1.0

Overall Score (0-5)

25

Assessed Controls

25

Identified Gaps

25

Critical Gaps

Maturity by Domain
Compliance by Framework
Compliance = Level ≥ 3
Maturity Distribution
Maturity Gaps (Current Level < 4)
Control Domain Current Target Gap Priority
AUTH-001
Enforce Phishing-resistant MFA (FIDO2/CBA) for all...
Authentication 1 4 3 levels Critical
AUTH-002
Enforce MFA for all users with Number Matching to ...
Authentication 1 4 3 levels Critical
AUTH-003
Configure Smart Lockout: block the threat actor (I...
Authentication 1 4 3 levels Critical
AUTH-004
Real-time checking of banned passwords against glo...
Authentication 1 4 3 levels Critical
AUTH-005
Block interactive login and rotate Service Account...
Authentication 1 4 3 levels Critical
AUTH-006
Enforce re-authentication for critical actions (e....
Authentication 1 4 3 levels Critical
AUTH-007
Disable legacy protocols (Basic Auth: POP3, IMAP, ...
Authentication 1 4 3 levels Critical
JML-001
Automate 'Birthright' provisioning via HR, creatin...
Identity Lifecycle (JML) 1 4 3 levels Critical
JML-002
Review trigger on transfers: a change of role in H...
Identity Lifecycle (JML) 1 4 3 levels Critical
JML-003
Automate exit 'Kill Switch': Blocking and revocati...
Identity Lifecycle (JML) 1 4 3 levels Critical
JML-004
Quarterly Access Certification campaigns with auto...
Identity Lifecycle (JML) 1 4 3 levels Critical
JML-005
Detection of orphan accounts (Reconciliation): Com...
Identity Lifecycle (JML) 1 4 3 levels Critical
JML-006
Strict expiration (TTL) for guest (B2B) accounts, ...
Identity Lifecycle (JML) 1 4 3 levels Critical
MON-001
Centralize Audit/Sign-in Logs in a SIEM. Retention...
Monitoring (MON) 1 4 3 levels Critical
MON-002
Automatic blocking based on Risk (User/Sign-in Ris...
Monitoring (MON) 1 4 3 levels Critical
MON-003
Alert on unverified illicit or high-privilege OAut...
Monitoring (MON) 1 4 3 levels Critical
MON-004
P1 alerts for changes to Tier 0 groups (Global/Dom...
Monitoring (MON) 1 4 3 levels Critical
MON-005
Monitor anomalies in Service Principals (read volu...
Monitoring (MON) 1 4 3 levels Critical
MON-006
User feedback ('Not me') in MFA generates an immed...
Monitoring (MON) 1 4 3 levels Critical
PAM-001
Eliminate permanent privileges (Zero Standing Priv...
Privileged Access (PAM) 1 4 3 levels Critical
PAM-002
Separate accounts: adm-user (no email/web) for man...
Privileged Access (PAM) 1 4 3 levels Critical
PAM-003
Remove local administrator account and use LAPS fo...
Privileged Access (PAM) 1 4 3 levels Critical
PAM-004
Implement a Tiered Model (Tiering/Red Forest): Tie...
Privileged Access (PAM) 1 4 3 levels Critical
PAM-005
2 monitored Emergency (Break Glass) accounts, clou...
Privileged Access (PAM) 1 4 3 levels Critical
PAM-006
Require dedicated Privileged Access Workstations (...
Privileged Access (PAM) 1 4 3 levels Critical
Recommendations Roadmap
AUTH-001 Critical

Enforce Phishing-resistant MFA (FIDO2/CBA) for all administrative accounts, bloc...

1 2

Action: MFA obrigatório, mas permite SMS/Voz.

AUTH-002 Critical

Enforce MFA for all users with Number Matching to mitigate MFA fatigue....

1 2

Action: 100% de cobertura, permite SMS.

AUTH-003 Critical

Configure Smart Lockout: block the threat actor (IP), not the user account (AD),...

1 2

Action: Política de bloqueio definida, desbloqueio manual.

AUTH-004 Critical

Real-time checking of banned passwords against global (pwned) lists and company ...

1 2

Action: Política de complexidade básica.

AUTH-005 Critical

Block interactive login and rotate Service Account secrets every 90 days (or use...

1 2

Action: Rotação manual ad-hoc (quando quebra).

AUTH-006 Critical

Enforce re-authentication for critical actions (e.g., viewing sensitive data) re...

1 2

Action: Re-autenticação apenas para reset de senha.

AUTH-007 Critical

Disable legacy protocols (Basic Auth: POP3, IMAP, SMTP) globally....

1 2

Action: Bloqueio apenas para novos usuários.

JML-001 Critical

Automate 'Birthright' provisioning via HR, creating accounts disabled until the ...

1 2

Action: Formulário padrão (E-mail), execução manual.

JML-002 Critical

Review trigger on transfers: a change of role in HR initiates access recertifica...

1 2

Action: Revisão manual ad-hoc pelo gestor.

JML-003 Critical

Automate exit 'Kill Switch': Blocking and revocation of tokens in <15 min after ...

1 2

Action: Manual (No mesmo dia - Best effort).

JML-004 Critical

Quarterly Access Certification campaigns with automatic revocation if there is n...

1 2

Action: Revisão apenas de Admins (Manual).

JML-005 Critical

Detection of orphan accounts (Reconciliation): Compare AD vs HR weekly to find o...

1 2

Action: Verificação manual anual.