 1 and 10 failed attempts. Field: maxAttempts. | Every record must satisfy: Attempts before lockout is 1 or more and Attempts before lockout is 10 or less. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Okta Password Policy Excludes The User's Last Name | Checks that the Okta password policy forbids using the user's last name in a password. | Every record must satisfy: Does not contain last name is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Validates that passwords are checked against a list of commonly used or breached passwords. | Checks that the password policy screens passwords against a list of common or breached passwords. | Every record must satisfy: Restrict use of common passwords is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Onlyfy
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Orca Security
List of Alerts
Test name | Test description | Test logic |
Data-At-Risk Findings Remediated | Protection of stored/exposed data: any Orca alert categorized as Data at risk (exposed sensitive data) must be remediated (status closed, snoozed, or dismissed) rather than left open or in progress. Checks alertType + status. Maps to GDPR Art. 32 (security of processing), ISO/IEC 27001:2022 Annex A 8.12 (data leakage prevention), and NIST 800-53 Rev5 SC-28 (protection of information at rest). | A record is marked failed when: Alert Type equals "Data at risk" and Status is none of "closed", "snoozed" or "dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Malicious Activity Findings Remediated | Malware / malicious-code protection: any Orca alert categorized as Malicious activity must be remediated (status closed, snoozed, or dismissed) and not left open or in progress. Checks alertType + status. Maps to NIST 800-53 Rev5 SI-3 (malicious code protection), ISO/IEC 27001:2022 Annex A 8.7 (protection against malware), and SOC 2 CC6.8. | A record is marked failed when: Alert Type equals "Malicious activity" and Status is none of "closed", "snoozed" or "dismissed". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - Alerts Are Attributable to a Named Asset | Ensures every security finding is traceable to the affected resource for accountability and triage (NIST 800-53 Rev5 CM-8/AU-3/SI-4). Each Orca alert must identify the affected asset (asset field) and carry a finding description (alertName field); a row missing either fails. | Every record must satisfy: Asset has a value and Alert Name has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - No Open Critical Alerts | Verifies remediation of the highest-severity cloud security findings (NIST 800-53 Rev5 RA-5(5)/SI-2/CA-5). A critical-severity Orca alert (severity field) must not remain in the Open status (status field); such a row fails. | A record is marked failed when: Severity equals "critical" and Status equals "open". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - Vulnerability Alerts Are Remediated | Confirms flaw remediation of vulnerability findings (NIST 800-53 Rev5 SI-2/RA-5). An Orca alert whose category (alertType field) is Vulnerabilities must not remain in the Open status (status field); such a row fails. | A record is marked failed when: Alert Type equals "Vulnerabilities" and Status equals "open". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of All Orca Users
Test name | Test description | Test logic |
Orca Security - User Accounts Have an Assigned Role | Enforces role-based access management so no Orca console account exists without a defined role (NIST 800-53 Rev5 AC-2/AC-6). Each user must have at least one role (role field); an account with no role fails. Empty proof yields needsReview since at least one account is expected. | Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Assets
Test name | Test description | Test logic |
No High Or Critical Risk Cloud Assets | Cloud security posture: no asset in the Orca inventory may carry a high or critical risk level; such assets must be risk-reduced. Checks riskLevel. Maps to NIST 800-53 Rev5 RA-5 (vulnerability monitoring & remediation) and ISO/IEC 27001:2022 Annex A 8.8 (management of technical vulnerabilities). | Every record must satisfy: Risk Level is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - Asset Inventory Records Are Complete | Validates completeness of the cloud asset inventory so every discovered resource is accountable (NIST 800-53 Rev5 CM-8). Each asset must record a name (assetName field), a type (assetType field), and its owning cloud account/subscription (subscriptionAccount field); a row missing any of these fails. Empty proof yields needsReview since no inventory was returned. | Every record must satisfy: Asset has a value and Asset Type has a value and Cloud Account has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - Assets Scanned Within 30 Days | Confirms vulnerability-scanning coverage and freshness across the cloud estate (NIST 800-53 Rev5 RA-5/SI-2). Each asset's last-scanned timestamp (lastScanned field) must be no more than 30 days old; assets not scanned within 30 days fail. Empty proof yields needsReview since no inventory was returned. Note: an asset with a blank lastScanned is treated as not-a-failure to avoid false negatives at threshold 1.0. | A record is sent for review when: Last Scanned is empty. A record is marked failed when: Last Scanned is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Orca Security - No Critical Risk-Level Assets | Surfaces cloud assets carrying unmitigated critical risk that require prioritized remediation (NIST 800-53 Rev5 RA-5/CM-6/CA-5). Any asset whose Orca risk level (riskLevel field) is Critical fails. | Every record must satisfy: Risk Level does not equal "critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Paylocity
List of Employee Details
Test name | Test description | Test logic |
Paylocity Employees in Non-Active Employment Statuses Are Reviewed for Continued Access | Surfaces employees whose employment status is neither active nor terminated (leave, retired, transferred) so their system access can be re-verified. | A record is sent for review when: Employment Status is one of "Leave of Absence", "Retired", "Deceased" or "Transferred". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Paylocity Terminated Employees Have a Recorded Termination Date | Flags employees marked as terminated whose records carry no termination date, so offboarding and access-removal timelines can be evidenced. | A record is marked failed when: Employment Status equals "Terminated" and Termination Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Pinpoint
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Pipedrive
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Pipeliner
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Prisma Cloud
List of Assets
Test name | Test description | Test logic |
Prisma Cloud - Cloud Asset Inventory Records Carry Required Identifying Fields | Checks that every cloud asset in your inventory has an identifier, asset type, and cloud provider recorded. | Every record must satisfy: ID is not blank and Asset Type has a value and Cloud Account Type has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Prisma Cloud Asset Inventory Records Include Type and Region | NIST SP 800-53 CM-8: the system component inventory must capture enough metadata to identify each component and its deployment location. Verifies every Prisma Cloud asset records an asset type and a cloud region. | Every record must satisfy: Asset Type has a value and Cloud Account Region has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Cloud Accounts
Test name | Test description | Test logic |
Prisma Cloud - Cloud Account Connections Modified Within The Last Year | Flags connected cloud accounts whose configuration has not been modified in over a year, so long-untouched connections get reviewed. | A record is sent for review when: Last Modified is empty. A record is sent for review when: Last Modified is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud - Connected Cloud Accounts Have A Designated Owner | Flags connected cloud accounts that have no designated owner recorded. | A record is marked failed when: Account Owner is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud Accounts Have an Assigned Owner | NIST SP 800-53 AC-2 and CM-8: managed accounts and inventoried components must have an accountable owner. Verifies every Prisma Cloud cloud account records an account owner. | Every record must satisfy: Account Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Policies
Test name | Test description | Test logic |
Prisma Cloud - Critical And High Severity Policies Are Enabled | Flags critical and high severity cloud security policies that are switched off, so gaps in automated detection coverage are visible. | A record is marked failed when: Severity equals "critical" and Enabled is false. A record is marked failed when: Severity equals "high" and Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud - Custom Policies Are Enabled | Flags organization-authored custom policies that are switched off, so tenant-specific detections are not left silently inactive. | A record is marked failed when: Mode equals "Custom" and Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud Security Policies Are Enabled | NIST SP 800-53 CM-6: configuration settings must be actively enforced. Verifies that every Prisma Cloud security policy returned in the proof is enabled. Collect the proof filtered to the policy types you require (for example Config policies) so that disabled policies surface as failures. | Every record must satisfy: Enabled is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Security Vulnerabilities
Test name | Test description | Test logic |
