- Severity
- CRITICAL
- Status
- IN PROGRESS
- Owner
- Identity Engineering
- Root cause
- Access management
- Test failure
- Design assessment (CDA)
- Opened
- 2026-04-05
- Due
- 2026-07-31
- Closed
- —
87 days old as of 2026-07-01
Three service accounts with domain admin rights lacked owners and password rotation.
PARTIAL
tested 2026-01-20
This issue records a CDA failure, shown first.
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the JML deprovisioning procedure; confirm it defines the 24-hour SLA and the HR trigger events (termination, transfer) that initiate it.PR.AA-01
- 2.Confirm the deprovisioning workflow is triggered automatically from the HR system of record rather than a manual notification.
- 3.Walk through the JML workflow configuration to confirm access across all in-scope systems is included, not just the primary directory.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 terminations and transfers across the period and confirm access was removed within 24 hours.
- 2.For sampled transfers, confirm access appropriate only to the prior role was removed even where some access correctly carried forward.PR.AA-01
- 3.Confirm any deprovisioning that missed the SLA was identified and escalated.
Related issues
Same root cause or a shared entity
Score contribution
Issue-pressure points as of 2026-07-01, before the factor is capped at 0–100.
- Enterprise IAM Platform40 of 79 pts
50.6% of this entity’s issue pressure
Annual priority score: 62 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- CRITICAL severity: 40
Linked entities
- Enterprise IAM Platform
APPLICATION · CRITICAL