| Roles undefined | 24 | 27 | APRA CPS 230 Operational Risk Management, APRA CPS 234, AWS Well-Architected Security Pillar |
| findings not remediated | 14 | 17 | AS9100D, AS9100D:2016, ASIC Cyber Resilience Good Practices |
| no annual review | 13 | 26 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Australian Information Security Manual, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Bundled consent | 12 | 12 | Code of Conduct on Data Protection for Research (GDPR Article 40), LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
| Tooling fragmented Event wagering systems: technical certification and operational audit, Farm assurance: food safety, workers, environment, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle | 11 | 11 | GAMP 5, GHG Protocol, GLI-33 |
| No retention schedule Digital investigation processes, Emergency management, business continuity and crisis management programs, Organizational resilience: security, preparedness and business continuity management | 10 | 11 | APPI, ASIS SPC.1-2009, Bermuda Personal Information Protection Act 2016 (PIPA) |
| No withdrawal mechanism | 10 | 10 | Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) |
| no ongoing monitoring IT risk management supervision of financial institutions and technology service providers, Insurance cybersecurity, PIN and cryptographic key security for payment transactions | 9 | 21 | C-TPAT, C2M2, FFIEC IT Examination Handbook |
| Objectives not measurable IT service management, Organizational resilience: security, preparedness and business continuity management, Privacy risk management | 9 | 20 | AS9100D:2016, ASIS SPC.1-2009, ISO 28001:2007 Supply Chain Security Management |
| No sanctions exposure analysis | 9 | 9 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 172-13 on the Protection of Personal Data |
| Flat networks | 8 | 40 | Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, FFIEC IT Examination Handbook |
| no executive sponsor Data quality management, PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption | 8 | 17 | API 1164, ISO 8000, NIST SP 800-161 |
| no trend analysis | 8 | 13 | BRCGS Global Standard for Food Safety Issue 9, FFIEC IT Examination Handbook, IEC 62304:2015 Medical Device Software Lifecycle Processes |
| No inventory | 8 | 9 | Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22739:2024, ISO 26000:2010 |
| Pipeline not tracked Banking supervision, Event wagering systems: technical certification and operational audit, Financial privacy | 8 | 9 | GLBA, GLI-33, GRI Standards |
| No insider threats Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| no withdrawal mechanism | 8 | 8 | Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) |
| Tactical only Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| Catalogue not refreshed Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| Coverage gaps for in scope entities or systems | 7 | 27 | UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010 |
| Procedure exists but execution inconsistent | 7 | 27 | UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010 |
| Owner accountability not codified | 7 | 27 | UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010 |
| Review cadence missed or undocumented | 7 | 27 | UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010 |
| Flat network | 7 | 9 | AWS Well-Architected Security Pillar, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 |
| Multi-framework alignment ad-hoc Banking supervision, Financial customer information security | 7 | 9 | FTC GLBA Safeguards Rule (16 CFR Part 314), GHG Protocol, GRI Standards |
| Reviews skipped AI risk management | 7 | 8 | COBIT 2019, EASA Part-IS, FFIEC IT Examination Handbook |
| Indefinite retention Data protection and privacy, Personal information protection | 7 | 8 | African Union Malabo Convention, Armenia Law on Protection of Personal Data (2015), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) |
| No review cadence | 7 | 8 | COBIT 2019, ISO 28001:2007 Supply Chain Security Management, ISO/IEC 27003:2017 |
| Transfer without lawful basis | 7 | 7 | LGPD, Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 172-13 on the Protection of Personal Data |
| Findings not closed Food safety and quality management certification, Whistleblowing management | 7 | 7 | BRCGS Global Standard for Food Safety Issue 9, FSSC 22000, ISO 37001 |
| No appeals path | 7 | 7 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| Late responses | 7 | 7 | NIST SP 800-122, Nebraska Data Privacy Act, Netherlands GDPR Implementation Act (UAVG |
| Register stale | 7 | 7 | FBI CJIS Security Policy, FFIEC Cybersecurity Assessment Tool (CAT), ISO 27019 |
| No certification | 7 | 7 | Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Missing training | 7 | 7 | BS 65000:2014, NIS2 Directive, NIST Privacy Framework |
| No age verification Biometric privacy, Data protection and privacy | 7 | 7 | Illinois Biometric Information Privacy Act (BIPA), Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Nebraska Data Privacy Act |
| No encryption | 7 | 7 | C2M2, LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| ROPA incomplete | 7 | 7 | BSI IT-Grundschutz, LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| IP register incomplete, ownership disputes likely Business continuity management, Energy management, Facility management | 6 | 19 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Time allocation for innovation crowded out by BAU Business continuity management, Energy management, Facility management | 6 | 17 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation budget not ring-fenced from operating budget Business continuity management, Energy management, Facility management | 6 | 17 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Strategic intelligence siloed in one team Business continuity management, Energy management, Facility management | 6 | 17 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Competence requirements for innovation roles not defined Business continuity management, Energy management, Facility management | 6 | 16 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Trend scanning is ad hoc and undocumented Business continuity management, Energy management, Facility management | 6 | 16 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Partnership agreements lack IP and confidentiality clauses Business continuity management, Energy management, Facility management | 6 | 16 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Stakeholder map omits external innovation partners (universities, startups) Business continuity management, Energy management, Facility management | 6 | 16 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No resource plan tied to portfolio priorities Business continuity management, Energy management, Facility management | 6 | 15 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Portfolio biased toward horizon 1 incremental projects Business continuity management, Energy management, Facility management | 6 | 14 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Executive sponsorship limited to lip service, no time committed Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Context analysis treated as one-off, not refreshed annually Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation strategy disconnected from corporate strategy Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Opportunities and risks tracked separately with no link to objectives Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Lagging indicators only, no leading indicators Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Tools and methods inconsistent across teams Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No clear accountability for innovation outcomes Business continuity management, Energy management, Facility management | 6 | 13 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Strategic intelligence not feeding into innovation decisions Business continuity management, Energy management, Facility management | 6 | 12 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Evaluation criteria differ across portfolio without rationale Business continuity management, Energy management, Facility management | 6 | 12 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Roles and responsibilities for innovation undefined Business continuity management, Energy management, Facility management | 6 | 12 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation maturity baseline never established Business continuity management, Energy management, Facility management | 6 | 12 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No procedure | 6 | 11 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Inventory incomplete Attestation and assurance standards, Criminal justice information security, Information security measurement | 6 | 11 | FBI CJIS Security Policy, ISO/IEC 27004:2016, ISO/IEC 27011:2024 |
| Internal audits of IMS not scheduled Business continuity management, Energy management, Facility management | 6 | 10 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Governance forum lacks decision-making authority Business continuity management, Energy management, Facility management | 6 | 10 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Risk treatment plans absent for high-uncertainty bets Business continuity management, Energy management, Facility management | 6 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| KPIs measure activity (idea count) not outcomes (revenue, adoption) Business continuity management, Energy management, Facility management | 6 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Customer feedback not systematically captured Business continuity management, Energy management, Facility management | 6 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Root cause analysis stops at symptom level Business continuity management, Energy management, Facility management | 6 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Culture barriers to risk-taking not addressed by leadership Business continuity management, Energy management, Facility management | 6 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Lessons learned stored but never reused Business continuity management, Energy management, Facility management | 6 | 8 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Maturity reassessment skipped year over year Business continuity management, Energy management, Facility management | 6 | 8 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No audit trail | 6 | 7 | Authorised Economic Operator (AEO) Programmes, ISO 27018, ISO 27043 |
| Metrics not tracked Financial privacy, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle | 6 | 6 | French Sapin II Law (Law No. 2016-1691), GAMP 5, GHG Protocol |
| Effectiveness not verified Road traffic safety management, Supply chain security, Whistleblowing management | 6 | 6 | ISO 28001:2007 Supply Chain Security Management, ISO 37002:2021, ISO 37301 |
| No tabletop exercises | 6 | 6 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Kuwait National Cybersecurity Framework |
| Lessons not actioned Business continuity management, Business continuity, supply chain, Digital investigation processes | 6 | 6 | Argyris Double-Loop Learning, ISO 22313:2020, ISO 30401 |
| No periodic review Emergency and incident management, Governance and management of enterprise information and technology, Information security measurement | 6 | 6 | COBIT 2019, ISO 22320:2018, ISO 37002:2021 |
| Metrics gaps | 6 | 6 | GLI-33, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, GS1 Global Standards |
| Design-only testing | 6 | 6 | AS9100D, AS9100D:2016, ISO 13485 |