Prisma Cloud - No Exploitable Critical Or High Vulnerabilities | Flags reported vulnerabilities that have a known working exploit, so the highest-risk findings are surfaced for prompt remediation. | A record is marked failed when: Exploitable is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud Critical and High Vulnerabilities Are Not Exploitable | NIST SP 800-53 RA-5 and SI-2: vulnerabilities must be monitored and remediated, prioritizing those with known exploits. The Prisma Cloud vulnerabilities proof is restricted to Critical and High severities; this test fails if any returned vulnerability is flagged exploitable. | Every record must satisfy: Exploitable is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Prisma Cloud Vulnerability Records Include a Published Date | NIST SP 800-53 RA-5 and SI-2: remediation must be prioritized and aged against vulnerability disclosure. Verifies every Prisma Cloud vulnerability record carries a published date so remediation SLAs can be measured. | Every record must satisfy: Published Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Users
Test name | Test description | Test logic |
Prisma Cloud - No Users Inactive For More Than 90 Days | Flags accounts with no sign-in in the last 90 days, plus accounts with no recorded sign-in at all, so unused access can be reviewed or removed. | A record is marked failed when: Last Login is more than 90 days in the past. A record is sent for review when: Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Prisma Cloud User Accounts Have an Identity and Role | NIST SP 800-53 AC-2 and AC-6(1): access reviews must identify the account and its assigned role to support recertification of access to security functions. Verifies every Prisma Cloud user account records a name and at least one role. Prisma Cloud exposes no access-review proof type, so this reads the user list. | Every record must satisfy: Name has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Prisma Cloud Users Have a Role Assignment | NIST SP 800-53 AC-2 and AC-6: accounts must have explicit role assignments to support least privilege and periodic access review. Verifies every Prisma Cloud user record has at least one assigned role. | Every record must satisfy: Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Qualys
List of Assets
Test name | Test description | Test logic |
Qualys - Asset Configuration Compliance Scan Recency (90-Day) | Verifies each Qualys-managed asset has had a Policy Compliance (configuration) scan within the last 90 days so configuration baselines are assessed on a recurring cadence. Checks the LAST_COMPLIANCE_SCAN_DATETIME field. Supports NIST SP 800-53 Rev. 5 CM-6 and RA-5, CMMC 2.0 / NIST 800-171 3.4.1, and ISO/IEC 27001:2022 Annex A A.8.9. | A record is marked failed when: Last Compliance Scan is empty. A record is marked failed when: Last Compliance Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys - Asset Vulnerability Scan Coverage And Recency (30-Day) | Flags any Qualys-managed asset that has never had a vulnerability scan or whose last vulnerability scan is older than 30 days, so scan coverage gaps and stale assets are remediated. Checks the LAST_VULN_SCAN_DATETIME field. Supports NIST SP 800-53 Rev. 5 RA-5 and SI-2, CMMC 2.0 / NIST 800-171 3.11.2, and ISO/IEC 27001:2022 Annex A A.8.8. | A record is marked failed when: Last Vulnerability Scan is empty. A record is marked failed when: Last Vulnerability Scan is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys Asset Inventory Records Are Fully Identified | NIST SP 800-53 Rev 5 CM-8 (System Component Inventory) and RA-5 asset coverage: every asset record must carry the identifying attributes needed for accountable inventory and scan attribution - hostname, IP address, and operating system. Fails any asset row missing HOSTNAME, IP, or OS. Fields checked: HOSTNAME (text), IP (text), OS (text). | Every record must satisfy: Asset has a value and IP Address has a value and Operating System has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Qualys Assets Have An Authenticated Vulnerability Scan Within 90 Days | NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): confirms each asset has a recorded authenticated vulnerability scan datetime no older than the quarterly (90-day) cadence. Fails any asset whose LAST_VULN_SCAN_DATETIME is empty or more than 90 days old. Fields checked: LAST_VULN_SCAN_DATETIME (date). | Every record must satisfy: Last Vulnerability Scan has a value. A record is marked failed when: Last Vulnerability Scan is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys Assets Scanned For Vulnerabilities Within 30 Days | NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): verifies every managed asset in the Qualys inventory was covered by a VM scan recently, so scan coverage stays current and no host drifts out of the scanning cadence. Fails any asset whose LAST_VM_SCANNED_DATE is empty (never scanned) or is more than 30 days old. Fields checked: LAST_VM_SCANNED_DATE (date). | Every record must satisfy: Last VM Scan has a value. A record is marked failed when: Last VM Scan is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of PC Scans
Test name | Test description | Test logic |
Qualys Policy Compliance Scans Completed Successfully | NIST SP 800-53 Rev 5 CM-6 (Configuration Settings) and RA-5: every Policy Compliance (PC) scan launched in the reporting period must have finished successfully so configuration-baseline compliance results are complete and trustworthy. Fails any scan whose STATE is not Finished. Text comparison is case-insensitive. Fields checked: STATE (text). | Every record must satisfy: Status equals "Finished". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Qualys - No Console Accounts Inactive More Than 90 Days | Identifies Qualys console user accounts that have not logged in within the last 90 days so stale or unused privileged accounts are reviewed, disabled, or removed. Checks the LAST_LOGIN_DATE field. Supports NIST SP 800-53 Rev. 5 AC-2 and AC-2(3), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18. | A record is sent for review when: Last Login Date is empty. A record is marked failed when: Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys Console Accounts Have No Stale Logins | NIST SP 800-53 Rev 5 AC-2 (Account Management, inactive account review): every Qualys console user account must have logged in within the last 90 days. Accounts that have never logged in (empty LAST_LOGIN_DATE) or have been inactive for more than 90 days are flagged for disablement/review. Fields checked: LAST_LOGIN_DATE (date). | Every record must satisfy: Last Login Date has a value. A record is marked failed when: Last Login Date is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of VM Scans
Test name | Test description | Test logic |
Qualys - Vulnerability Scans Completed Without Error Or Cancellation | Flags any Qualys vulnerability (VM) scan in the reporting period that ended in an Error or Canceled state, so failed scan jobs are investigated and re-run rather than leaving blind spots in vulnerability coverage. Checks the scan STATE field. Supports NIST SP 800-53 Rev. 5 RA-5 and SI-2, CMMC 2.0 / NIST 800-171 3.11.2, and ISO/IEC 27001:2022 Annex A A.8.8. | A record is marked failed when: Status equals "Error". A record is marked failed when: Status equals "Canceled". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys VM Scans Completed Successfully | NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning): every vulnerability (VM) scan launched in the reporting period must have finished successfully rather than erroring, canceling, or stalling, so scan results are complete and trustworthy. Fails any scan whose STATE is not Finished. Text comparison is case-insensitive. Fields checked: STATE (text). | Every record must satisfy: Status equals "Finished". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys VM Scans Launched Within The Monthly Cadence | NIST SP 800-53 Rev 5 RA-5 (Vulnerability Monitoring and Scanning, scan frequency): confirms vulnerability scans in the reporting period were actually launched on the expected monthly cadence and none is stale. Fails any scan whose LAUNCH_DATETIME is empty or more than 35 days old. Fields checked: LAUNCH_DATETIME (date). | Every record must satisfy: Launch Date has a value. A record is marked failed when: Launch Date is more than 35 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
VM Remediation Tickets
Test name | Test description | Test logic |
Qualys - High-Severity Vulnerabilities Remediated Within SLA | Enforces a severity-tiered remediation SLA: any high-severity Qualys remediation ticket (SEVERITY 4 or 5) that is past its due date fails the check, while lower-severity tickets are not flagged by this control. Checks the SEVERITY and overDue fields. Supports NIST SP 800-53 Rev. 5 RA-5(d) and SI-2, CMMC 2.0 / NIST 800-171 3.11.3, and ISO/IEC 27001:2022 Annex A A.8.8. | A record is marked failed when: Severity is 4 or more and Overdue is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Qualys VM Remediation Tickets Have Due Dates And Are Not Overdue | NIST SP 800-53 Rev 5 SI-2 (Flaw Remediation): every vulnerability remediation ticket must have a defined remediation deadline (DUE_DATETIME) and must not be past due (overDue). Flags remediation SLA breaches. Fails any ticket with an empty due date or overDue=true. Fields checked: DUE_DATETIME (date), overDue (boolean). | Every record must satisfy: Due date has a value. Every record must satisfy: Overdue is false. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
Rally
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rapid7
List of Asset Groups
Test name | Test description | Test logic |
Rapid7 Asset Groups Contain Assets | Supports NIST 800-53 Rev5 CM-8 / RA-5 (asset inventory and scan scope completeness): every InsightVM asset group must contain at least one asset so scan scope and reporting groupings are not empty. Checks numberField.assets is 1 or more. | Every record must satisfy: Assets is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Assets
Test name | Test description | Test logic |
