Deterministic domain assessment

Turn one security domain into an evidence-led improvement plan.

Choose a domain, record current control status and evidence references, then export a risk-ranked plan. No answers, evidence or identifiers leave this page.

IDP-01critical

Authoritative identity lifecycle

Joiner, mover and leaver events reconcile against active accounts and access within approved timeframes.

Expected evidence: authoritative roster reconciliation; termination sample; exception register

IDP-02critical

Privileged access boundary

Privileged access is vaulted or just-in-time, individually attributable and independently reviewed.

Expected evidence: privileged account inventory; PAM session records; break-glass test

IDP-03high

Access certification

Business owners periodically certify sensitive roles, groups, applications and service identities.

Expected evidence: certification campaign; owner decisions; revocation evidence

IDP-04high

Identity detection and containment

Risky sign-ins, token theft, MFA abuse and privilege changes produce owned investigations and reversible response.

Expected evidence: identity detection coverage; triage record; session revocation test