| Internal traffic between services unencrypted within trusted zones | 5 | 69 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Firewall rule base contains stale allow any entries | 5 | 69 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Server room doors propped open during cooling failures | 5 | 65 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| CCTV coverage gaps at loading docks and equipment delivery areas | 5 | 64 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Access reviews performed but exceptions never remediated | 5 | 60 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Legacy TLS versions remain enabled on external services | 5 | 55 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Role definitions drift from documented matrix without change control | 5 | 55 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Service accounts excluded from periodic recertification | 5 | 51 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Clock drift across hosts breaks event correlation | 5 | 49 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Emergency changes bypass CAB and lack retrospective review | 5 | 49 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Privileged user activity not isolated for independent review | 5 | 49 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Unauthorised software present on endpoints not flagged by tooling | 5 | 48 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Federation trust relationships not reviewed when partnerships change | 5 | 48 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Privileged accounts shared across administrators without individual accountability | 5 | 47 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Cryptographic keys stored alongside the data they protect | 5 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Contractor screening relies on vendor attestation without sampling | 5 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Supplier incidents discovered through news rather than contractual notification | 5 | 44 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| MFA exceptions granted indefinitely without compensating controls | 5 | 43 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Vendor SOC reports collected but exceptions not analysed | 5 | 42 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Environmental sensor alerts route to unmonitored mailboxes | 5 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Tailgating observed without challenge during walkthroughs | 5 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Flat networks expose sensitive workloads without segmentation | 5 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Severity criteria inconsistent across teams leading to under reporting | 5 | 39 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Flow down clauses present in master agreements but missing from statements of work | 5 | 39 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Critical patches deployed beyond the policy SLA without exception | 5 | 38 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Tabletop exercises lack participation from business owners | 5 | 37 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| EDR coverage gaps on legacy operating systems | 5 | 37 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Alternate site capacity not validated against current load | 5 | 37 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Sanctions applied informally without HR documentation | 5 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Baselines exist on paper but production hosts drift without alerting | 5 | 34 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Documentation exists but lacks evidence of periodic refresh | 5 | 34 | South Africa Promotion of Access to Information Act (PAIA), South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Lessons learned captured but corrective actions not tracked to closure | 5 | 34 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Stale accounts retained for terminated personnel beyond the 24 hour SLA | 5 | 34 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Critical log sources missing from the SIEM with no detection coverage | 5 | 34 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Code scan findings closed without verification of fix | 5 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Assessment scope omits inherited cloud provider controls | 5 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Open source components used without SBOM or licence review | 5 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Continuous monitoring metrics collected but not reported to leadership | 5 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Decommissioned drives stored unencrypted while awaiting destruction | 5 | 32 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| USB usage permitted without DLP inspection or encryption | 5 | 32 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Reviewers acknowledge alerts but do not document investigation outcomes | 5 | 30 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Counterfeit detection procedures absent for hardware refresh cycles | 5 | 30 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Position risk designations not reviewed when responsibilities change | 5 | 30 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| RTO and RPO targets undefined for tier two systems | 5 | 30 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Password complexity enforced but reuse not blocked across systems | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Hardening benchmarks applied at build but not re evaluated annually | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Alert backlog exceeds analyst capacity leading to triage delays | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| System security plan not refreshed after material system changes | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Sub tier suppliers not identified for critical components | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Shared accounts authenticate without traceability to individuals | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Detection coverage gaps allow incidents to be discovered externally | 5 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Threat modelling performed inconsistently across product teams | 5 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Security requirements absent from procurement templates for low value buys | 5 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Visitor logs incomplete or escort sign offs missing | 5 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Plan not updated after major architecture changes | 5 | 27 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Termination access removal exceeds documented SLA | 5 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Audit log retention shorter than the policy mandated period | 5 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Background checks not re run when employees move to higher risk roles | 5 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Privacy considerations addressed separately from security planning | 5 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Asset inventory missing cloud workloads and ephemeral resources | 5 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Risk register entries lack named owner or due date | 5 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Rules of behaviour acknowledged once but not refreshed annually | 5 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Vendor engineers granted standing access rather than session based access | 5 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Authorization boundary description does not match the asset inventory | 5 | 23 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Role based training not refreshed when job duties change | 5 | 20 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Default vendor credentials remain on appliances and IoT devices | 5 | 20 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Phishing failures not followed by remedial coaching | 5 | 20 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| POAM items past due without justification or risk acceptance | 5 | 20 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Remote maintenance sessions unmonitored after initial authentication | 5 | 19 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Backups taken but restore tests never performed end to end | 5 | 19 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Third party incident responder retainer expired | 5 | 19 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Maintenance vendors lack signed confidentiality and security clauses | 5 | 19 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Destruction certificates lack serial numbers tying back to inventory | 5 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Media classification labels missing on physical assets | 5 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Anti malware signatures not updated on isolated network segments | 5 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Reauthorization scheduled past the policy required interval | 5 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Vendor risk tier ratings static despite changes in service scope | 5 | 15 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Notification timelines miss jurisdictional regulatory deadlines | 5 | 15 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Contractors and third parties not enrolled in mandatory training | 5 | 15 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Knowledge from past projects not captured or reused Business continuity management, Facility management, Innovation management | 5 | 15 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Maintenance tools not sanitised before removal from secure areas | 5 | 15 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Training content not reviewed annually for current threat trends | 5 | 15 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Backup tapes shipped without tamper evident packaging | 5 | 14 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Input validation handled inconsistently across microservices | 5 | 14 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Unclear escalation thresholds Financial institution cybersecurity self-assessment, Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 5 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Planning artefacts lack version history and approval signatures | 5 | 14 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Architecture diagrams missing third party and SaaS dependencies | 5 | 14 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Long-lived tokens | 5 | 14 | AWS Well-Architected Security Pillar, ISO 27017, ISO 27018 |
| Initiative prioritisation done by HiPPO not criteria Business continuity management, Energy management, Facility management | 5 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Innovation objectives lack measurable targets Business continuity management, Energy management, Facility management | 5 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Recovery untested | 5 | 12 | AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes |
| IMS scope undefined or inconsistent across business units Business continuity management, Energy management, Innovation management | 5 | 11 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Internal capability gaps not assessed against strategy Business continuity management, Energy management, Facility management | 5 | 11 | ISO 22313:2020, ISO 37002:2021, ISO 41001:2018 |
| Management reviews skip innovation as an agenda item Business continuity management, Facility management, Innovation management | 5 | 11 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Benchmarking against peers absent Business continuity management, Energy management, Innovation management | 5 | 10 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Scope unclear | 5 | 9 | GLI-33, HKMA Cyber Resilience Assessment Framework (C-RAF), ISO/IEC 27014:2020 |
| Feedback loops from operations back to strategy missing Business continuity management, Energy management, Innovation management | 5 | 9 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Annual-only review | 5 | 9 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Scope ambiguous | 5 | 9 | Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22000, ISO/IEC 23837 |
| Metrics absent | 5 | 9 | COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook |
| Roadmap not updated when strategy changes Business continuity management, Energy management, Innovation management | 5 | 8 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Improvement register stale, items older than 12 months unactioned Business continuity management, Facility management, Innovation management | 5 | 7 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Unclear roles | 5 | 7 | APRA CPS 234, Azure Security Benchmark, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) |
| Evidence not retained Information security management system auditing | 5 | 7 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| No screening | 5 | 6 | Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes, CMMC 2.0 |