Rapid7 Assets Assessed For Configuration Policies | Supports NIST 800-53 Rev5 CM-6 / RA-5 (configuration baseline assessment): every InsightVM asset must have been assessed against configuration policies so baseline drift is detected. Checks booleanField.assessedForPolicies is true. | Every record must satisfy: Assessed for Policies is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rapid7 Assets Assessed For Vulnerabilities | Supports NIST 800-53 Rev5 RA-5 (vulnerability scan coverage): every InsightVM asset in inventory must have been assessed for vulnerabilities. Checks booleanField.assessedForVulnerabilities is true. | Every record must satisfy: Assessed for Vulnerabilities is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rapid7 Assets Scanned Within the Last 45 Days | Supports NIST 800-53 Rev5 RA-5 (vulnerability scanning frequency): every InsightVM asset must have a non-empty lastScanned date that is within the last 45 days so vulnerability data stays current. Checks dateField.lastScanned. | Every record must satisfy: Last Scanned has a value. A record is marked failed when: Last Scanned is more than 45 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Rapid7 InsightVM - Administrator Role Assignments Reviewed | Flags Rapid7 InsightVM accounts that hold an administrator role so you can confirm each one still needs privileged access. | A record is sent for review when: Role is empty. A record is sent for review when: Role contains "Administrator". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Rapid7 InsightVM - No Locked-Out User Accounts | Checks every Rapid7 InsightVM account for a locked state and flags locked accounts so the lockout can be investigated. | A record is sent for review when: Lockout is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerabilities by Asset
Test name | Test description | Test logic |
Rapid7 Asset Vulnerabilities Below High CVSS Score | Supports NIST 800-53 Rev5 RA-5 (risk-based remediation prioritization): no vulnerability finding on the asset may have a CVSS severity score of 7.0 or higher (High/Critical). Checks numberField.severityScore is below 7. | Every record must satisfy: CVSS Severity is less than 7. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Rapid7 No Critical Vulnerabilities On Asset | Supports NIST 800-53 Rev5 RA-5 / SI-2 (flaw remediation): no vulnerability finding on the asset may carry a Critical severity rating. Checks textField.severity is not Critical. | Every record must satisfy: Severity does not equal "Critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerabilities by Site
Test name | Test description | Test logic |
Rapid7 No Critical Or Severe Vulnerabilities At Site | Supports NIST 800-53 Rev5 RA-5 / SI-2 (flaw remediation): no vulnerability finding at the site may carry a Critical or Severe severity rating. Checks textField.severity is neither Critical nor Severe. | Every record must satisfy: Severity is none of "Critical" or "Severe". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Rapid7 Site Vulnerabilities Within Remediation SLA | Supports NIST 800-53 Rev5 SI-2 (flaw remediation timeliness): no open vulnerability finding at the site may have been first recorded more than 90 days ago, enforcing a 90-day remediation SLA. Checks dateField.firstRecorded. | Every record must satisfy: First Recorded has a value. A record is marked failed when: First Recorded is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Re:amaze
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Salesflare
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Salesforce
List of Permission Sets
Test name | Test description | Test logic |
Salesforce Permission Sets Have A Description | Requires every custom permission set to carry a description so each grant of additional privileges is documented and justifiable during access reviews. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege) and CM-8, ISO/IEC 27001:2022 A.5.15 (Access Control) and A.8.2, and SOC 2 CC6.3. Field checked: description. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Profiles
Test name | Test description | Test logic |
Full License Profiles Are Custom Built For Least Privilege | Surfaces profiles on the full user license that are standard rather than custom, since standard profiles cannot be tailored and often grant broader access than needed. | A record is sent for review when: User License equals "Salesforce" and Custom is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Salesforce Usernames Follow Email Identifier Standard | Enforces the organization's user-identifier standard by requiring every Salesforce username to be a well-formed email address, supporting unique, attributable identifiers. Maps to NIST 800-53 Rev5 IA-4 (Identifier Management), NIST 800-171 3.5.5/3.5.6 and ISO/IEC 27001:2022 A.5.16 (Identity Management). Field checked: username. | Every record must satisfy: Username is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Salesforce Users Are Not Assigned The System Administrator Profile | Surfaces every account assigned the highly privileged built-in System Administrator profile so privileged access can be justified and kept to a minimum during access reviews. Maps to NIST 800-53 Rev5 AC-6(5) (Privileged Accounts) and AC-2, NIST 800-171 3.1.5 (Least Privilege), ISO/IEC 27001:2022 A.8.2 (Privileged Access Rights) and SOC 2 CC6.3. Field checked: profile. Customize the profile name to your org's admin profile. | Every record must satisfy: Profile does not equal "System Administrator". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Salesforce Users Have Logged In Within 90 Days | Detects dormant/inactive Salesforce accounts by requiring each user's most recent login to be within the last 90 days. Maps to NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts), NIST 800-171 3.1.11, ISO/IEC 27001:2022 A.5.18 and SOC 2 CC6.2/CC6.3. Field checked: lastLoginDate. | A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Profile Details
Test name | Test description | Test logic |
Salesforce Custom Profile Has Documented Justification | Requires any custom (non-standard) Salesforce profile to carry a description documenting its business justification; standard profiles pass automatically. Ensures tailored privilege sets are reviewed and justified. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege) and CM-8, NIST 800-171 3.1.5, ISO/IEC 27001:2022 A.5.15 and A.8.2, and SOC 2 CC6.3. Fields checked: isCustom, description. | A record is marked failed when: Custom is true and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Salesforce Service Cloud
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SentinelOne
List of Agents
Test name | Test description | Test logic |
SentinelOne Agents Are Assigned to an Account and Group | Ensures every SentinelOne endpoint agent is enrolled under an account and a management group so that protection policy is inherited (NIST 800-53 Rev5 CM-8), by requiring non-empty computerName, accountName, and groupName. | Every record must satisfy: Endpoint Name has a value and Account has a value and Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SentinelOne Agents Completed a Recent Successful Scan | Confirms each SentinelOne endpoint agent has a last successful scan within the past 7 days (NIST 800-53 Rev5 SI-3), catching endpoints that are stale or have never scanned. Requires computerName and lastScanDate to be present; an empty lastScanDate (never scanned) fails. | Every record must satisfy: Endpoint Name has a value and Last Scan Date has a value. A record is marked failed when: Last Scan Date is more than 7 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SentinelOne Agents Scanned Within 30 Days | Verifies every SentinelOne endpoint agent completed a successful scan within the last 30 days (NIST 800-53 Rev5 SI-3, RA-5). Field: lastScanDate (from agents.lastSuccessfulScanDate). A stale or never-scanned agent is surfaced for review. | A record is sent for review when: Last Scan Date is empty. A record is marked failed when: Last Scan Date is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Alerts
Test name | Test description | Test logic |
SentinelOne - Security Alerts Have Been Reported | Verifies that every SentinelOne cloud-detection alert carries a reported timestamp (reportedDate, from alertInfo.reportedAt), evidencing that detections were escalated/reported rather than left untracked. Supports incident reporting and response under NIST SP 800-53 Rev. 5 IR-6 and AU-6, ISO/IEC 27001:2022 Annex A A.5.25, and SOC 2 CC7.3. | Every record must satisfy: Reported Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Alerts Are Named and Reported | Confirms each SentinelOne alert has a rule name, an alert id, and a non-empty reportedDate, evidencing that detections were surfaced/triaged rather than left unreported (NIST 800-53 Rev5 SI-4 / IR-6). | Every record must satisfy: Name has a value and Alert ID has a value and Reported Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Alerts Carry a Valid Severity Classification | Verifies every SentinelOne alert is classified with a recognized severity of Low, Medium, High, or Critical so that responders can prioritize remediation (NIST 800-53 Rev5 SI-4). A proof with no rows is treated as needsReview: this template only flags violations, so a zero-row proof cannot distinguish a compliant state from evidence that was never collected. | A record is marked failed when: Severity has a value and Severity is none of "Low", "Medium", "High" or "Critical". A record is sent for review when: Severity is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Alerts Recorded With Identifier And Timestamp | Verifies every cloud-detection alert has a name, alert id, severity, and creation timestamp so the monitoring record is auditable (NIST 800-53 Rev5 AU-3, SI-4, IR-6). Fields: name, alertId, severity, createdDate. | Every record must satisfy: Name has a value and Alert ID has a value and Severity has a value and Created Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Device Control Rules
