← Inspection rules

SEC-002 / v1.2.0 / 2026-10-02

Inspect MFA methods and coverage

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Human access to administration, SSO, and data platforms. Inspect service identities separately.

Where to look first

  • IdP/SaaS policies and contractor accounts
  • Recovery methods, exceptions, administrator authentication

Inspection steps

  1. Check enforcement for administrators, contractors, exceptions, and unenrolled accounts.
  2. Inspect repeated-prompt and phishing controls, including recovery paths.

Remediation direction

  • Adopt phishing-resistant authentication where supported; assign an owner and expiry to exceptions.

Evidence required for completion

  • Record coverage and evidence that administrative access without required authentication is rejected.

Limits and unverified scope

  • MFA does not guarantee protection against compromised endpoints or stolen sessions. Missing IdP access means unverified.

Additional references