| Findings not remediated | 5 | 6 | ASIC Cyber Resilience Good Practices, BSIMM, Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) |
| no monitoring | 5 | 6 | Azure Security Benchmark, BREEAM, DAMA-DMBOK2 |
| No methodology | 5 | 6 | Azure Security Benchmark, C2M2, ISO/IEC 27004:2016 |
| Annual review skipped Financial customer information security | 5 | 6 | FSSC 22000, FTC GLBA Safeguards Rule (16 CFR Part 314), French Sapin II Law (Law No. 2016-1691) |
| Risk monitoring siloed | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Audit rights never exercised | 5 | 5 | ISO 37001, Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), Serbia Law on Personal Data Protection (2018) |
| Exclusions unjustified | 5 | 5 | AS9100D, AS9100D:2016, ISO 13485 |
| Remediation not tracked | 5 | 5 | Australian Energy Sector Cyber Security Framework (AESCSF), Bermuda Personal Information Protection Act 2016 (PIPA), Botswana Data Protection Act (2024) |
| Module absent | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Marketing without opt-in | 5 | 5 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA |
| Controls not traced to risks | 5 | 5 | AS9100D, AS9100D:2016, ISO 13485 |
| No incident response plan Cybersecurity of networks, critical information infrastructure and network information, Personal information protection | 5 | 5 | BIMCO Cyber Security, C2M2, China Cybersecurity Law (CSL) |
| Missing FedRAMP banner language | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Shared admin accounts Telecommunications information security | 5 | 5 | 3GPP 5G Security Architecture (TS 33.501), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO/IEC 27011:2024 |
| no concentration analysis Financial institution cybersecurity self-assessment, IT risk management supervision of financial institutions and technology service providers, Organizational resilience | 5 | 5 | AASB S2 Climate-related Disclosures, BS 65000:2014, FFIEC Cybersecurity Assessment Tool (CAT) |
| Claims not handled | 5 | 5 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No change triggers | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| No phishing simulation | 5 | 5 | Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Lloyd's Minimum Standards |
| No documented lawful basis Personal data protection | 5 | 5 | African Union Malabo Convention, Danish Data Protection Act (Databeskyttelsesloven), Data Protection Act 2017 |
| Slow response | 5 | 5 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| Emergency maintenance performed without retrospective documentation | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Findings closed without verification Food safety management, Laboratory competence | 5 | 5 | ISO 22000:2018, ISO/IEC 17025:2017, NY DFS 23 NYCRR 500 |
| Effectiveness of corrective action never reviewed Asset management, Environmental management, Sustainable development in communities; management system | 5 | 5 | ISO 14001:2015, ISO 14001:2026, ISO 37101:2016 |
| No closure tracking Aviation, space and defense quality management system on ISO 9001:2015 | 5 | 5 | AS9100D, Argyris Double-Loop Learning, BSIMM |
| no tabletop exercises | 5 | 5 | Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| No key management | 5 | 5 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2, NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) |
| No phishing tests | 5 | 5 | FedRAMP High, FedRAMP Moderate, ISO 27799 |
| No annual training | 5 | 5 | Laos Law on Prevention and Combating Cybercrime (2015), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| no board reporting IT risk management supervision of financial institutions and technology service providers, Whistleblowing management | 5 | 5 | FFIEC IT Examination Handbook, ISO 37002:2021, Kuwait National Cybersecurity Framework |
| register incomplete Criminal justice information security, Health information security, IT risk management supervision of financial institutions and technology service providers | 5 | 5 | FBI CJIS Security Policy, FFIEC IT Examination Handbook, ISO 27799:2025 |
| No independent assurance Business continuity, business impact analysis, Privacy framework | 5 | 5 | ISO 30414:2018, ISO/IEC 29100:2024, ISO/TS 22317:2021 |
| no annual refresh | 5 | 5 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Illinois Biometric Information Privacy Act (BIPA) |
| Nonconformities not logged or trended Energy management, Facility management, Innovation management | 5 | 5 | ISO 37002:2021, ISO 39001:2012, ISO 41001:2018 |
| Shared accounts in use Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements), Supply chain security | 5 | 5 | BSI IT-Grundschutz, Cyber Essentials Plus, ISO 28001:2007 Supply Chain Security Management |
| exclusions undocumented Greenhouse gas accounting, reporting, verification and validation | 5 | 5 | APRA CPS 230 Operational Risk Management, CFTC System Safeguards (17 CFR 37, 38, 39, 49), ISO 14064 |
| Evidence is point in time rather than ongoing Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 4 | 44 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| Policy document exists but lacks evidence of board approval or refresh cycle | 4 | 39 | Solvency II, South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Accountabilities defined on paper but not reflected in performance objectives | 4 | 39 | Solvency II, South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Unmanaged endpoints | 4 | 29 | Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, PCI P2PE, PCI PIN Security |
| Control owner unclear or vacant Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 4 | 22 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| No metric tracks control effectiveness Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 4 | 22 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| No exit plan | 4 | 16 | BSI IT-Grundschutz, PCI P2PE, PCI PIN Security |
| default credentials PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 4 | 16 | NIST SP 800-123, PCI P2PE, PCI PIN Security |
| late notifications PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 4 | 16 | PCI P2PE, PCI PIN Security, PCI SSF |
| MFA not enforced for privileged or remote access Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Shared or generic accounts retained Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Stale or dormant accounts not deprovisioned Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Access reviews skipped or rubber-stamped Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| stale policies | 4 | 13 | DAMA-DMBOK2, PCI P2PE, PCI PIN Security |
| Lessons learned never closed out Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Policy not communicated Aviation information security management, Knowledge management | 4 | 13 | AS9100D:2016, EASA Part-IS, ISO 30401 |
| Forensic readiness lacking outside core systems Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Playbooks untested for major scenarios Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Lessons not shared Information security management system auditing, Sustainable procurement | 4 | 11 | ISO 20400:2017, ISO 45001, ISO 9001 |
| No traceability | 4 | 9 | BSIMM, COBIT 2019, ISO 26262:2018 |
| No independent assessment | 4 | 9 | CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-128 |
| Metrics not tied to outcomes | 4 | 8 | ISO 30401, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Policies past their review date Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 4 | 8 | AS9100D, ASIS SPC.1-2009, Aged Care Quality Standards (Australia) |
| AI inventory missing shadow deployments by business units | 4 | 7 | South Africa Promotion of Access to Information Act (PAIA), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics, Sweden Data Protection Act (Dataskyddslag, 2018:218) |
| Coverage gaps | 4 | 7 | BSIMM, CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, NIST SP 800-171 |
| Innovation policy not formally approved or communicated Facility management, Innovation management, Road traffic safety management | 4 | 7 | ISO 37002:2021, ISO 39001:2012, ISO 41001:2018 |
| no key rotation | 4 | 6 | FFIEC IT Examination Handbook, ISO/IEC 27010:2015, NIST SP 800-171 Rev 3 |
| Corrective actions closed without verifying effectiveness Business continuity management, Innovation management, Road traffic safety management | 4 | 6 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Inventory stale | 4 | 6 | Australian Energy Sector Cyber Security Framework (AESCSF), C2M2, FFIEC Cybersecurity Assessment Tool (CAT) |
| Bias and safety testing not performed at required cadence | 4 | 6 | South Africa Promotion of Access to Information Act (PAIA), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics, Sweden Data Protection Act (Dataskyddslag, 2018:218) |
| Lessons not captured Governance of organizations | 4 | 5 | ISO 37000:2021, ISO 37001, ISO/IEC 27003:2017 |
| Late notification | 4 | 5 | ISO/IEC 27007:2020, NIST SP 800-122, Nigeria Data Protection Regulation (NDPR) |
| No exit confirmation Enterprise risk management | 4 | 5 | ISO 15189:2022, ISO 19011, ISO 27018 |
| No effectiveness check Aviation information security management | 4 | 5 | AS9100D:2016, EASA Part-IS, ISO 19011 |
| Actions not tracked Whistleblowing management | 4 | 5 | ISO 22000, ISO 37001, ISO 37002:2021 |
| No automated-decision opt-out | 4 | 5 | Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| No correction workflow | 4 | 5 | ISO 27018, ISO/IEC 27018:2019, NIST SP 800-53 Rev 5 LOW |
| No verification step | 4 | 5 | FedRAMP High, ISO 22313:2020, ISO 22320:2018 |
| No rollback capability | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Setuid binaries unaudited | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Transfers not inventoried | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Operating criteria not documented for SEUs Business continuity management, Energy management, Facility management | 4 | 4 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No enhanced safeguards Social responsibility | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| All admins see all logs | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Sensitive categories not identified | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Correction requests not actioned | 4 | 4 | AICPA Privacy Management Framework (PMF), Australia Consumer Data Right, Australian Privacy Principles (APPs) |
| Design briefs silent on energy Business continuity management, Energy management, Facility management | 4 | 4 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Timeout over 15 minutes | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No leading indicators Organizational resilience: security, preparedness and business continuity management | 4 | 4 | ASIS SPC.1-2009, ISO 37001, ISO 45001 |
| Non-accredited assessor | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No spam protection | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Command text not captured | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Personal containers unencrypted | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Lock shows live data | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Bluetooth/Wi-Fi enabled by default | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No travel device program | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Children without parental consent | 4 | 4 | LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| no remediation plan Financial institution cybersecurity self-assessment | 4 | 4 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FFIEC Cybersecurity Assessment Tool (CAT), PCI DSS 4.0 |
| No detection rules | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No bastion enforcement | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Configuration drift | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Undocumented sec-admin access | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Split tunneling allowed | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Admins browse with admin | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Inactive accounts active over 35 days | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Multi-theory integration ad-hoc Leadership behaviour: the transformational, transactional and passive-avoidant range and its measurement, Leadership development | 4 | 4 | Full Range Leadership Model (Bass & Avolio), Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework |
| Commissioning does not verify energy performance Business continuity management, Energy management, Facility management | 4 | 4 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Emergency accounts persist | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Processing wrongly scoped out | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Patches exceed SLA | 4 | 4 | NIS2 Directive Implementing Acts, NIST SP 800-123, NIST SP 800-137 |
| Non-FIPS ciphers enabled | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| shadow IT not captured Financial institution cybersecurity self-assessment | 4 | 4 | FFIEC Cybersecurity Assessment Tool (CAT), NIST SP 800-172, NIST SP 800-53 Rev 5 LOW |
| No automated deprovisioning | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No PbD in development | 4 | 4 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| No processor contracts | 4 | 4 | Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| no completion tracking | 4 | 4 | C5 (Germany), Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017 |
| Improvement limited to closing audit findings Anti-bribery management, Food safety management | 4 | 4 | ISO 22000:2018, ISO 37001:2016, ISO 37001:2025 |
| Retention shorter than required | 4 | 4 | ISO 13485, ISO 15189:2022, ISO 19011 |
| Manual inventory | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Siloed plans | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| RTO undefined | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Competence assumed from job title Business continuity management, Organizational resilience: security, preparedness and business continuity management, Privacy information management | 4 | 4 | ASIS SPC.1-2009, ISO 22313:2020, ISO 27701:2019 |
| Sensitive data unencrypted | 4 | 4 | AICPA SOC 3, APRA CPS 234, ASIC Cyber Resilience Good Practices |
| USB unrestricted | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No allowlisting | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Maintenance focused on uptime not energy Business continuity management, Energy management, Facility management | 4 | 4 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No data inventory | 4 | 4 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Controls drift after change | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Unencrypted backups | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No verification | 4 | 4 | FedRAMP High, NIST SP 800-53 Revision 5.1 HIGH, New Jersey Data Privacy Act |
| No session recording Financial institution cybersecurity self-assessment, Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements), Pipeline industrial control systems cybersecurity | 4 | 4 | API 1164, BSI IT-Grundschutz, FFIEC Cybersecurity Assessment Tool (CAT) |
| No remote session logging | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Verification not documented | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Stale notice | 4 | 4 | NIST Privacy Framework, Nebraska Data Privacy Act, New Hampshire Data Privacy Act |
| No sharing review process | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No screenshot evidence | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Consent not demonstrable | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No peer review | 4 | 4 | Argyris Double-Loop Learning, IAIS Insurance Core Principles (ICPs), ISO 27019 |
| No exec sponsor | 4 | 4 | Azure Security Benchmark, ISO 22313:2020, ISO 22318 |
| stale review | 4 | 4 | Azure Security Benchmark, BREEAM, BS 65000:2014 |
| No pre-prod testing | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Requests not actioned | 4 | 4 | Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), Azerbaijan Law on Personal Data (2010), Bermuda Personal Information Protection Act 2016 (PIPA) |
| TI not actioned | 4 | 4 | BSI IT-Grundschutz, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| No defined review cadence | 4 | 4 | Bahrain PDPL, Barbados Data Protection Act 2019, ISO/IEC 27031:2011 |
| No security on CAB | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No PAM session logs | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No post-change testing | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Resources allocated only at start of year Occupational health and safety | 4 | 4 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011 |
| No priority clauses | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No criticality tiers | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No alerts on account changes | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No application control | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No transaction replay | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No rogue detection | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Independent testing only | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Manual ticket-only provisioning | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Definitions not applied | 4 | 4 | Botswana Data Protection Act (2024), Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020) |
| No coordination with HR/legal | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No automated expiry | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Storage reassigned between tenants without sanitisation Cloud PII protection, Cloud information security, Cloud privacy | 4 | 4 | ISO 27017:2015, ISO 27018:2019, ISO/IEC 27017:2026 |
| No remediation tracking | 4 | 4 | BIMCO Cyber Security, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), Security of Critical Infrastructure Act 2018 (SOCI) |
| No documented risk assessment Insurance cybersecurity | 4 | 4 | AICPA SOC 3, C-TPAT, NAIC Insurance Data Security Model Law (MDL-668) |
| no maturity assessment Organizational resilience | 4 | 4 | BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150 |
| No life cycle cost analysis Business continuity management, Energy management, Facility management | 4 | 4 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Internal traffic unencrypted | 4 | 4 | AWS Well-Architected Security Pillar, ISO 27018, NIST Cybersecurity Framework 2.0 |
| No access controls | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Backups never restored | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No risk assessment | 4 | 4 | Australia My Health Records Act 2012, Authorised Economic Operator (AEO) Programmes, NIST Privacy Framework |
| Stack traces exposed | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No continuous monitoring | 4 | 4 | Australia IRAP, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-122 |
| No maturity baseline Innovation management | 4 | 4 | ISO 31000, ISO 37301, ISO 55001 |
| No method statement Occupational health and safety | 4 | 4 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011 |
| No independent ConMon | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Inadequate logging | 4 | 4 | Australian Energy Sector Cyber Security Framework (AESCSF), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, NIST SP 800-123 |
| Untested backups | 3 | 70 | Australian Information Security Manual, Azure Security Benchmark, NERC CIP |
| No awareness training Insurance cybersecurity | 3 | 55 | Australian Information Security Manual, BSIMM, NAIC Insurance Data Security Model Law (MDL-668) |
| compliance nominal not operational | 3 | 24 | Ontario Accessibility for Ontarians with Disabilities Act (AODA), Open Banking Security, OpenSSF Scorecard |
| Logs not centralised | 3 | 21 | Australian Information Security Manual, BSI IT-Grundschutz, TISAX |
| No data classification | 3 | 21 | BSIMM, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Lloyd's Minimum Standards |
| Consent not granular | 3 | 19 | NIST SP 800-53 Rev 5, SOC 2, SSAE 18 |
| single vendor dependency PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| missing AOCs | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| weak forensic preservation PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Time drift on legacy systems Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No tamper-evident protections on logs Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Retention shorter than regulatory minimum Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| weak responsibility matrix PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| expired attestations PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| no card brand contact PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| missing comms tree PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Critical systems not forwarding logs Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| weak key rotation | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| unmanaged endpoints PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Stakeholder needs not refreshed annually | 3 | 13 | AS9100D, ISO/IEC 27003:2017, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| No penetration testing | 3 | 12 | BSIMM, CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 |
| missing risk appetite PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 12 | PCI P2PE, PCI PIN Security, PCI SSF |
| undefined accountability PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security | 3 | 12 | PCI P2PE, PCI PIN Security, PCI SSF |
| No baselines | 3 | 11 | Australian Energy Sector Cyber Security Framework (AESCSF), CMMC 2.0, NIST Privacy Framework |
| No automated drift detection Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 11 | BSI IT-Grundschutz, Belgium CyberFundamentals, NIST SP 1800-32 |
| Logs not reviewed | 3 | 11 | Australia My Health Records Act 2012, BIMCO Cyber Security, CMMC 2.0 |
| Management review skipped Aviation information security management | 3 | 11 | EASA Part-IS, ISO 27005, ISO 31000 |
| Penetration tests scope narrow and exclude key applications | 3 | 11 | COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Audit findings without closure dates | 3 | 10 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| Pseudonymous data treated as out of scope without safeguards review Biometric privacy | 3 | 10 | DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia) |
| Applicability re-run not triggered when revenue mix shifts Biometric privacy | 3 | 10 | DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia) |
| Scan coverage gaps for containerised and ephemeral workloads | 3 | 10 | COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Consumer health data not separated from general sensitive data Biometric privacy | 3 | 10 | DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia) |
| Policy not reviewed annually Food safety and quality management certification | 3 | 10 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 27043 |
| B2B contact data assumed exempt past PA 23-56 effective date Biometric privacy | 3 | 10 | DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia) |
| Continual improvement not demonstrated through EnPIs | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Management review skipped one or more cycles | 3 | 9 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| No threat modelling | 3 | 8 | BSIMM, Canada Artificial Intelligence and Data Act (AIDA), Secure by Design: A Guide for Manufacturers (CISA) |
| High severity vulnerabilities exceed remediation SLA without risk acceptance | 3 | 8 | COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Threat intelligence consumed but not operationalised into detections | 3 | 8 | COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Root cause analysis is symptomatic only | 3 | 8 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| IT and OT response teams not aligned | 3 | 8 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Argyris Double-Loop Learning, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Roles overlap without clear accountable owner Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 8 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Board reporting cadence not formalised Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 8 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Decisions undocumented Digital investigation processes, Governance of information security, Health information security | 3 | 8 | ISO 27799:2025, ISO/IEC 27014:2020, ISO/IEC 27043:2015 |
| Mitigations not tracked | 3 | 7 | ISO/IEC 27014:2020, ISO/IEC 29134:2023, Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) |
| Director and officer awareness thin | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023 |