Test name | Test description | Test logic |
SentinelOne Device Control Rules Are Enabled | Confirms each SentinelOne USB/peripheral device-control rule is Enabled (status = Enabled) and fully specified with a name and ruleType, enforcing removable-media restrictions (NIST 800-53 Rev5 MP-7 / SC-41). Empty proof needs review because it may indicate no device-control policy is configured. | Every record must satisfy: Status equals "Enabled" and Name has a value and Rule Type has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Groups
Test name | Test description | Test logic |
SentinelOne Groups Are Named And Correctly Typed | Verifies every endpoint group has a name and id and a recognized membership type (static/dynamic/pinned) so grouping used for policy scoping is well-formed (NIST 800-53 Rev5 CM-8, AC-3). Fields: name, groupId, type (from groups.type). | Every record must satisfy: Name has a value and Group ID has a value. A record is marked failed when: Type is none of "static", "dynamic" or "pinned". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SentinelOne Groups Have An Accountable Creator | Verifies every group records a creator id and creation date so group configuration changes are attributable (NIST 800-53 Rev5 AU-2, CM-3). Fields: creatorId (from groups.creatorId), createdOn (from groups.createdAt). | Every record must satisfy: Creator ID has a value and Created On has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SentinelOne Policy Groups Are Governed and Attributable | Verifies each SentinelOne policy group is fully defined with a name, id, type, and a recorded creator so that endpoint policy baselines are attributable (NIST 800-53 Rev5 CM-2), by requiring non-empty name, groupId, type, and creatorId. | Every record must satisfy: Name has a value and Group ID has a value and Type has a value and Creator ID has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
SentinelOne - No Console Accounts Inactive Over 90 Days | Flags SentinelOne console accounts whose last login (lastLogin) is more than 90 days ago so dormant privileged accounts can be reviewed, disabled, or removed. Supports account management and inactivity review under NIST SP 800-53 Rev. 5 AC-2(3), CMMC 2.0 / NIST 800-171 3.1.1, and ISO/IEC 27001:2022 Annex A A.5.18. | A record is marked failed when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Console Users Are Named and Role-Assigned | Verifies each SentinelOne console account is attributable to a named individual with an assigned role (NIST 800-53 Rev5 AC-2 / AC-6) by requiring non-empty fullName, email, and roleId. | Every record must satisfy: Full Name has a value and Email has a value and Role ID has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Console Users Are Not Inactive | Flags SentinelOne console users whose last login is more than 90 days ago as candidates for disablement (NIST 800-53 Rev5 AC-2(3)). Users that have never logged in (empty lastLogin) are not flagged; each row must still carry an email of record. | A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. Every record must satisfy: Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SentinelOne Console Users Have MFA Enabled | Verifies every management-console user has two-factor authentication enabled (NIST 800-53 Rev5 IA-2(1), AC-2). Field: mfa (boolean, from users.twoFaEnabled). | Every record must satisfy: MFA is true. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow
List of Assets
Test name | Test description | Test logic |
ServiceNow - Company Assets Have An Assigned Owner | Confirms each inventoried company asset (configuration item) has an assigned owner, supporting accountable asset inventory. Supports NIST SP 800-53 Rev. 5 CM-8 and PM-5. Fields: assignedTo (ast_assigned_to display value), name (ast_display_name display value). | Every record must satisfy: Asset Name has a value and Owner has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow Asset Inventory Has Serial Numbers | The configuration item / asset inventory must uniquely and accurately identify each component (NIST 800-53 Rev5 CM-8 System Component Inventory). Flags assets whose serialNumber is empty so they can be reviewed. Note: intended for hardware CIs; non-serialized items (e.g. software) will surface for review at threshold 1.0. | Every record must satisfy: Model Number has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Catalog Tasks
Test name | Test description | Test logic |
ServiceNow - Catalog Tasks Are Prioritized And Time-Stamped | Confirms each catalog fulfillment task carries a priority and a recorded open date, ensuring change/request work is triaged and traceable. Supports NIST SP 800-53 Rev. 5 CM-3 and SA-10. Fields: priority (priority.display_value), opened_at (opened_at.value). | Every record must satisfy: Priority has a value and Open Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow - Catalog Tasks Routed To A Fulfillment Group | Confirms each service catalog fulfillment task is assigned to an owning group so that provisioning/change work is tracked to an accountable team. Supports NIST SP 800-53 Rev. 5 CM-3 and SA-10. Field: assignment_group (assignment_group.display_value). | Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow Catalog Tasks Are Routed To An Assignment Group | Every catalog/fulfillment task must be assigned to a responsible team so change and service work is owned and actioned (NIST 800-53 Rev5 CM-3 Configuration Change Control / SA-5). Checks that assignment_group is populated on all catalog tasks. | Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
ServiceNow Closed Catalog Tasks Record A Completion Date | Completed change/fulfillment work must have an auditable completion timestamp (NIST 800-53 Rev5 CM-3 Configuration Change Control / AU-3). Implication: unless the state contains 'Closed' the row passes; any Closed catalog task must have closed_at populated. Uses !contains 'Closed' which matches the out-of-the-box Closed Complete/Incomplete/Skipped states. | A record is marked failed when: State contains "Closed" and Closed Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Groups
Test name | Test description | Test logic |
ServiceNow Active Assignment Groups Document Their Purpose | Routes active ServiceNow assignment groups with no description to review. | A record is sent for review when: Active is true and Description is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow Assignment Groups Have An Owner | Every assignment group must have a designated manager/owner accountable for its membership and work (NIST 800-53 Rev5 AC-2 Account Management / PS-2). Flags groups where the manager field is empty. Note: at threshold 1.0 any un-owned group fails, which is the intended finding. | Every record must satisfy: Manager has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Incidents
Test name | Test description | Test logic |
ServiceNow - Closed Incidents Have An Accountable Assignee | Confirms that any incident with a closure timestamp was assigned to an individual owner, establishing accountability for resolved incidents. Open incidents (no closed_at) are not penalized. Supports NIST SP 800-53 Rev. 5 IR-5 and AU-3. Fields: closed_at (closed_at.value, empty when not closed), assigned_to (assigned_to.display_value). | A record is marked failed when: Closed has a value and Assigned To is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow - Incidents Retain An Update Audit Trail | Confirms every incident records who last modified it and when, preserving an audit trail for incident handling. Supports NIST SP 800-53 Rev. 5 AU-3 and IR-4. Fields: sys_updated_by (sys_updated_by.display_value), sys_updated_on (sys_updated_on.value). | Every record must satisfy: Updated By has a value and Updated has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow - Incidents Routed To An Assignment Group | Confirms every incident is routed to an owning assignment group so that response ownership is unambiguous. Supports NIST SP 800-53 Rev. 5 IR-4 and IR-5. Field: assignment_group (assignment_group.display_value). | Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
ServiceNow Critical Incidents Have An Assigned Owner | High-severity incidents must have a named individual accountable for resolution, not just a queue (NIST 800-53 Rev5 IR-4 Incident Handling). Implication: unless priority is the out-of-the-box '1 - Critical' value, the row passes; critical incidents must have assigned_to populated. Note: relies on the default ServiceNow priority label; if an org renames priority choices this check fails open (passes) for renamed values. | A record is marked failed when: Priority equals "1 - Critical" and Assigned To is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow Incident Record Completeness | Incident records must capture the minimum data needed to track and document an event (NIST 800-53 Rev5 IR-5 Incident Monitoring / IR-6 Reporting): an identifier (number), a reporter (caller_id), and a description (short_description). Flags incidents missing any of these required fields. | Every record must satisfy: Number has a value and Short Description has a value and Caller has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow Incidents Are Not Left Open Beyond 90 Days | Flags ServiceNow incidents that remain open more than 90 days after they were raised. This is an ageing check on open incidents: an incident that took longer than 90 days but has since closed is not flagged. | A record is marked failed when: Opened is more than 90 days in the past and Closed is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow Incidents Are Routed To An Assignment Group | Every incident must be assigned to a responsible team so it is triaged and worked, not orphaned (NIST 800-53 Rev5 IR-4 Incident Handling / IR-5 Monitoring). Checks that the assignment_group field is populated on all incidents in the period. | Every record must satisfy: Assignment Group has a value. The test passes only if every record passes. If the proof contains no records, the test is marked passed. |
