| Logical access and privilege | CC6.1 – CC6.3 | A.5.15 – A.5.18, A.8.2 | Entra PIM per-shift approval, zero standing privilege, MFA on activation | PIM audit log, access reviews |
| Endpoint and device security | CC6.6 – CC6.8 | A.8.1, A.8.7, A.8.9 | Conditional Access with Intune compliance: EDR, encryption, patch level | Policy export, compliance report |
| Credential and secret management | CC6.1, CC6.7 | A.5.17, A.8.24 | 100-character unique credentials in IT Glue, reachable only via Landing Zone | Credential standard, retrieval log |
| Logging and monitoring | CC7.2 | A.8.15, A.8.16 | Central Azure logging of sign-ins, PIM activity and jump-host sessions; alerting | Log retention, alert rules |
| Vulnerability and patch management | CC7.1 | A.8.8 | Continuous scanning, patch governance, penetration-test remediation program | Scan reports, remediation tracker |
| Incident response | CC7.3 – CC7.5 | A.5.24 – A.5.28 | Documented plan; CISO as single point of contact; client notification | Incident response plan, tabletop records |
| Change management | CC8.1 | A.8.32 | Ticket-referenced, approved changes; project work separately scoped | Change tickets, approvals |
| Business continuity | A1.2 – A1.3 | A.5.29, A.5.30 | Documented continuity plan; Azure-hosted tooling with resilient design | Continuity plan, test results |
| Security awareness | CC1.4, CC2.2 | A.6.3 | KnowBe4 simulations; quarterly CISO-led training; onboarding gate | Completion and phish-prone metrics |
| Third-party and vendor risk | CC9.2 | A.5.19 – A.5.21 | Assessment of platforms in the delivery chain (Microsoft, N-able, IT Glue) | Vendor SOC and ISO reports |