| Detection coverage not mapped to MITRE ATT&CK | 3 | 7 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| Withdrawal not as easy as granting consent | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard |
| No evidence policies were communicated to staff Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 7 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| Scope boundaries unclear for cloud services Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 7 | AS9100D, ASIS SPC.1-2009, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Cooperation credit strategy absent | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023 |
| Self disclosure protocols undefined | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023 |
| Risk appetite undefined Financial institution cybersecurity self-assessment, Governance and management of enterprise information and technology | 3 | 7 | C2M2, COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT) |
| Children consent thresholds not enforced | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard |
| Tabletop exercises not run in last 12 months | 3 | 7 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| Records lack granularity per processing purpose | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard |
| ICS forensics tooling not in place | 3 | 7 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Argyris Double-Loop Learning, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Bundled consent across distinct purposes | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard |
| Benefits not tracked | 3 | 7 | Authorised Economic Operator (AEO) Programmes, COBIT 2019, ISO 9001 |
| Legal register not refreshed for new enforcement actions | 3 | 7 | UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023 |
| Change management bypasses energy review | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Operational controls not linked to risks | 3 | 6 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| missing legal review | 3 | 6 | Security of Critical Infrastructure Act 2018 (SOCI), Singapore Cybersecurity Act 2018, Singapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) |
| Effectiveness checks not performed | 3 | 6 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Control implemented without explicit link to the EnMS | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| no regulator engagement | 3 | 6 | Azerbaijan Law on Personal Data (2010), Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), Security of Critical Infrastructure Act 2018 (SOCI) |
| Data subject request workflow exceeds statutory response deadlines | 3 | 6 | South Korea ISMS-P, Sweden Data Protection Act (Dataskyddslag, 2018:218), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) |
| Consent capture mechanisms do not record granularity required by law | 3 | 6 | South Korea ISMS-P, Sweden Data Protection Act (Dataskyddslag, 2018:218), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) |
| Change records missing rollback evidence | 3 | 6 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Energy performance impact not assessed | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Environmental excursions not investigated | 3 | 6 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Top management oversight not evidenced | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No life cycle energy assessment for purchases | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Use of deprecated ciphers or self-signed certificates Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Inconsistent encryption coverage across data stores Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No documented rotation schedule Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No SLA tracking | 3 | 5 | COBIT 2019, ISO 27018, ISO/IEC 27004:2016 |
| No periodic monitoring | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Disposal undocumented Attestation and assurance standards | 3 | 5 | HIPAA Security Rule, SOC for Cybersecurity, SSAE 18 |
| Boundaries unclear Automotive functional safety | 3 | 5 | Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 26262:2018, SOC for Cybersecurity |
| No transfer impact assessment performed | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Reliance on adequacy without supplementary measures | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| No simulations | 3 | 5 | FedRAMP High, ISO/IEC 27011:2024, NIST SP 800-53 Revision 5.1 HIGH |
| Sub-processor transfers untracked | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Keys stored alongside encrypted data Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Policy not aligned to control statement | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Procedure undocumented | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| SCCs not updated to current versions | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Responsibilities undefined | 3 | 4 | Botswana Data Protection Act (2024), Brazil Open Finance (Resolução Conjunta No. 1/2020), C2M2 |
| Audit trail incomplete | 3 | 4 | ASEAN Guide on AI Governance and Ethics, French Sapin II Law (Law No. 2016-1691), NIST Cybersecurity Framework 2.0 |
| No attestation | 3 | 4 | Azure Security Benchmark, ISO 27017, NIST SP 800-144 |
| Scrap not physically destroyed | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| Records incomplete Aviation information security management, Criminal justice information security | 3 | 4 | EASA Part-IS, FBI CJIS Security Policy, NIST SP 800-53 Rev 5 |
| Supervisory engagement weak | 3 | 4 | HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM, HKMA TM-G-1 |
| Internal audit coverage skews to financial controls rather than full scope | 3 | 4 | Solvency II, South Korea ISMS-P, Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) |
| Training not refreshed | 3 | 4 | CMMC 2.0, ISO 37001, Samoa Telecommunications Act (2005) |
| Log retention periods inconsistent across systems | 3 | 4 | Solvency II, South Korea ISMS-P, Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) |
| weak governance | 3 | 4 | Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-122 |
| Methodology inconsistent Aviation information security management | 3 | 4 | EASA Part-IS, GHG Protocol, NIST SP 800-171 |
| No access mechanism | 3 | 4 | APPI, Angola Personal Data Protection Law (Law No. 22/11), Argentina Law 25.326 (Personal Data Protection Law) |
| Critique not engaged Leadership development | 3 | 4 | Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework, Hersey & Blanchard Situational Leadership Model |
| No risk appetite statement | 3 | 4 | APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), COBIT 2019 |
| Late changes uncontrolled | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| Sectoral coordination ad-hoc Financial customer information security | 3 | 4 | FTC GLBA Safeguards Rule (16 CFR Part 314), Georgia Law on Personal Data Protection (2012), Ghana Data Protection Act 2012 (Act 843) |
| No flowdown of customer reqs | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No verification vs validation distinction | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No MRB for use-as-is | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| no egress filtering | 3 | 4 | AWS Well-Architected Security Pillar, Azure Security Benchmark, NIST SP 800-171 Rev 3 |
| Supplier de-listing not executed | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No deploy audit trail | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| No SCRM strategy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Logs collected but never reviewed Cloud PII protection, Financial customer information security | 3 | 3 | FTC GLBA Safeguards Rule (16 CFR Part 314), HIPAA Security Rule, ISO 27018:2019 |
| POA&Ms stale | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No data discovery | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Updates not communicated | 3 | 3 | ASEAN Data Management Framework, HIPAA Security Rule, Russia Federal Law on Personal Data (152-FZ) |
| No drift detection Security configuration hardening of DOD information systems | 3 | 3 | DISA Security Technical Implementation Guides (STIGs), ISO 27017, Lloyd's Minimum Standards |
| Role based training not delivered to high risk teams Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 3 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| Contractor competence not verified Asset management, Food safety management | 3 | 3 | ISO 22000:2018, ISO 45001, ISO 55001:2014 |
| No criminal-risk register | 3 | 3 | Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), South Korea PIPA |
| Changes made without change control | 3 | 3 | Annex 11 to EU GMP, Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2 |
| Lessons learned not captured | 3 | 3 | NIST SP 800-128, Space ISAC (Information Sharing and Analysis Center), TISAX |
| Reasonable care defence undocumented | 3 | 3 | Jamaica Data Protection Act 2020, Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kentucky Consumer Data Protection Act |
| Auditors not independent of audited area Laboratory competence | 3 | 3 | ISO 37301, ISO/IEC 17025:2017, ISO/IEC 17025:2017 |
| Corrections applied without a cause analysis Anti-bribery management | 3 | 3 | ISO 37001:2016, ISO 37001:2025, ISO/IEC 27003:2017 |
| corrective actions not tracked to closure | 3 | 3 | ISO/IEC 29100:2024, South Africa Promotion of Access to Information Act (PAIA), US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements |
| Objectives stated as aspirations with no measure Anti-bribery management, Quality plans | 3 | 3 | ISO 10005:2005, ISO 37001:2016, ISO 37001:2025 |
| Effectiveness never reviewed Environmental management, Food safety management, Information security management system auditing | 3 | 3 | ISO 14004:2016, ISO 22000:2018, ISO/IEC 27007:2020 |
| Competence reassessment intervals not defined ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| Corrective actions overdue Emergency management, business continuity and crisis management programs | 3 | 3 | NFPA 1600, TISAX, US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements |
| Indefinite retention by default | 3 | 3 | Israel Protection of Privacy Law (5741-1981), PCI DSS 4.0, Uzbekistan Law on Personal Data (No. ZRU-547) |
| Subject notification skipped (high-risk underestimated) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Lawful mechanism not chosen per transfer | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Thresholds not defined Farm assurance: food safety, workers, environment | 3 | 3 | DAMA-DMBOK2, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, Science Based Targets initiative (SBTi) Corporate Standard |
| Training metrics not reported to leadership Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management | 3 | 3 | AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning |
| Cleaning frequency not based on risk | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Agreements not updated when scope changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Visitor logs incomplete | 3 | 3 | HIPAA Security Rule, NIST SP 800-171, NIST SP 800-53 Rev 5 |
| Monitoring gaps | 3 | 3 | COBIT 2019, FBI CJIS Security Policy, ISO 22000 |
| Disposal informal | 3 | 3 | COBIT 2019, ISO 27043, ISO 27799 |
| No feedback loop | 3 | 3 | COBIT 2019, ISO 20400:2017, Kotter 8-Step Change Model |
| No BCR approval procedure | 3 | 3 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| plan untested | 3 | 3 | AWS Well-Architected Security Pillar, FFIEC IT Examination Handbook, ISO 28001:2007 Supply Chain Security Management |
| No external comms | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| No benchmarking | 3 | 3 | ISO 39001:2012, ISO 45001, ISO 55001 |
| recovery objectives undefined Federal information security governance, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle | 3 | 3 | C2M2, FISMA, GAMP 5 |
| Access granted before screening completes | 3 | 3 | CMMC 2.0, NIST SP 800-171, NIST SP 800-171A |
| No accountability | 3 | 3 | AWS Well-Architected Security Pillar, C2M2, ISO 22000 |
| Processors with no notification duty Data protection and privacy | 3 | 3 | Rwanda DPL, Uruguay DPL, Vietnam PDPD |
| No federation | 3 | 3 | AWS Well-Architected Security Pillar, MARS-E, NIST SP 800-144 |
| No segmentation | 3 | 3 | AWS Well-Architected Security Pillar, BIMCO Cyber Security, Nevada Gaming Control Board Cybersecurity Requirements |
| no risk assessment | 3 | 3 | Australia My Health Records Act 2012, NIST SP 800-144, Saudi Arabia PDPL |
| stale strategy | 3 | 3 | Azure Security Benchmark, NIST SP 800-137, NIST SP 800-161 Rev 1 |