List of Users
Test name | Test description | Test logic |
ServiceNow Active User Accounts Are Individually Identifiable | Flags active ServiceNow accounts that carry no username or no email address. | A record is marked failed when: Active is true and Username is empty. A record is marked failed when: Active is true and Email is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
ServiceNow Active Users Have MFA Enabled | Enforces multifactor authentication for the ServiceNow platform (NIST 800-53 Rev5 IA-2(1)/IA-2(2)). For every active user (active=true) the enable_multifactor_authn flag must be true; deactivated accounts are exempt. Implemented as an implication (not active OR mfa) so service/deactivated accounts do not cause false failures. | A record is marked failed when: Active is true and MFA Enabled is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Shortcut
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SmartRecruiters
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snowflake
List of Users
Test name | Test description | Test logic |
Snowflake - MFA Enrolled for Active Users | Flags Snowflake user accounts that are still active but are not enrolled in multi-factor authentication. | A record is marked failed when: Disabled is false and MFA is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snowflake - No Active Users With 90-Day Inactivity | Flags Snowflake user accounts that are still active but have not signed in during the last 90 days. | A record is marked failed when: Disabled is false and Last login is more than 90 days in the past. A record is sent for review when: Disabled is false and Last login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users and Roles
Test name | Test description | Test logic |
Snowflake - MFA Enabled For All Active Users | Flags Snowflake user accounts that can still log in but do not have multi-factor authentication enabled. | A record is marked failed when: Disabled is false and MFA is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snowflake - No Active Users With 90-Day Login Inactivity | Flags Snowflake user accounts that can still log in but have not signed in within the last 90 days. | A record is marked failed when: Disabled is false and Last login is empty. A record is marked failed when: Disabled is false and Last login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Time Travel Configuration by Database
Test name | Test description | Test logic |
Snowflake - Time Travel Retention Enabled For Database Objects | Checks that every database, schema, and table in the selected Snowflake database keeps at least one day of Time Travel history so deleted or modified data can be recovered. | Every record must satisfy: Retention time in days is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Time Travel Configuration for Databases
Test name | Test description | Test logic |
Snowflake - Time Travel Retention Enabled For All Databases | Checks that every Snowflake database retains at least one day of Time Travel history so deleted or modified data can be recovered. | Every record must satisfy: Retention time in days is 1 or more. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Snyk
List of Issues
Test name | Test description | Test logic |
Snyk - No Open Critical-Severity Issues | Supports NIST 800-53 Rev5 RA-5 (vulnerability remediation): every open Snyk finding must be below Critical severity, so no unremediated Critical vulnerabilities remain. Checks the 'severity' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Severity does not equal "critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snyk - No Open High or Critical Issues | Supports NIST 800-53 Rev5 RA-5 (risk-based remediation SLA): every open Snyk finding must be below High severity, enforcing that both High and Critical vulnerabilities are remediated. Checks the 'severity' field is neither 'high' nor 'critical'. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Severity is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snyk - No Open IaC Configuration Findings | Supports NIST 800-53 Rev5 CM-6 (configuration settings / secure baseline): Snyk IaC configuration findings must be remediated, so no open finding has issueType 'Configuration'. Checks the 'issueType' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Issue Type does not equal "Configuration". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snyk - No Open SAST (Code) Findings | Supports NIST 800-53 Rev5 SA-11 (developer security testing / static analysis): all Snyk Code (SAST) findings must be resolved, so no open finding has issueType 'Code'. Checks the 'issueType' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Issue Type does not equal "Code". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Snyk - No Suppressed (Ignored) Issues | Supports NIST 800-53 Rev5 RA-5 (suppression governance / risk acceptance): open findings must not be silently suppressed, so no finding has status 'Ignored'. Checks the 'status' field. A proof with no rows is reported as Needs Review, because it cannot distinguish a compliant state from evidence that was never collected. | Every record must satisfy: Status does not equal "Ignored". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users by Org
Test name | Test description | Test logic |
Snyk - Org Members Have Assigned Role and Email | Supports NIST 800-53 Rev5 AC-2 (account management): every Snyk organization member must have both an assigned role (privilege set) and an identifiable email, so no account is unattributed or missing an authorization role. Checks the 'role' and 'email' fields. Empty proof (no members returned) is inconclusive and flagged for review. | Every record must satisfy: Role has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Splunk
List of Alerts
Test name | Test description | Test logic |
Splunk Alerts Shared At App Or Global Scope | Verifies each Splunk alert is shared at app or global scope (not private to a single user) so monitoring coverage persists and stays centrally visible when an individual account is removed. Maps to NIST 800-53 Rev5 SI-4/CM-6, ISO/IEC 27001:2022 A.8.16, SOC 2 CC7.2. Checks the alert sharing scope. | A record is marked failed when: Sharing is none of "GLOBAL" or "APP". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Splunk Security Alerts Are Enabled | Verifies configured Splunk alerts/saved-search alerts are enabled (not disabled) so security monitoring rules are actively evaluating events. Maps to NIST 800-53 Rev5 SI-4/AU-6, ISO/IEC 27001:2022 A.8.16, SOC 2 CC7.2. Checks the alert enabled/disabled status. | Every record must satisfy: Status equals "Enabled". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Triggered Alerts
Test name | Test description | Test logic |
Splunk Triggered Alerts Are Severity Classified | Verifies every triggered/fired Splunk alert carries a valid severity classification (Info, Low, Medium, High or Critical) so security events are categorized for triage and incident response. Maps to NIST 800-53 Rev5 IR-5/AU-6/SI-4, ISO/IEC 27001:2022 A.5.25, SOC 2 CC7.3. Checks the triggered-alert severity. | A record is marked failed when: Severity is none of "Info", "Low", "Medium", "High" or "Critical". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Splunk Accounts Use Centralized Authentication | Verifies Splunk user accounts authenticate through a centralized identity provider (LDAP or SAML) rather than local Splunk-native credentials, enforcing central identity management. Maps to NIST 800-53 Rev5 IA-2, NIST 800-171 3.5.1/3.5.2, ISO/IEC 27001:2022 A.5.16. Checks the account authentication type. | A record is marked failed when: Authentication system is none of "LDAP" or "SAML". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Splunk Dormant User Account Review | Flags Splunk user accounts with no successful login in the last 90 days so dormant/inactive accounts are disabled or reviewed (account management). Maps to NIST 800-53 Rev5 AC-2(3), NIST 800-171 3.1.11, ISO/IEC 27001:2022 A.5.18. Checks last_successful_login. | A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Splunk User Accounts Have Roles Assigned | Ensures every Splunk user account has at least one role assigned so authorization is explicit and there are no orphaned/role-less accounts (account provisioning and access enforcement). Maps to NIST 800-53 Rev5 AC-2/AC-6, NIST 800-171 3.1.1, ISO/IEC 27001:2022 A.5.18. Checks the roles field. | Every record must satisfy: Roles has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
SpotDraft
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
SugarCRM
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Taleez
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
TalentLyft
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Teamleader
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Teamtailor
Application Lifecycle Summary
Test name | Test description | Test logic |
Job Application Records Identify The Candidate, Position, And Application Date | Checks that each job application record identifies the candidate by email, names the position applied for, and records the date the application was received. | Every record must satisfy: Candidate Email has a value and Job Title has a value and Applied Date has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Teamwork
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tellent Recruitee
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable
Access Group
Test name | Test description | Test logic |
