‹ Back to Act

Risk / detail

ACME Corp

Enforce phishing-resistant MFA on all privileged + cloud-admin roles

Score impact
+7 posture
Loss avoided (ALE)
$1.8M
Effort
~1 week · Cloud Platform
Frameworks satisfied
3

Plan

4 steps
  1. Inventory privileged + service-principal roles reaching the CDE/PHI
  2. Enforce phishing-resistant (FIDO2) MFA on those roles
  3. Remove the break-glass bypass; document the emergency path
  4. Capture enforcement evidence → auto-maps to PCI/FedRAMP/NIST

Closes

critical
MFA not enforced for privileged cloud access
View the exposure →

Satisfies — one fix, many frameworks

Because every control maps through the CSF hub, completing this single action posts evidence to all 3 frameworks at once — no duplicate work.