| short retention | 3 | 3 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Azure Security Benchmark, PCI DSS 4.0 |
| keys not rotated | 3 | 3 | C5 (Germany), NIST SP 800-150, PCI DSS 4.0 |
| reviews overdue | 3 | 3 | C5 (Germany), ISO 15189:2022, ISO/IEC 17025:2017 |
| No Whistleblower integration | 3 | 3 | Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) |
| Keys never rotated Aviation information security management, Industrial automation and control system security | 3 | 3 | AWS Well-Architected Security Pillar, EASA Part-IS, IEC 62443 |
| Restore never tested GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle, Health information security | 3 | 3 | CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, GAMP 5, ISO 27799:2025 |
| Training stale | 3 | 3 | ISO 27043, ISO 27799, PCI DSS 4.0 |
| No restore tests | 3 | 3 | ISO 22317, ISO 27019, PCI DSS 4.0 |
| Corrections not actioned | 3 | 3 | Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA), Consumer Data Right (CDR) Framework (Australia) |
| No board visibility Biometric privacy, Organizational resilience | 3 | 3 | BS 65000:2014, Illinois Biometric Information Privacy Act (BIPA), Texas Data Privacy Act |
| No subprocessor visibility | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| No measurement of effectiveness | 3 | 3 | HIPAA Security Rule, ISO/IEC 27007:2020, NIST SP 800-66 Rev 2 |
| No written programme | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Missing notice elements | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Overseas disclosure without safeguards | 3 | 3 | Australia Consumer Data Right, Australian Privacy Principles (APPs), Consumer Data Right (CDR) Framework (Australia) |
| No collection notice | 3 | 3 | Australian Privacy Principles (APPs), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No DPA register | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Selection undocumented Information security management system auditing | 3 | 3 | Canada ITSG-33, ISO/IEC 27007:2020, MARS-E |
| No Board oversight | 3 | 3 | Lloyd's Minimum Standards, Nigeria Open Banking Regulatory Framework (CBN, 2023), Science Based Targets initiative (SBTi) Corporate Standard |
| Purpose creep | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Brazil Open Finance (Resolução Conjunta No. 1/2020), New Hampshire Data Privacy Act |
| No stress testing | 3 | 3 | APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), IAIS Insurance Core Principles (ICPs) |
| No root cause | 3 | 3 | ISO 28001:2007 Supply Chain Security Management, ISO/IEC 25012:2008, ISO/IEC 27003:2017 |
| 30-day SLA frequently missed | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Audit log integrity not assessed | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| no remediation | 3 | 3 | Argyris Double-Loop Learning, ISO 37002:2021, PCI DSS 4.0 |
| No access logging | 3 | 3 | Australia My Health Records Act 2012, Laos Law on Prevention and Combating Cybercrime (2015), PCI DSS 4.0 |
| No outcome metrics Governance of organizations, Social responsibility | 3 | 3 | ISO 26000:2010, ISO 37000:2021, LEADS in a Caring Environment |
| No formal ConMon strategy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No tracked SLA | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| EA not maintained | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No aging metric | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| SPOFs unmitigated | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Same metro zone | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Local-only logs | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| Scope misunderstood Health information privacy and security | 3 | 3 | Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843), HITECH Act |
| Feedback collected but not acted on | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ITIL 4 |
| Annual review not performed | 3 | 3 | NIST Cybersecurity Framework 2.0, UK Building Safety Act 2022, US Foreign Corrupt Practices Act (FCPA) |
| No annual pen test Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements) | 3 | 3 | BSI IT-Grundschutz, Lloyd's Minimum Standards, New Zealand Information Security Manual (NZISM) |
| Visitor escorts not enforced | 3 | 3 | HIPAA Security Rule, NIST Cybersecurity Framework 2.0, NIST SP 800-66 Rev 2 |
| Emergency changes bypass review | 3 | 3 | FBI CJIS Security Policy, NIST SP 800-171 Rev 3, NIST SP 800-53 Rev 5 |
| Recertification not performed | 3 | 3 | HIPAA Security Rule, NIST SP 800-66 Rev 2, UK Defence Standard 05-138 |
| Configuration drift unmanaged | 3 | 3 | ASIC Cyber Resilience Good Practices, AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF) |
| Re-screening not performed | 3 | 3 | HIPAA Security Rule, ISO 37001, NIST SP 800-66 Rev 2 |
| Contractors and temporary staff excluded | 3 | 3 | APEC Cross-Border Privacy Rules (CBPR) System, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) |
| Effectiveness not measured | 3 | 3 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, ISO/SAE 21434, NIST SP 800-53 Rev 5 |
| Coverage incomplete | 3 | 3 | Australian Privacy Principles (APPs), BSIMM, PCI DSS 4.0 |
| Exceptions granted with no expiry | 3 | 3 | Azure Security Benchmark, NIST Cybersecurity Framework 2.0, NIST SP 800-171A |
| No role-based training Business continuity management, Insurance cybersecurity | 3 | 3 | ISO 22313:2020, ISO 37001, NAIC Insurance Data Security Model Law (MDL-668) |
| CUI specific incidents not exercised | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| no breach response | 3 | 3 | Australian Privacy Principles (APPs), FFIEC IT Examination Handbook, Nevada Gaming Control Board Cybersecurity Requirements |
| Exceptions never reviewed Privacy framework | 3 | 3 | ANSSI Guide d'hygiene informatique (42 mesures, v2.0), ISO/IEC 29100:2024, NIST Cybersecurity Framework 2.0 |
| No accuracy review of long-held records Data protection and privacy | 3 | 3 | POPIA, Qatar DPL, Rwanda DPL |
| No data subject breach notification | 3 | 3 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Data collected but not analysed Environmental management, Quality management | 3 | 3 | ISO 14004:2016, ISO 9001, ISO 9001:2015 |
| Retention period inconsistent across systems | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| No SLA monitoring | 3 | 3 | AWS Well-Architected Security Pillar, CCPA/CPRA, NIST SP 800-144 |
| API authorization not tested | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Transfers without mapping (cloud sprawl) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Plan unwritten | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| No tracking of completion | 3 | 3 | C5 (Germany), HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| Service accounts not enumerated | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| no governance | 3 | 3 | Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-144 |
| Auditors auditing their own area Environmental management, Food safety management, Organizational resilience: security, preparedness and business continuity management | 3 | 3 | ASIS SPC.1-2009, ISO 14004:2016, ISO 22000:2018 |
| findings reported but not tracked to closure Environmental management | 3 | 3 | Azure Security Benchmark, ISO 14001:2015, ISO 14001:2026 |
| Flat OT network | 3 | 3 | IEC 62351, ISO 27019, NIST SP 800-82 Rev 3 |
| CAPA backlog from prior inspections | 3 | 3 | EU Clinical Trials Regulation (CTR 536/2014), EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Medical Devices Regulation (MDR 2017/745) |
| KPIs not defined Enterprise risk management | 3 | 3 | ISO 13485, ISO 19011, ISO 31000:2018 |
| No appeal process | 3 | 3 | Colorado Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Measurement uncertainty not estimated | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| BYOD authorization unclear | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Resource gaps not surfaced before incidents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Evaluation criteria not documented | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Standards updates not tracked Battery sustainability, safety, labelling, due diligence, waste management and the battery passport; circular economy | 3 | 3 | EU Batteries Regulation (Regulation (EU) 2023/1542), FISMA, GS1 Global Standards |
| No periodic refresh Aviation, space and defense quality management system on ISO 9001:2015, Information management for built assets (BIM) | 3 | 3 | AS9100D, ISO 19650, ISO 9001 |
| lessons not implemented | 3 | 3 | FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook, NIST SP 800-82 Rev 3 |
| No lessons learned Management system auditing | 3 | 3 | ISO 19011:2018, ISO 19011:2026, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) |
| Resource gaps surfaced only after incidents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| unauthenticated scans only | 3 | 3 | Cyber Essentials Plus, NIST SP 800-190, PCI DSS 4.0 |
| Identity verification weak (impersonation risk) | 3 | 3 | Indonesia PDP Law, Jamaica Data Protection Act 2020, Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Missing NIST alignment | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Records not retrievable on demand | 3 | 3 | HIPAA Security Rule, NIST SP 800-66 Rev 2, Union Customs Code (UCC) |
| Asset register out of date | 3 | 3 | HIPAA Security Rule, NIST SP 800-66 Rev 2, UK Defence Standard 05-138 |
| Exceptions never expire | 3 | 3 | NIST SP 800-128, NIST SP 800-171, NIST SP 800-218 |
| Backups unencrypted | 3 | 3 | 3GPP 5G Security Architecture (TS 33.501), CISA Zero Trust Maturity Model, Ukraine Law on Personal Data Protection (Law No. 2297-VI) |
| Surge capacity not planned for outbreak scenarios | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No management review Biometric privacy | 3 | 3 | BIMCO Cyber Security, ISO/IEC 27003:2017, Illinois Biometric Information Privacy Act (BIPA) |
| Reassessment overdue for long serving staff | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Locum induction not recorded | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No customer notification | 3 | 3 | ISO 27018, Nigeria Open Banking Regulatory Framework (CBN, 2023), PCI DSS 4.0 |
| Contractors untrained Supply chain security | 3 | 3 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO 22000, ISO 28001:2007 Supply Chain Security Management |
| Minutes record discussion but no decisions Asset management, Food safety management, Quality management | 3 | 3 | ISO 22000:2018, ISO 55001:2024, ISO 9001:2015 |
| Access logs not reviewed | 3 | 3 | NIST Cybersecurity Framework 2.0, UK Concordat on Open Research Data (UKRI), WHO Global Strategy on Digital Health 2020-2025 |
| Documents uncontrolled Asset management, Environmental management | 3 | 3 | ISO 14001:2015, ISO 55001:2014, ISO 55001:2024 |
| External notification timelines unclear | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Contractors missing NDA Enterprise risk management | 3 | 3 | ISO 15189:2022, ISO 19011, ISO 31000:2018 |
| Lot to lot verification skipped under pressure | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical reagents single sourced without contingency | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Supplier performance not monitored | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No process for handling unaccredited referral results | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| External comms ad hoc AI risk management, Whistleblowing management | 3 | 3 | ISO 37002:2021, ISO/IEC 23894:2023, ISO/IEC 27003:2017 |
| Traceability chain broken to manufacturer working calibrators | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Calibration intervals not justified by data | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Non-APL products | 3 | 3 | FedRAMP High, FedRAMP Moderate, New Zealand Information Security Manual (NZISM) |
| No ongoing monitoring after onboarding | 3 | 3 | HIPAA Security Rule, NIST SP 800-66 Rev 2, Samoa Telecommunications Act (2005) |
| Drift not detected | 3 | 3 | AWS Well-Architected Security Pillar, NIST SP 800-137, NIST SP 800-171 |
| Contractors excluded Environmental management | 3 | 3 | ISO 14004:2016, ISO 37301, Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) |
| Trends not reviewed in management review | 3 | 3 | 21 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017 |
| No measurement uncertainty estimate per assay | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Alerts not triaged | 3 | 3 | ASIC Cyber Resilience Good Practices, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), IEC 62351 |