Access Group Entries Are Fully Provisioned | NIST 800-53 Rev5 AC-3 / AC-6: every access group principal entry must be fully defined (name, principalName, principalPermissions present) and the group build must be complete (status COMPLETED). Fields: name, principalName, principalPermissions, status. | Every record must satisfy: Name has a value and Principal Name has a value and Principal Permissions has a value and Status equals "COMPLETED". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Access Groups Do Not Grant To All Users | NIST 800-53 Rev5 AC-6 (Least Privilege): no access group entry may grant access to the broad all_users principal; each principalType must be a scoped user or group. Field: principalType (emitted values user, group, all_users). | Every record must satisfy: Principal Type does not equal "all_users". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable - Access Groups Reviewed/Updated Within 365 Days | Verifies each Tenable access group configuration has been reviewed or updated within the last 365 days, evidencing periodic access-control review (NIST 800-53 Rev5 AC-2, CM-3). Checks the lastUpdated date field and fails any access group not touched within the window. | A record is sent for review when: Last Updated is empty. A record is marked failed when: Last Updated is more than 365 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Export Vulnerabilities
Test name | Test description | Test logic |
Tenable Scans Report No Critical or High Vulnerabilities | NIST SP 800-53 RA-5 / SI-2: vulnerabilities discovered through scanning must be remediated. Verifies that no exported Tenable.io vulnerability finding has a severity of critical or high. | Every record must satisfy: Severity is none of "critical" or "high". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable Vulnerabilities Are Remediated Within 30 Days | NIST SP 800-53 SI-2: flaws must be remediated within an organization-defined timeframe. Flags any Tenable.io vulnerability whose first-found date is more than 30 days in the past. | A record is sent for review when: First Found is empty. A record is marked failed when: First Found is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerability Findings Have Triage Metadata | NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring): each exported vulnerability finding must carry the metadata required to triage and remediate it - the affected asset, the detecting plugin, and a severity. Fields: assetName, pluginName, severity. | Every record must satisfy: Asset Name has a value and Plugin Name has a value and Severity has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Access Control Permissions
Test name | Test description | Test logic |
Access Control Permissions Are Fully Attributed | NIST 800-53 Rev5 AC-2 (Account Management): every access-control permission entry must be attributable for review - it must name the permission, the granted permissions, and the objects it applies to. Fields: name, permissions, objects. | Every record must satisfy: Name has a value and Permissions has a value and Objects has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Admin Impersonation Permissions Granted | NIST 800-53 Rev5 AC-6 (Least Privilege): access-control permission entries must not carry the privileged CanImpersonateAdmin action, which allows acting as an administrator. Field: permissions (comma-joined action display names, e.g. CanScan, CanView, CanImpersonateAdmin). | Every record must satisfy: Permissions does not contain "CanImpersonateAdmin". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable - Access Permissions Are Assigned to a User or Group | Verifies each Tenable access-control permission has at least one grantee (user or group) so no orphaned/unassigned permission entries exist (NIST 800-53 Rev5 AC-2, AC-6). Checks the users and groups text fields, which Tenable populates with 'No Users'/'No Groups' when a permission has no subjects. | A record is marked failed when: Users equals "No Users" and Groups equals "No Groups". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable - Access Permissions Are Scoped, Not Granted Over All Assets | Verifies each Tenable access-control permission is scoped to specific objects rather than the blanket All Assets scope, enforcing least privilege (NIST 800-53 Rev5 AC-6). Checks the objects text field (Tenable joins object names/types) and fails any permission whose scope includes AllAssets. | Every record must satisfy: Objects does not contain "AllAssets". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable - Access Permissions Define Explicit Actions | Verifies each Tenable access-control permission grants at least one explicit action rather than an empty/misconfigured grant, supporting deliberate least-privilege configuration (NIST 800-53 Rev5 AC-6, CM-6). Checks the permissions text field, which Tenable populates with 'No Actions' when a permission has no actions. | Every record must satisfy: Permissions does not equal "No Actions". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Assets
Test name | Test description | Test logic |
Tenable Asset Inventory Records Are Complete | NIST SP 800-53 CM-8: system component inventory must record identifying attributes for each asset. Verifies every Tenable.io asset records a hostname, IP address, and operating system. | Every record must satisfy: Name has a value and IP Address has a value and Operating System has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable Assets Have Been Observed Within the Last 90 Days | NIST SP 800-53 CA-7 / RA-5: continuous monitoring and vulnerability scanning. Flags any Tenable asset whose last seen date is more than 90 days ago, indicating it is no longer being observed by the platform. | A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable Vulnerability Management - Assets Seen Within 30 Days | Checks that every Tenable asset has been seen by a scanner, agent, or connector within the last 30 days and flags stale inventory entries. | A record is sent for review when: Last Seen is empty. A record is marked failed when: Last Seen is more than 30 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Attestations
Test name | Test description | Test logic |
PCI ASV Attestations Are Passing | NIST 800-53 Rev5 RA-5 (Vulnerability Monitoring) / PCI DSS ASV: each PCI ASV scan attestation must be in a passed state. Field: status (emitted value passed for a passing attestation). | Every record must satisfy: Status equals "passed". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Tenable - PCI ASV Attestation Scan Is Not Expired | Verifies each Tenable PCI ASV attestation still has a valid (non-expired) scan so vulnerability-scan coverage remains current (NIST 800-53 Rev5 RA-5). Checks the scan_expiration_date field and fails any attestation whose expiration date is in the past. | A record is sent for review when: Scan Expiration is empty. A record is marked failed when: Scan Expiration is more than 0 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable - PCI ASV Attestations Updated Within 90 Days | Verifies each Tenable PCI ASV attestation has been updated within the last 90 days, evidencing the required quarterly ASV scan cadence (NIST 800-53 Rev5 RA-5(2), CA-2). Checks the updated_at date field and fails any attestation not refreshed within the window. | A record is sent for review when: Updated On is empty. A record is marked failed when: Updated On is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable PCI ASV Attestation Records Are Complete | NIST SP 800-53 CA-2 / RA-5: assessment and scan results must be documented and tracked. Verifies every Tenable.io PCI ASV attestation record includes a name, identifier, and status. | Every record must satisfy: Name has a value and Id has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Users
Test name | Test description | Test logic |
Tenable Enabled Users Are Not Locked Out | NIST SP 800-53 AC-7: locked-out accounts indicate repeated failed authentication that requires review. Verifies that every enabled Tenable.io user account is not in a locked-out state. | A record is sent for review when: Enabled is empty. A record is sent for review when: Lockout is empty. A record is marked failed when: Enabled is true and Lockout is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Tenable User Records Include Name, Username, and Email | NIST SP 800-53 AC-2: account management requires complete, identifiable account records. Verifies every Tenable.io user record includes a display name, username, and email address. | Every record must satisfy: Name has a value and Username has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
User Accounts Show Recent Login Activity | NIST 800-53 Rev5 AC-2(3) (Disable Inactive Accounts): every user account must have logged in within the last 90 days; accounts idle longer than 90 days are flagged for review or disablement. Field: lastLogin (ISO date). | A record is sent for review when: Last Login is empty. A record is marked failed when: Last Login is more than 90 days in the past. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
UAR Application
Test name | Test description | Test logic |
Tenable User Access Review Records Are Complete | NIST SP 800-53 AC-2 and AC-6: periodic access reviews require complete records of access and assigned role. Verifies every Tenable.io user access review record includes an owner, username, email, and role. | Every record must satisfy: Owner has a value and Username has a value and Email has a value and Role has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Traffit
User Account Lifecycle
Test name | Test description | Test logic |
Deleted ATS Accounts Are Deactivated | Flags user accounts that the source system reports as deleted but that are still marked active. | A record is marked failed when: Deleted is true and Active is true. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Trello
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
vtiger
List of Users
Test name | Test description | Test logic |
