Control areas
Security should be evaluated across the complete solution boundary.
The exact controls and responsible party vary by product, deployment, integration, infrastructure, service,
and signed agreement.
01
Identity and access
Authentication, identity sources, roles, permissions, privileged access, account lifecycle,
administrative actions, and user responsibility.
- Role and permission design
- Administrative access
- Account provisioning and removal
- Identity-provider integration where applicable
02
Application and data
Secure application behavior, validation, authorization, session handling, data access, exports, logging,
integrations, and configuration.
- Authorization at relevant functions
- Input and output handling
- Data-flow and integration review
- Environment-appropriate logging
03
Infrastructure and operations
Hosting boundary, network and platform controls, secrets, patching, monitoring, backup responsibilities,
support access, and operational change.
- Environment ownership
- Platform and dependency maintenance
- Operational access and monitoring
- Backup and recovery responsibilities