| Consent records lack timestamp or version | 3 | 3 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Turnaround time commitments not monitored | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No documented review cadence Criminal justice information security | 3 | 3 | FBI CJIS Security Policy, HIPAA Security Rule, NIST SP 800-172 |
| no root-cause analysis Aviation information security management | 3 | 3 | BIMCO Cyber Security, EASA Part-IS, Saudi Arabia PDPL |
| Sample acceptance criteria not in writing | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Inherent vs residual risk scoring not documented | 3 | 3 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| ERP transaction restrictions undocumented | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Energy considered only after design freeze | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Records dispersed and not centrally managed | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| no root cause analysis | 3 | 3 | ISO/IEC 27031:2011, PDPA Thailand, Vermont Artificial Intelligence and Consumer Data Act (AICDA) |
| No anonymous channel Aviation information security management | 3 | 3 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), EASA Part-IS, ISO 37301 |
| Missing risk analysis | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Expired reagents found in active stock | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Annual cycle ad-hoc Event wagering systems: technical certification and operational audit | 3 | 3 | GLI-33, Global Cross-Border Privacy Rules (Global CBPR) Forum, Greece Law 4624/2019 |
| delayed notification | 3 | 3 | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), PDPA Thailand, Singapore Cybersecurity Act 2018 |
| Downstream propagation absent (siloed responses) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Performance verification skipped after relocation | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Maintenance done by unqualified staff | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical suppliers not risk assessed | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No portability format | 3 | 3 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA |
| No lessons captured Digital investigation processes, Innovation management | 3 | 3 | ISO 56002, ISO/IEC 27043:2015, NIST SP 800-150 |
| Gaps in log generation for critical events | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Forensic capability not validated | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Cloud audit logs not retained | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Application level controls absent | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Sample size too small | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| No applicability memo | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| De-identification public commitment missing | 3 | 3 | Maryland Online Data Privacy Act of 2024, Minnesota Consumer Data Privacy Act, Montana Consumer Data Privacy Act |
| Missing exemption documentation Insurance cybersecurity | 3 | 3 | NAIC Insurance Data Security Model Law (MDL-668), Nebraska Data Privacy Act, New Hampshire Data Privacy Act |
| Review held without top management Asset management, Environmental management | 3 | 3 | ISO 14001:2015, ISO 14004:2016, ISO 55001:2024 |
| Contractor devices missing from inventory | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Generic training only Emergency management, business continuity and crisis management programs | 3 | 3 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NFPA 1600, NIST SP 800-171 |
| Auditors auditing their own work AI management, Asset management, Quality management | 3 | 3 | ISO 55001:2024, ISO 9001:2015, ISO/IEC 42001:2023 |
| Referral labs used without accreditation evidence | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Objectives not measurable, so achievement cannot be shown Asset management, Environmental management | 3 | 3 | ISO 14001:2015, ISO 14001:2026, ISO 55001:2024 |
| No periodic review of authorization list | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0 |
| Briefings irregular | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| Context not refreshed AI risk management, Knowledge management | 3 | 3 | ISO 30401, ISO/IEC 23894:2023, ISO/IEC 27003:2017 |
| Audit rights not exercised | 3 | 3 | FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011), Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), Turkey KVKK |
| Reviews not performed | 3 | 3 | ISO 22318, NIST SP 800-171, PCI DSS 4.0 |
| Indirect collection notice missing | 3 | 3 | Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Senegal Law on Personal Data Protection (Law No. 2008-12) |
| No Code of Conduct adoption | 3 | 3 | Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Lithuania Law on Legal Protection of Personal Data (2018) |
| Training not delivered | 3 | 3 | ISO 22739:2024, ISO 26000:2010, Kuwait Data Privacy Protection Regulation (KDPPR, 2021 |
| Sensitive data uncategorised (treated as general) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| No crisis communication plan | 3 | 3 | Belgium CyberFundamentals, DORA, EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) |
| No configuration baselines | 3 | 3 | ASIC Cyber Resilience Good Practices, C2M2, CFTC System Safeguards (17 CFR 37, 38, 39, 49) |
| Auditors not independent Business continuity management, Knowledge management | 3 | 3 | ISO 22313:2020, ISO 30401, ISO 9001 |
| System documented once and never maintained Asset management, Environmental management | 3 | 3 | ISO 14001:2015, ISO 14001:2026, ISO 55001:2024 |
| Breach detection passive (manual reports only) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| Consent records weak (bundled + pre-ticked) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| Interested parties listed without the requirement each imposes Anti-bribery management, Privacy information management | 3 | 3 | ISO 37001:2016, ISO 37001:2025, ISO/IEC 27701:2025 |
| No internal audit programme | 3 | 3 | NATO AQAP 2110, Turkey KVKK, Union Customs Code (UCC) |
| Software versions not tracked per analyser | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Segregation between incompatible activities unclear | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No DPIA for high-risk | 3 | 3 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA |
| Missing insurance coverage ISMS certification body requirements | 3 | 3 | ISO/IEC 17025:2017, ISO/IEC 27006-1:2024, South Korea PIPA |
| Remote access without MFA | 3 | 3 | IEC 62443, TISAX, US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements |
| Sectoral coordination weak Banking supervision | 3 | 3 | GS1 Global Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM |
| Standing privileged access | 3 | 3 | Azure Security Benchmark, CISA Zero Trust Maturity Model, DoD Zero Trust Reference Architecture |
| No transition plan | 3 | 3 | Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020), CDP (formerly Carbon Disclosure Project) |
| keys never rotated Aviation information security management | 3 | 3 | AWS Well-Architected Security Pillar, EASA Part-IS, PCI DSS 4.0 |
| Self-signed certificates in production | 3 | 3 | 3GPP 5G Security Architecture (TS 33.501), Azure Security Benchmark, UK Defence Standard 05-138 |
| Classification not documented | 3 | 3 | Brazil AI Framework, Canada Artificial Intelligence and Data Act (AIDA), Russia Federal Law on Personal Data (152-FZ) |
| Evidence not preserved Aviation information security management | 3 | 3 | EASA Part-IS, NIST SP 800-161, US Foreign Corrupt Practices Act (FCPA) |
| Templates outdated Business continuity management, Business continuity, business impact analysis | 3 | 3 | ISO 22313:2020, ISO/TS 22317:2021, NIST SP 800-161 |
| no independent audit | 3 | 3 | Digital Services Act (DSA), Kuwait Data Privacy Protection Regulation (KDPPR, 2021, TNFD Recommendations |
| No regulatory mapping | 3 | 3 | ISO 15189:2022, ISO 27005, ISO/IEC 25012:2008 |
| Changes made without reviewing environmental consequences Environmental management | 3 | 3 | ISO 14001:2015, ISO 14001:2026, ISO 14004:2016 |
| Uncontrolled documents Environmental management, Food safety management | 3 | 3 | DAMA-DMBOK2, ISO 14004:2016, ISO 22000:2018 |
| no annual review evidence | 3 | 3 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NIST SP 800-61, NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems |
| Contractors not screened | 3 | 3 | ISO 27019, NIST SP 800-171 Rev 3, PCI DSS 4.0 |
| Weak authentication | 3 | 3 | Brazil Open Finance (Resolução Conjunta No. 1/2020), NIST SP 800-123, TNFD Recommendations |
| International cooperation absent | 3 | 3 | French Sapin II Law (Law No. 2016-1691), Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843) |
| No complaints process | 3 | 3 | Australia Consumer Data Right, Australia NHMRC National Statement on Ethical Conduct in Human Research, Australian Privacy Principles (APPs) |
| No retention policy | 3 | 3 | ISO 22739:2024, NIST SP 800-128, Sigstore |
| Dependencies not mapped | 3 | 3 | APRA CPS 230 Operational Risk Management, ISO 22313:2020, ISO/IEC 29134:2023 |
| No prior consultation Data protection and privacy | 3 | 3 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Nigeria Data Protection Act 2023 (NDPA) |
| Follow-ups close on promise not evidence Enterprise risk management | 3 | 3 | ISO 15189:2022, ISO 19011, ISO 31000:2018 |
| Complaints not handled or escalated | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No revocation mechanism | 3 | 3 | Botswana Data Protection Act (2024), Connecticut Data Privacy Act (CTDPA), Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP |
| No documented rationale ISMS certification body requirements | 3 | 3 | ISO/IEC 27006-1:2024, PCI DSS 4.0, Union Customs Code (UCC) |
| Logs collected but not parsed by SIEM | 3 | 3 | ISO 13485, ISO 15189:2022, ISO 19011 |
| Sampling plan not statistically justified | 3 | 3 | 21 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017 |
| Use cases focused on IT, missing SWIFT-specific scenarios | 3 | 3 | ISO 13485, ISO 15189:2022, ISO 19011 |
| Risk register not refreshed on a defined cadence | 3 | 3 | ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017 |
| Out of date records ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| Sampling not representative Enterprise risk management | 3 | 3 | 21 CFR Part 211, ISO 19011, ISO 31000:2018 |
| Reviews not minuted Enterprise risk management | 3 | 3 | ISO 13485, ISO 19011, ISO 31000:2018 |
| Competence assumed from job titles Compliance management, Compliance management; effectiveness evaluation, Quality plans | 3 | 3 | ISO 10005:2018, ISO 37301:2021, ISO 37302:2025 |
| Out of service equipment used for urgent work | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Production data copied to test | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Lessons learned not implemented | 3 | 3 | NIST SP 800-53 Rev 5, PCI DSS 4.0, Senegal Law on Personal Data Protection (Law No. 2008-12) |
| Setpoints drift between shifts Business continuity management, Energy management, Road traffic safety management | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 50001:2018 |
| Same nonconformity recurring across audits Anti-bribery management, Privacy information management | 3 | 3 | ISO 37001:2016, ISO 37001:2025, ISO/IEC 27701:2025 |
| Reference material traceability not documented to SI where applicable | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Calibration providers not assessed for competence | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Outsourced providers have no energy obligations Business continuity management, Facility management, Road traffic safety management | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Material changes not notified | 3 | 3 | Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Kenya Data Protection Act, South Korea Cloud Security Assurance Program (CSAP) |
| Lot bridging absent for critical assays | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Suppliers not assessed against energy criteria Business continuity management, Energy management, Facility management | 3 | 3 | ISO 22313:2020, ISO 41001:2018, ISO 50001:2018 |
| Procurement decisions based on capex only Business continuity management, Energy management, Facility management | 3 | 3 | ISO 22313:2020, ISO 41001:2018, ISO 50001:2018 |