CRM User Accounts Are Attributable To A Named Individual | Checks that every CRM user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Wallarm
List of Users
Test name | Test description | Test logic |
Wallarm No Stale Or Dormant User Logins | Detects dormant/stale Wallarm console accounts: every user must have a last_login_time that is present and within the last 180 days. Accounts that have never logged in (empty last_login_time) or have not logged in for more than 180 days are flagged for disable/removal review. NIST SP 800-53 Rev 5 AC-2(3) Disable Accounts / AC-2 Account Management. Fields checked: last_login_time (userList). | A record is marked failed when: Last Login is more than 180 days in the past. Every record must satisfy: Last Login has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wallarm Users Have Valid Email Identity | Identity assurance: every Wallarm user account must be tied to a well-formed email address ([email protected]) so access maps to a real, attributable identity rather than a shared/orphaned login. NIST SP 800-53 Rev 5 IA-4 Identifier Management / AC-2 Account Management. Regex is JS+.NET safe and case-explicit. Fields checked: email (userList). | Every record must satisfy: Email Address is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Scanner State
Test name | Test description | Test logic |
Wallarm Scanner Active And Next Scan Scheduled | Active monitoring, not just deployed: the scanner must not be administratively disabled (state present and not 'disabled') and must have an upcoming scan scheduled within the next 30 days (next_scan_time present and less than 30 days from now). A disabled scanner or an indefinitely-deferred next scan means protection is effectively off. NIST SP 800-53 Rev 5 SI-4 System Monitoring / SC-7 Boundary Protection. Fields checked: state, next_scan_time (scannerState). | Every record must satisfy: State has a value. Every record must satisfy: State does not equal "disabled". Every record must satisfy: NextScanTime is less than 30 days in the future. Every record must satisfy: NextScanTime has a value. A record is marked failed when: NextScanTime is more than 0 days in the past. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Wallarm Scanner Completed A Recent Scan | Continuous monitoring cadence: the Wallarm scanner must have completed a scan within the last 7 days (last_scan_time present and not more than 7 days ago). A stale or absent last scan means external attack-surface discovery has lapsed. NIST SP 800-53 Rev 5 CA-7 Continuous Monitoring / SI-4 System Monitoring / RA-5 Vulnerability Scanning. Fields checked: last_scan_time (scannerState). | A record is marked failed when: LastScanTime is more than 7 days in the past. Every record must satisfy: LastScanTime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Wallarm Scanner Vulnerability Detection Is Current | Vulnerability scanning frequency: the Wallarm scanner's last vulnerability detection run (last_vuln_time) must be present and within the last 30 days, proving the vulnerability engine is actively running on the defined schedule. NIST SP 800-53 Rev 5 RA-5 Vulnerability Monitoring and Scanning / SI-4 System Monitoring. Fields checked: last_vuln_time (scannerState). | A record is marked failed when: LastVulnTime is more than 30 days in the past. Every record must satisfy: LastVulnTime has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Wave Financial
Chart of Accounts
Test name | Test description | Test logic |
Chart Of Accounts Contains No Suspense Or Uncategorized Accounts | Flags general ledger accounts named as suspense or uncategorized holding accounts, which can conceal unreconciled activity. | Every record must satisfy: Account Name does not match the pattern "[Ss][Uu][Ss][Pp][Ee][Nn][Ss][Ee]|[Uu][Nn][Cc][Aa][Tt][Ee][Gg][Oo][Rr][Ii][SsZz][Ee][Dd]|[Aa][Ss][Kk] [Mm][Yy] [Aa][Cc][Cc][Oo][Uu][Nn][Tt][Aa][Nn][Tt]". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Chart Of Accounts Entries Have An Account Number And Name | Confirms every account in the chart of accounts has both an account number and an account name. | Every record must satisfy: Account Number has a value and Account Name has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Vendor and Customer Master Lists
Test name | Test description | Test logic |
Vendor And Customer Master Records Are Named And Classified | Checks that every vendor or customer on the master list has a name and is classified as a supplier or a customer rather than left unidentified. | Every record must satisfy: Entity Name has a value and Entity Type does not equal "Unknown". The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Wiz
List of Users
Test name | Test description | Test logic |
Wiz Console Accounts With No Sign-In In 90 Days | Flags non-suspended Wiz console accounts that have not signed in within the last 90 days. | A record is marked failed when: Is Suspended is false and Last Login is more than 90 days in the past. A record is sent for review when: Is Suspended is false and Last Login is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wiz User Accounts Have Identity Attributes | NIST 800-53 Rev5 IA-4 / AC-2: identifier management requires every account to have the attributes needed to attribute it to a person or service. Verifies name and email are populated on each Wiz user. Fields: name, email (emitted directly by the users GraphQL query / proof spec). | Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wiz User Accounts Have Name and Email Identifiers | NIST 800-53 Rev5 AC-2 / IA-4 (account management and identifier assignment): fails any Wiz console user account missing a display name or a valid email address (must contain '@'), so every account maps to an identifiable, contactable owner. | Every record must satisfy: Name has a value and Email contains "@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wiz User Email Is Well-Formed | NIST 800-53 Rev5 IA-4 / AC-2: account identifiers must be valid so notifications and access reviews reach the correct owner. Verifies each user's email matches a basic [email protected] structure. Regex uses no letters or inline flags so it is case-agnostic and parses in both.NET and JS. Field: email (emitted directly by the users GraphQL query / proof spec). | Every record must satisfy: Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Vulnerabilities
Test name | Test description | Test logic |
No Critical Vulnerabilities Marked as Rejected | NIST 800-53 Rev5 RA-5 / CA-5 (risk acceptance requires review): fails any finding whose cvssSeverity is CRITICAL while its findingStatus is REJECTED, surfacing critical findings that were dismissed/risk-accepted without going through a documented POA&M review. | A record is marked failed when: CVSS Severity equals "CRITICAL" and Finding Status equals "REJECTED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
No Open Critical Vulnerabilities | NIST 800-53 Rev5 RA-5 (vulnerability remediation): fails any finding whose cvssSeverity is CRITICAL while its findingStatus is still OPEN, so unremediated critical vulnerabilities are surfaced. Resolved criticals and lower-severity findings pass. | A record is marked failed when: CVSS Severity equals "CRITICAL" and Finding Status equals "OPEN". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
No Open High-Severity Vulnerabilities | NIST 800-53 Rev5 RA-5 (remediate within severity-based SLA): fails any finding whose cvssSeverity is HIGH while its findingStatus is still OPEN, tracking the high-severity remediation queue separately from criticals. Resolved highs and other severities pass. | A record is marked failed when: CVSS Severity equals "HIGH" and Finding Status equals "OPEN". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Resolved Vulnerabilities Record a Resolution Date | NIST 800-53 Rev5 RA-5 / CA-5 (remediation is documented): fails any finding whose findingStatus is RESOLVED but has no resolvedAt date, so remediation of a closed finding is evidenced with a resolution timestamp. Open/in-progress findings are not required to have a resolution date and pass. | A record is marked failed when: Finding Status equals "RESOLVED" and Resolved At is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerability Findings Are Attributed to an Asset and Subscription | NIST 800-53 Rev5 CM-8 / RA-5 (component inventory and remediation ownership): fails any finding missing an assetName or subscriptionName, so every vulnerability is tied to an identifiable asset and cloud subscription accountable for remediation. | Every record must satisfy: Asset Name has a value and Subscription has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerability Findings Carry a Valid Severity Rating | NIST 800-53 Rev5 RA-5 / RA-3 (findings categorized by risk): fails any finding whose cvssSeverity is not one of the recognized ratings CRITICAL/HIGH/MEDIUM/LOW/NONE, catching blank or unclassified findings that would escape severity-based triage. | A record is marked failed when: CVSS Severity is empty. A record is marked failed when: CVSS Severity is none of "CRITICAL", "HIGH", "MEDIUM", "LOW" or "NONE". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Vulnerability Findings Have a Valid Remediation Status | NIST 800-53 Rev5 RA-5 (track findings to remediation): fails any finding whose findingStatus is not one of the defined workflow states OPEN/IN_PROGRESS/RESOLVED/REJECTED, ensuring every finding is in a tracked remediation state rather than a blank or unknown status. | A record is marked failed when: Finding Status is empty. A record is marked failed when: Finding Status is none of "OPEN", "IN_PROGRESS", "RESOLVED" or "REJECTED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wiz Vulnerability Findings Have Required Identity | NIST 800-53 Rev5 RA-5 / CM-8: every vulnerability finding must carry the identifying metadata needed to triage and track remediation. Verifies id, name, and cvssSeverity are populated on each finding. Fields: id, name, cvssSeverity (all always emitted by the vulnerabilities transform). | Every record must satisfy: ID has a value and Name has a value and CVSS Severity has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Workable
