3.28

Overall Score (0-5)

25

Assessed Controls

15

Identified Gaps

0

Critical Gaps

Maturity by Domain
Compliance by Framework
Compliance = Level ≥ 3
Maturity Distribution
Maturity Gaps (Current Level < 4)
Control Domain Current Target Gap Priority
AUTH-005
Block interactive login and rotate Service Account...
Authentication 2 4 2 levels High
MON-004
P1 alerts for changes to Tier 0 groups (Global/Dom...
Monitoring (MON) 2 4 2 levels High
JML-004
Quarterly Access Certification campaigns with auto...
Identity Lifecycle (JML) 2 4 2 levels High
AUTH-003
Configure Smart Lockout: block the threat actor (I...
Authentication 3 4 1 levels Medium
JML-002
Review trigger on transfers: a change of role in H...
Identity Lifecycle (JML) 3 4 1 levels Medium
JML-006
Strict expiration (TTL) for guest (B2B) accounts, ...
Identity Lifecycle (JML) 3 4 1 levels Medium
MON-002
Automatic blocking based on Risk (User/Sign-in Ris...
Monitoring (MON) 3 4 1 levels Medium
PAM-002
Separate accounts: adm-user (no email/web) for man...
Privileged Access (PAM) 3 4 1 levels Medium
PAM-003
Remove local administrator account and use LAPS fo...
Privileged Access (PAM) 3 4 1 levels Medium
PAM-005
2 monitored Emergency (Break Glass) accounts, clou...
Privileged Access (PAM) 3 4 1 levels Medium
AUTH-004
Real-time checking of banned passwords against glo...
Authentication 3 4 1 levels Medium
AUTH-007
Disable legacy protocols (Basic Auth: POP3, IMAP, ...
Authentication 3 4 1 levels Medium
JML-003
Automate exit 'Kill Switch': Blocking and revocati...
Identity Lifecycle (JML) 3 4 1 levels Medium
MON-001
Centralize Audit/Sign-in Logs in a SIEM. Retention...
Monitoring (MON) 3 4 1 levels Medium
PAM-006
Require dedicated Privileged Access Workstations (...
Privileged Access (PAM) 3 4 1 levels Medium
Recommendations Roadmap
AUTH-005 High

Block interactive login and rotate Service Account secrets every 90 days (or use...

2 3

Action: Rotação manual periódica (Planilha de controle).

MON-004 High

P1 alerts for changes to Tier 0 groups (Global/Domain Admins) with out-of-band n...

2 3

Action: Relatório diário de mudanças.

JML-004 High

Quarterly Access Certification campaigns with automatic revocation if there is n...

2 3

Action: Anual (Todos) via Planilha Excel.

AUTH-003 Medium

Configure Smart Lockout: block the threat actor (IP), not the user account (AD),...

3 4

Action: Smart Lockout em modo Audit (Log only).

JML-002 Medium

Review trigger on transfers: a change of role in HR initiates access recertifica...

3 4

Action: Gatilho automático gera tarefa de revisão.

JML-006 Medium

Strict expiration (TTL) for guest (B2B) accounts, requiring sponsor renewal....

3 4

Action: TTL automático (90 dias) com renovação.

MON-002 Medium

Automatic blocking based on Risk (User/Sign-in Risk) for high-risk events....

3 4

Action: Alerta integrado ao Ticket (SOAR).

PAM-002 Medium

Separate accounts: adm-user (no email/web) for management and user for daily use...

3 4

Action: Contas Cloud-Only, MFA forte.

PAM-003 Medium

Remove local administrator account and use LAPS for unique, per-workstation rota...

3 4

Action: LAPS em 100% com auditoria de uso.

PAM-005 Medium

2 monitored Emergency (Break Glass) accounts, cloud-only, excluded from MFA and ...

3 4

Action: 2 contas cloud-only, alertas configurados.

AUTH-004 Medium

Real-time checking of banned passwords against global (pwned) lists and company ...

3 4

Action: Integração com listas globais (pwned).

AUTH-007 Medium

Disable legacy protocols (Basic Auth: POP3, IMAP, SMTP) globally....

3 4

Action: Bloqueio Global com exceções monitoradas.