| Roles undefined | 24 | 27 | APRA CPS 230 Operational Risk Management, APRA CPS 234, AWS Well-Architected Security Pillar |
| findings not remediated | 14 | 17 | AS9100D, AS9100D:2016, ASIC Cyber Resilience Good Practices |
| no annual review | 13 | 26 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Australian Information Security Manual, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Tooling fragmented Enterprise risk management | 13 | 13 | GAMP 5, GHG Protocol, GLI-33 |
| No periodic review Enterprise risk management | 12 | 12 | COBIT 2019, FedRAMP High, FedRAMP Moderate |
| Bundled consent | 12 | 12 | Code of Conduct on Data Protection for Research (GDPR Article 40), LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
| Objectives not measurable | 11 | 22 | AS9100D:2016, ASIS SPC.1-2009, COSO Enterprise Risk Management (ERM) Framework (2017) |
| No retention schedule | 10 | 11 | ASIS SPC.1-2009, Bermuda Personal Information Protection Act 2016 (PIPA), Brunei Personal Data Protection Order 2022 (PDPO) |
| No sanctions exposure analysis | 10 | 10 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 172-13 on the Protection of Personal Data |
| No withdrawal mechanism | 10 | 10 | Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) |
| Indefinite retention | 9 | 10 | African Union Malabo Convention, Argentina Law 25.326 (Personal Data Protection Law), Armenia Law on Protection of Personal Data (2015) |
| Transfer without lawful basis | 9 | 9 | Kuwait Data Privacy Protection Regulation (KDPPR, 2021, LGPD, Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) |
| Flat networks | 8 | 40 | Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, FFIEC IT Examination Handbook |
| no ongoing monitoring | 8 | 20 | C-TPAT, C2M2, FFIEC IT Examination Handbook |
| no trend analysis | 8 | 13 | BRCGS Global Standard for Food Safety Issue 9, FFIEC IT Examination Handbook, IEC 62304:2015 Medical Device Software Lifecycle Processes |
| Multi-framework alignment ad-hoc | 8 | 10 | FTC GLBA Safeguards Rule (16 CFR Part 314), GHG Protocol, GRI Standards |
| Pipeline not tracked | 8 | 9 | GLBA, GLI-33, GRI Standards |
| No inventory | 8 | 9 | Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22739:2024, ISO 26000:2010 |
| Tactical only Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| No insider threats Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| Catalogue not refreshed Occupational health and safety | 8 | 8 | AS9100D:2016, ISO 13485, ISO 14001 |
| Supplier incidents discovered through news rather than contractual notification | 7 | 62 | FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1 |
| Flow down clauses present in master agreements but missing from statements of work | 7 | 55 | FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1 |
| Counterfeit detection procedures absent for hardware refresh cycles | 7 | 42 | FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1 |
| Sub tier suppliers not identified for critical components | 7 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1 |
| Penetration tests scope narrow and exclude key applications | 7 | 32 | COSO Internal Control, FedRAMP High, FedRAMP Moderate |
| Scan coverage gaps for containerised and ephemeral workloads | 7 | 31 | COSO Internal Control, FedRAMP High, FedRAMP Moderate |
| Risk register entries lack named owner or due date | 7 | 30 | COSO Internal Control, FedRAMP High, FedRAMP Moderate |
| No incident response plan | 7 | 28 | Australian Information Security Manual, BIMCO Cyber Security, C2M2 |
| Threat intelligence consumed but not operationalised into detections | 7 | 25 | COSO Internal Control, FedRAMP High, FedRAMP Moderate |
| High severity vulnerabilities exceed remediation SLA without risk acceptance | 7 | 24 | COSO Internal Control, FedRAMP High, FedRAMP Moderate |
| Vendor risk tier ratings static despite changes in service scope | 7 | 21 | FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1 |
| Flat network | 7 | 9 | AWS Well-Architected Security Pillar, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 |
| Annual review skipped | 7 | 8 | FSSC 22000, FTC GLBA Safeguards Rule (16 CFR Part 314), French Sapin II Law (Law No. 2016-1691) |
| Shared admin accounts | 7 | 8 | 3GPP 5G Security Architecture (TS 33.501), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO/IEC 27011:2024 |
| No review cadence | 7 | 8 | COBIT 2019, ISO 28001:2007 Supply Chain Security Management, ISO/IEC 27003:2017 |
| Reviews skipped AI risk management | 7 | 8 | COBIT 2019, EASA Part-IS, FFIEC IT Examination Handbook |
| Register stale | 7 | 7 | FBI CJIS Security Policy, FFIEC Cybersecurity Assessment Tool (CAT), ISO 27019 |
| No encryption | 7 | 7 | C2M2, LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| No certification | 7 | 7 | Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Late responses | 7 | 7 | NIST SP 800-122, Nebraska Data Privacy Act, Netherlands GDPR Implementation Act (UAVG |
| Effectiveness not verified | 7 | 7 | ISO 28001:2007 Supply Chain Security Management, ISO 37002:2021, ISO 37301 |
| No appeals path | 7 | 7 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| ROPA incomplete | 7 | 7 | BSI IT-Grundschutz, LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| Missing training | 7 | 7 | BS 65000:2014, NIS2 Directive, NIST Privacy Framework |