| Certificates of destruction not retained | 3 | 3 | HIPAA Security Rule, ISO/IEC 27701:2019, NIST SP 800-66 Rev 2 |
| No link between scope changes and resource updates | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Surge capacity not planned | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Removable media unrestricted | 3 | 3 | Cyber Essentials Plus, HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| No communication plan Enterprise risk management | 3 | 3 | ASIC Cyber Resilience Good Practices, Australian Energy Sector Cyber Security Framework (AESCSF), ISO 31000:2018 |
| Subcontracted resources not included in plan | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical suppliers single sourced | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Plan never exercised | 3 | 3 | Authorised Economic Operator (AEO) Programmes, BS 65000:2014, NIST SP 800-82 Rev 3 |
| Specifications not updated after method changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Supplier performance not reviewed annually | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No verification after software upgrades | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Statutory timeframes missed | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No community engagement Building sustainability assessment and certification | 3 | 3 | Australia NHMRC National Statement on Ethical Conduct in Human Research, BREEAM, LEADS in a Caring Environment |
| Over-collection beyond stated purpose Personal information protection | 3 | 3 | China Personal Information Protection Law (PIPL), Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA) |
| Access controls not enforced for visitors | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Authorization granted without practical assessment | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No periodic review of agreements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No 10-year supply-chain records | 3 | 3 | EU Cyber Resilience Act, EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Machinery Regulation (Regulation (EU) 2023/1230) |
| Reassessment intervals not defined | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Subcontracted personnel competence not verified | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No record of authorization changes when methods change | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Stale compliance review Data protection and privacy | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, Nigeria Data Protection Act 2023 (NDPA) |
| No 72-hour notification capability Personal data protection | 3 | 3 | Egypt Personal Data Protection Law (Law No. 151 of 2020), Malta Data Protection Act (Cap. 586, 2018), Montenegro Law on Personal Data Protection (2023) |
| Workload not measured against capacity | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Competence on rare assays not maintained | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No minimisation justification | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Vendor risk assessments not refreshed at the required cadence | 3 | 3 | Solvency II, South Korea ISMS-P, Space ISAC (Information Sharing and Analysis Center) |
| Budget cycles not aligned with method changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| identity verification overly burdensome Privacy framework | 3 | 3 | ISO/IEC 29100:2024, South Korea Credit Information Act, Uzbekistan Law on Personal Data (No. ZRU-547) |
| Documentation only for notified breaches | 3 | 3 | Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act |
| Findings unremediated | 3 | 3 | COBIT 2019, HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| New starter checklist incomplete | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Notifiable breaches not reported | 3 | 3 | Australian Energy Sector Cyber Security Framework (AESCSF), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO) |
| No independent review ISMS certification body requirements, Medical device software life cycle processes | 3 | 3 | Canada Artificial Intelligence and Data Act (AIDA), IEC 62304:2015 Medical Device Software Lifecycle Processes, ISO/IEC 27006-1:2024 |
| Inadequate security measures | 3 | 3 | Argentina Law 25.326 (Personal Data Protection Law), Azerbaijan Law on Personal Data (2010), Netherlands GDPR Implementation Act (UAVG |
| Corrective actions not tracked Compliance management; effectiveness evaluation, Conformity assessment; AI governance | 3 | 3 | ISO 37002:2021, ISO 37302:2025, ISO/IEC 42006:2025 |
| No certificate of destruction Criminal justice information security | 3 | 3 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FBI CJIS Security Policy, NIST SP 800-171 |
| Storage temperature deviations not actioned | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Subcontractor flow-down clauses absent or weak in contracts | 3 | 3 | Solvency II, South Korea ISMS-P, Space ISAC (Information Sharing and Analysis Center) |
| Authorization tied to job title rather than verified competence ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| No privacy program plan distinct from security | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Out of service status not flagged in LIS | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Renewable or low carbon options not evaluated | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No breach notification process | 3 | 3 | Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014), Argentina Law 25.326 (Personal Data Protection Law), Data Protection Act 2017 |
| No completion tracking | 3 | 3 | Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017, PCI DSS 4.0 |
| Findings not tracked to closure Automotive system, software, hardware and machine learning engineering process capability, Biometric privacy, Governance of organizations | 3 | 3 | Automotive SPICE (ASPICE) v4.1, ISO 37000:2021, Illinois Biometric Information Privacy Act (BIPA) |
| No drift monitoring AI risk management | 3 | 3 | Canada Artificial Intelligence and Data Act (AIDA), ISO/IEC 23894:2023, PCI DSS 4.0 |
| Required records not identified Asset management, Occupational health and safety, Quality management | 3 | 3 | ISO 45001:2018, ISO 55001:2014, ISO 9001:2015 |
| No objection mechanism | 3 | 3 | African Union Malabo Convention, Angola Personal Data Protection Law (Law No. 22/11), Data Protection Act 2017 |
| Maintenance carried out by users without training | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Appeals not tracked | 3 | 3 | Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics |
| Reference material lot changes not bridged | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Sectoral application gaps Health information privacy and security, Leadership development | 3 | 3 | GS1 Global Standards, HITECH Act, Hersey & Blanchard Situational Leadership Model |
| No maturity assessment | 3 | 3 | BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150 |
| Containment level not validated for new agents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Storage of patient samples not segregated from reagents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Security not documented | 3 | 3 | Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO) |
| Root cause analysis superficial Laboratory competence, Quality management | 3 | 3 | ISO 15189:2022, ISO 9001:2015, ISO/IEC 17025:2017 |
| Opportunities never identified Environmental management, Food safety management, Quality management | 3 | 3 | ISO 14001:2026, ISO 22000:2018, ISO 9001:2015 |
| No review after a real incident Environmental management, Food safety management | 3 | 3 | ISO 14001:2015, ISO 14001:2026, ISO 22000:2018 |
| split tunneling enabled | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-171 Rev 3 |
| Cleaning and decontamination logs incomplete | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Modifications bypass design review | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Correspondence not tracked | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Roadmap not tracked GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle | 3 | 3 | GAMP 5, Global Cross-Border Privacy Rules (Global CBPR) Forum, HKMA Cyber Resilience Assessment Framework (C-RAF) |
| No covert channel detection | 3 | 3 | FedRAMP High, FedRAMP Moderate, PCI DSS 4.0 |
| No matching agreements | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No performance evidence ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| No evidence of practical assessment for new methods ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| Training records missing for locum or agency staff ISMS certification body requirements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024 |
| SSN used as primary key | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No threat modeling | 3 | 3 | CNCF Security Technical Advisory Group (TAG), FedRAMP High, FedRAMP Moderate |
| Health PII commingled | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Vague lawful basis | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No purposing analysis | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No risk executive function | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No external privacy reporting | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Lessons learned not actioned | 3 | 3 | EASA Part-IS, NIST SP 800-171 Rev 3, PCI DSS 4.0 |
| Improvements not tracked | 3 | 3 | COSO Enterprise Risk Management (ERM) Framework (2017), ISO 20400:2017, ISO/IEC 17025:2017 |
| No privacy-specific policy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| DGB exists in name only | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No disclosure register | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Energy specifications not communicated to suppliers Business continuity management, Energy management, Facility management | 3 | 3 | ISO 22313:2020, ISO 41001:2018, ISO 50001:2018 |
| Board reporting infrequent or absent | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Processor notification absent in contracts | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| Lawful basis selected after processing (consent bias) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Privacy notices out of date | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Appetite not approved at board level | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| DSAR portal absent (email-only handling) | 3 | 3 | Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act |
| RoPA missing or incomplete | 3 | 3 | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), Fiji Data Protection Bill (2020), Georgia Law on Personal Data Protection (2012) |
| No CI mapping for the organization | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No behavior baseline | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| Training delivered but effectiveness never evaluated Compliance management; competence management, Environmental management | 3 | 3 | ISO 14001:2015, ISO 14001:2026, ISO 37303:2025 |
| Unlimited concurrent sessions | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| Backup analysers not maintained to same standard | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No authority assessment | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No HR/Legal/IT working group | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No SORN for in-scope systems | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Notice misaligned with actual processing | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Purposes drift after launch | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Role split between functions | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Framing assumptions undocumented | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No oversight of data matching | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No CUI clauses in contracts | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No threat-sharing memberships | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Testing siloed by system | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Plan stale or generic | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No role-based pathway | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Budget not tracked separately | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Privacy considered only at the end | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Authorization stale | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |