Cedar Grove Church
Fictional assessment · Scope: one campus, one email environment, 22 people accounts and 35 managed devices.
Leadership Priorities
Strengthen privileged account access, establish independent verification of payment changes, and confirm what can be restored from backups.
What Was Reviewed
Account and email configurations, financial approval practices, device protection, network separation, access to sensitive information, recovery arrangements, and responsibility for key systems.
| Evidence Measure | Illustrative Result |
|---|---|
| Controls in scope | 60 |
| Approved not applicable | 6 |
| Satisfied / partial / not satisfied / unknown | 24 / 10 / 12 / 8 |
| Evidence coverage | 46 of 54 applicable controls · 85.2% |
Coverage is not a security grade. Eight applicable controls remain unknown; they are not counted as passed.
01 / Privileged Accounts Lack Agreed Sign-in Protection
The fictional settings export shows two active privileged accounts excluded from the agreed strong sign-in policy. No account compromise is asserted.
Next step: Confirm recovery access, approve the policy change, and verify effective protection with a safe authorized check.
Owner: Tenant administrator
Status: Open · Likelihood 4 × impact 4 = 16
02 / Payment Changes Rely on Email Alone
A process walkthrough shows that a new vendor payment destination can be approved without confirmation through an independently established contact.
Next step: Require independent confirmation and appropriate approval before changing payment instructions. Test the process with a synthetic request.
Owner: Finance lead
Status: Planned · Likelihood 3 × impact 4 = 12
03 / Recovery Capability Is Not yet Evidenced
A product invoice and verbal assurance have been provided, but no backup coverage settings or restore record are available.
Next step: Obtain the coverage evidence and perform an approved, isolated sample restore. Keep this item unrated until the evidence supports a conclusion.
Owner: Backup owner
Status: Open · Verification priority high
The 30/60/90-Day Roadmap
- 30 days Address urgent identity and finance gaps; confirm recovery evidence.
- 60 days Review access lifecycle, clarify responsibilities, and submit priority fixes for verification.
- 90 days Revisit lower-priority improvements, staff training, and ongoing review needs.
Critical observations are escalated when discovered, rather than held until the end of a 30-day window. Actual priorities depend on the engagement and leadership decisions. Risk acceptance remains distinct from verified remediation.