THE QUESTION: THE QUESTION: Same control, two pieces of evidence: is access to production actually restricted? One of these tells you much less than its confidence suggests.
[A] platform/controls-dashboard.csv 1 │ control: CC6.1 production access restriction 2 │ status: PASS · last checked 2h ago 3 │ test: org_setting.sso_required == true 4 │ test: org_setting.mfa_policy == "enforced" 5 │ scope: default org policy (exceptions not evaluated) 6 │ evidence: this dashboard, auto-attached quarterly
[B] audits/q3-access-spot-check.md 1 │ method: pulled 40 active prod accounts, checked live 2 │ finding: 2 ex-contractor accounts, sessions active 3 │ finding: svc-deploy key shared by 3 teams, no MFA 4 │ tickets: ACC-2214, ACC-2215, ACC-2219 opened 5 │ caveat: 40 of ~900 accounts, one afternoon
grc@ctrl-f:~$