Application Lifecycle Summary
Test name | Test description | Test logic |
Rejected Job Applications Record A Reject Reason | Flags job applications that were rejected without a documented reason for the rejection. | A record is marked failed when: Rejected Date has a value and Reject Reason is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Account Lifecycle
Test name | Test description | Test logic |
ATS User Records Attributable And Role Assigned | Checks that every user record has a name, email, unique identifier, and an assigned access role. | Every record must satisfy: Name is not blank and Email is not blank and Remote ID is not blank and Access Role is not blank. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Workday
List of Employees
Test name | Test description | Test logic |
Employee Department Assignment Present | Organizational placement for access grouping and data ownership: every worker on the Workday roster is assigned to a department, supporting role/group-based access and asset ownership attribution. Checks textField.department is non-empty. Maps to NIST 800-53 Rev5 AC-2 (organizational account grouping) and ISO/IEC 27001:2022 Annex A A.5.9 (inventory of associated assets/owners). | Every record must satisfy: Department has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Employee Onboarding Start Date Recorded | Joiner-lifecycle record-keeping: every worker on the Workday roster has a recorded employment start date, establishing the authoritative provisioning/onboarding date used to time access grants. Checks dateField.startDate is non-empty. Maps to ISO/IEC 27001:2022 Annex A A.5.16 (identity lifecycle) and A.6.1 (screening/onboarding), and GDPR Art.30 (records of processing for HR data). | Every record must satisfy: Start Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Employee Roster Identity Completeness | Access-governance completeness: every worker on the Workday employee roster has both a name and an email so each account can be uniquely identified and reconciled during access reviews. Checks textField.name and textField.email are non-empty. Maps to NIST 800-53 Rev5 AC-2 (account management / identification), ISO/IEC 27001:2022 Annex A A.5.16 (identity management), and SOC 2 CC6.1. | Every record must satisfy: Name is not blank and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Employees with Status Change
Test name | Test description | Test logic |
Active Employee Status Termination Integrity | Account-status data integrity for joiner/mover/leaver events: no worker is simultaneously flagged active while carrying a termination (end) date, which would indicate a stale or contradictory account state that could leave access provisioned after departure. A row fails when the worker's status is ACTIVE and an end date is nonetheless recorded. Maps to NIST 800-53 Rev5 AC-2 (account management integrity) and SOC 2 CC6.2. | A record is marked failed when: Status equals "ACTIVE" and End Date has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Terminated Employee Offboarding Date Recorded | Leaver-lifecycle control: any worker in the personnel-status-change proof who is no longer active must have a recorded end date, evidencing that a termination/offboarding date exists to drive timely deprovisioning. A row fails when the worker's status is INACTIVE and no end date is recorded. Maps to NIST 800-53 Rev5 AC-2(3) (disable/remove accounts), ISO/IEC 27001:2022 Annex A A.6.5 (responsibilities after termination), and SOC 2 CC6.2/CC6.3. | A record is marked failed when: Status equals "INACTIVE" and End Date is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Wrike
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Zendesk
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Zendesk Groups Contain No Deleted Entries | Access review hygiene: deleted Zendesk groups must not linger in the membership/role listing, since stale groups obscure who has access to what. Checks listOfGroups deleted boolean. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.18 (Access rights), SOC 2 CC6.2/CC6.3. | Every record must satisfy: Deleted is false. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Zendesk Groups Have A Documented Purpose | Access governance: each Zendesk group (used to scope agent access) must carry a description documenting its purpose so access-rights reviews are meaningful. Checks listOfGroups description. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.18 (Access rights), SOC 2 CC6.3. | Every record must satisfy: Description has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Organizations
Test name | Test description | Test logic |
Zendesk Organizations Have Verified Domain Names | Account provenance / asset inventory: each customer Organization record must declare its domain name(s) so end-user accounts are correctly and automatically mapped to a known organization (prevents mis-scoped access). Checks listOfOrganizations domain_names. Maps to NIST 800-53 Rev5 AC-2 (Account Management), ISO/IEC 27001:2022 Annex A A.5.9 (Inventory of information and associated assets), SOC 2 CC6.1. | Every record must satisfy: Domain Names has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Zendesk Administrator Accounts Flagged For Least-Privilege Review | Least-privilege access review: flags any account holding the elevated 'admin' role so reviewers can confirm each administrator is still justified (agent/end-user roles pass). Requires the 'All roles' List of Users proof variant, which emits the role column. Checks listOfUsers role. Maps to NIST 800-53 Rev5 AC-6 (Least Privilege), CMMC 2.0 / NIST 800-171 3.1.5, ISO/IEC 27001:2022 Annex A A.5.15/A.8.2 (Access control / Privileged access), SOC 2 CC6.3. | Every record must satisfy: Role does not equal "admin". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Zendesk User Accounts Have Complete Identity Attributes | Access review support: every Zendesk user/agent account must have a display name and an email so accounts are attributable to a real identity (no anonymous/orphan accounts). Checks listOfUsers name and email. Maps to NIST 800-53 Rev5 AC-2 (Account Management), CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.16 (Identity management), SOC 2 CC6.1/CC6.2. | Every record must satisfy: Name has a value and Email has a value. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Zendesk User Accounts Use Managed Email Domains | Identity governance / least privilege: Zendesk accounts should authenticate with managed corporate email, not personal free-mail providers (gmail/yahoo/hotmail/outlook/icloud/protonmail), which cannot be centrally deprovisioned. Regex-checks listOfUsers email. Maps to NIST 800-53 Rev5 AC-2, CMMC 2.0 / NIST 800-171 3.1.1, ISO/IEC 27001:2022 Annex A A.5.16 (Identity management), SOC 2 CC6.1. | Every record must satisfy: Email does not match the pattern "@([Gg][Mm][Aa][Ii][Ll]|[Yy][Aa][Hh][Oo][Oo]|[Hh][Oo][Tt][Mm][Aa][Ii][Ll]|[Oo][Uu][Tt][Ll][Oo][Oo][Kk]|[Ii][Cc][Ll][Oo][Uu][Dd]|[Pp][Rr][Oo][Tt][Oo][Nn][Mm][Aa][Ii][Ll])\.[Cc][Oo][Mm]$". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Zoho BugTracker
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
Zoho Desk
List of Groups
Test name | Test description | Test logic |
User Groups Are Named And Their Purpose Is Documented | Checks that every user group has a name, and flags groups with no description so their purpose and membership can be reviewed. | Every record must satisfy: Name is not blank. A record is sent for review when: Description is empty. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
List of Issues
Test name | Test description | Test logic |
Issues Are Identified And Have A Tracked Status | Checks that every ticket in the list has a name and a current status so the work item can be tracked. | Every record must satisfy: Name has a value and Status has a value. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
No Unresolved Issues Older Than 90 Days | Flags tickets created more than 90 days ago that are still not closed, surfacing aging unresolved work. | A record is sent for review when: Created is empty. A record is marked failed when: Created is more than 90 days in the past and Status does not equal "CLOSED". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
List of Users
Test name | Test description | Test logic |
Active Ticketing User Accounts Have An Assigned Role | Flags active ticketing user accounts that carry no assigned role. | A record is marked failed when: Active is true and Roles is empty. The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
Active User Accounts Do Not Use Shared Or Generic Identities | Flags active user accounts whose email suggests a shared, generic, or system identity rather than an individually assigned account. | A record is marked failed when: Active is true and Email contains "admin@". A record is marked failed when: Active is true and Email contains "test@". A record is marked failed when: Active is true and Email contains "shared@". A record is marked failed when: Active is true and Email contains "service@". A record is marked failed when: Active is true and Email contains "guest@". The test passes only if every record passes. If the proof contains no records, the test is sent for review. |
User Accounts Are Attributable To A Named Individual | Checks that every user account has a name and a valid email address, so each account can be traced back to a real person. | Every record must satisfy: Name is not blank and Email is a well-formed email address. The test passes only if every record passes. If the proof contains no records, the test is marked failed. |
