← Inspection rules
SEC-002 / v1.2.0 / 2026-10-02
Inspect MFA methods and coverage
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Human access to administration, SSO, and data platforms. Inspect service identities separately.
Where to look first
- IdP/SaaS policies and contractor accounts
- Recovery methods, exceptions, administrator authentication
Inspection steps
- Check enforcement for administrators, contractors, exceptions, and unenrolled accounts.
- Inspect repeated-prompt and phishing controls, including recovery paths.
Remediation direction
- Adopt phishing-resistant authentication where supported; assign an owner and expiry to exceptions.
Evidence required for completion
- Record coverage and evidence that administrative access without required authentication is rejected.
Limits and unverified scope
- MFA does not guarantee protection against compromised endpoints or stolen sessions. Missing IdP access means unverified.