- Severity
- MODERATE
- Status
- OPEN
- Owner
- Cloud Platform Team
- Root cause
- Configuration
- Test failure
- Design assessment (CDA)
- Opened
- 2026-04-20
- Due
- 2026-10-31
- Closed
- —
72 days old as of 2026-07-01
Cloud IAM policies rely on manual review rather than automated guardrails.
PARTIAL
tested 2026-04-15
This issue records a CDA failure, shown first.
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the guardrail policy definitions; confirm they cover the cloud security baselines the organization requires.
- 2.Confirm the guardrails are enforced as a deployment-time gate rather than a post-deployment detective check.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Attempt to deploy a non-compliant test resource and confirm the guardrail blocks it.
- 2.Select 25 production deployments across the period and confirm none bypassed the guardrail policy.
- 3.Review guardrail policy change logs to confirm no unauthorized weakening occurred during the period.
Related issues
Same root cause or a shared entity
Score contribution
Issue-pressure points as of 2026-07-01, before the factor is capped at 0–100.
- Cloud Infrastructure Program12 of 37 pts
32.4% of this entity’s issue pressure
Annual priority score: 65 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- MODERATE severity: 12
Linked entities
- Cloud Infrastructure Program
PROGRAM · HIGH