| Evidence is point in time rather than ongoing | 6 | 124 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Firewall rule base contains stale allow any entries | 6 | 84 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Internal traffic between services unencrypted within trusted zones | 6 | 84 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Control owner unclear or vacant | 6 | 79 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| No metric tracks control effectiveness | 6 | 79 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Server room doors propped open during cooling failures | 6 | 73 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Access reviews performed but exceptions never remediated | 6 | 73 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| CCTV coverage gaps at loading docks and equipment delivery areas | 6 | 72 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Role definitions drift from documented matrix without change control | 6 | 67 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Legacy TLS versions remain enabled on external services | 6 | 67 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Service accounts excluded from periodic recertification | 6 | 62 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Clock drift across hosts breaks event correlation | 6 | 59 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Emergency changes bypass CAB and lack retrospective review | 6 | 59 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Privileged user activity not isolated for independent review | 6 | 59 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Unauthorised software present on endpoints not flagged by tooling | 6 | 58 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Federation trust relationships not reviewed when partnerships change | 6 | 57 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Privileged accounts shared across administrators without individual accountability | 6 | 57 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Cryptographic keys stored alongside the data they protect | 6 | 55 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Vendor SOC reports collected but exceptions not analysed | 6 | 55 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Contractor screening relies on vendor attestation without sampling | 6 | 53 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| MFA exceptions granted indefinitely without compensating controls | 6 | 51 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Flat networks expose sensitive workloads without segmentation | 6 | 50 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Severity criteria inconsistent across teams leading to under reporting | 6 | 47 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Environmental sensor alerts route to unmonitored mailboxes | 6 | 46 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Tailgating observed without challenge during walkthroughs | 6 | 46 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Critical patches deployed beyond the policy SLA without exception | 6 | 46 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Open source components used without SBOM or licence review | 6 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Tabletop exercises lack participation from business owners | 6 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Alternate site capacity not validated against current load | 6 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| EDR coverage gaps on legacy operating systems | 6 | 45 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Code scan findings closed without verification of fix | 6 | 44 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Sanctions applied informally without HR documentation | 6 | 42 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Baselines exist on paper but production hosts drift without alerting | 6 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Critical log sources missing from the SIEM with no detection coverage | 6 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Stale accounts retained for terminated personnel beyond the 24 hour SLA | 6 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Lessons learned captured but corrective actions not tracked to closure | 6 | 41 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Continuous monitoring metrics collected but not reported to leadership | 6 | 40 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Assessment scope omits inherited cloud provider controls | 6 | 40 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| USB usage permitted without DLP inspection or encryption | 6 | 39 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Decommissioned drives stored unencrypted while awaiting destruction | 6 | 39 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Threat modelling performed inconsistently across product teams | 6 | 39 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Reviewers acknowledge alerts but do not document investigation outcomes | 6 | 36 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| RTO and RPO targets undefined for tier two systems | 6 | 36 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Detection coverage gaps allow incidents to be discovered externally | 6 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Alert backlog exceeds analyst capacity leading to triage delays | 6 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Hardening benchmarks applied at build but not re evaluated annually | 6 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Position risk designations not reviewed when responsibilities change | 6 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Password complexity enforced but reuse not blocked across systems | 6 | 35 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Shared accounts authenticate without traceability to individuals | 6 | 34 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Visitor logs incomplete or escort sign offs missing | 6 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| System security plan not refreshed after material system changes | 6 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Plan not updated after major architecture changes | 6 | 33 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Security requirements absent from procurement templates for low value buys | 6 | 32 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Audit log retention shorter than the policy mandated period | 6 | 30 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Asset inventory missing cloud workloads and ephemeral resources | 6 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Background checks not re run when employees move to higher risk roles | 6 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Termination access removal exceeds documented SLA | 6 | 29 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Privacy considerations addressed separately from security planning | 6 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Authorization boundary description does not match the asset inventory | 6 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Vendor engineers granted standing access rather than session based access | 6 | 28 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Rules of behaviour acknowledged once but not refreshed annually | 6 | 27 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Phishing failures not followed by remedial coaching | 6 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Role based training not refreshed when job duties change | 6 | 25 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| POAM items past due without justification or risk acceptance | 6 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Default vendor credentials remain on appliances and IoT devices | 6 | 24 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Third party incident responder retainer expired | 6 | 23 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Backups taken but restore tests never performed end to end | 6 | 23 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Maintenance vendors lack signed confidentiality and security clauses | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Reauthorization scheduled past the policy required interval | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Anti malware signatures not updated on isolated network segments | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Remote maintenance sessions unmonitored after initial authentication | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Media classification labels missing on physical assets | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Destruction certificates lack serial numbers tying back to inventory | 6 | 22 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Training content not reviewed annually for current threat trends | 6 | 19 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Maintenance tools not sanitised before removal from secure areas | 6 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Contractors and third parties not enrolled in mandatory training | 6 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Notification timelines miss jurisdictional regulatory deadlines | 6 | 18 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Planning artefacts lack version history and approval signatures | 6 | 17 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Input validation handled inconsistently across microservices | 6 | 17 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Backup tapes shipped without tamper evident packaging | 6 | 17 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| no executive sponsor | 6 | 16 | API 1164, ISO 8000, NIST SP 800-161 |
| Architecture diagrams missing third party and SaaS dependencies | 6 | 16 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| No evidence policies were communicated to staff | 6 | 16 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Policies past their review date | 6 | 16 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| No procedure | 6 | 11 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Internal traffic unencrypted | 6 | 8 | AWS Well-Architected Security Pillar, ISO 27018, ISO/IEC 27018:2019 |
| No role-based training | 6 | 8 | CMMC 2.0, FedRAMP High, ISO 22313:2020 |
| No audit trail | 6 | 7 | Authorised Economic Operator (AEO) Programmes, ISO 27018, ISO 27043 |
| Lessons not actioned | 6 | 6 | Argyris Double-Loop Learning, ISO 22313:2020, ISO 22318 |
| Metrics gaps | 6 | 6 | GLI-33, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, GS1 Global Standards |
| no board reporting | 6 | 6 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), FFIEC IT Examination Handbook, ISO 37002:2021 |
| Visitor logs incomplete | 6 | 6 | BRCGS Global Standard for Food Safety Issue 9, HIPAA Security Rule, NIST SP 800-171 |
| Emergency maintenance performed without retrospective documentation | 6 | 6 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 |
| Marketing without opt-in | 6 | 6 | Law on Personal Data Protection (Official Gazette No. 42/2020), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Metrics not tracked | 6 | 6 | French Sapin II Law (Law No. 2016-1691), GAMP 5, GHG Protocol |
| Design-only testing | 6 | 6 | AS9100D, AS9100D:2016, ISO 13485 |
| shadow IT not captured Enterprise risk management | 6 | 6 | FFIEC Cybersecurity Assessment Tool (CAT), ISO 31000:2018, NIST SP 800-172 |
| No tabletop exercises | 6 | 6 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Kuwait National Cybersecurity Framework |
| No annual training | 6 | 6 | Laos Law on Prevention and Combating Cybercrime (2015), Law on Personal Data Protection (Official Gazette No. 42/2020), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) |
| IP register incomplete, ownership disputes likely | 5 | 95 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Time allocation for innovation crowded out by BAU | 5 | 85 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation budget not ring-fenced from operating budget | 5 | 85 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Strategic intelligence siloed in one team | 5 | 85 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Trend scanning is ad hoc and undocumented | 5 | 80 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Stakeholder map omits external innovation partners (universities, startups) | 5 | 80 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Partnership agreements lack IP and confidentiality clauses | 5 | 80 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Competence requirements for innovation roles not defined | 5 | 80 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Knowledge from past projects not captured or reused | 5 | 75 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No resource plan tied to portfolio priorities | 5 | 75 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Portfolio biased toward horizon 1 incremental projects | 5 | 70 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Tools and methods inconsistent across teams | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation strategy disconnected from corporate strategy | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Executive sponsorship limited to lip service, no time committed | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Context analysis treated as one-off, not refreshed annually | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| No clear accountability for innovation outcomes | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Opportunities and risks tracked separately with no link to objectives | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Lagging indicators only, no leading indicators | 5 | 65 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Evaluation criteria differ across portfolio without rationale | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation maturity baseline never established | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Strategic intelligence not feeding into innovation decisions | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Roles and responsibilities for innovation undefined | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation objectives lack measurable targets | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Initiative prioritisation done by HiPPO not criteria | 5 | 60 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Management reviews skip innovation as an agenda item | 5 | 55 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| IMS scope undefined or inconsistent across business units | 5 | 55 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Internal capability gaps not assessed against strategy | 5 | 55 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Internal audits of IMS not scheduled | 5 | 50 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Governance forum lacks decision-making authority | 5 | 50 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Benchmarking against peers absent | 5 | 50 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Culture barriers to risk-taking not addressed by leadership | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Root cause analysis stops at symptom level | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Feedback loops from operations back to strategy missing | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Customer feedback not systematically captured | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| KPIs measure activity (idea count) not outcomes (revenue, adoption) | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Risk treatment plans absent for high-uncertainty bets | 5 | 45 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Roadmap not updated when strategy changes | 5 | 40 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Maturity reassessment skipped year over year | 5 | 40 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Lessons learned stored but never reused | 5 | 40 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Improvement register stale, items older than 12 months unactioned | 5 | 35 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Innovation policy not formally approved or communicated | 5 | 35 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Corrective actions closed without verifying effectiveness | 5 | 30 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Nonconformities not logged or trended | 5 | 25 | ISO 22313:2020, ISO 37002:2021, ISO 39001:2012 |
| Board reporting cadence not formalised | 5 | 23 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Roles overlap without clear accountable owner | 5 | 23 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Unclear escalation thresholds | 5 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Long-lived tokens | 5 | 14 | AWS Well-Architected Security Pillar, ISO 27017, ISO 27018 |
| Recovery untested | 5 | 12 | AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes |
| Metrics absent | 5 | 9 | COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook |
| Scope unclear | 5 | 9 | GLI-33, HKMA Cyber Resilience Assessment Framework (C-RAF), ISO/IEC 27014:2020 |
| Scope ambiguous | 5 | 9 | Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22000, ISO/IEC 23837 |
| Role based training not delivered to high risk teams | 5 | 9 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Training metrics not reported to leadership | 5 | 9 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Evidence not retained | 5 | 8 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Unclear roles | 5 | 7 | APRA CPS 234, Azure Security Benchmark, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) |
| No closure tracking | 5 | 7 | AS9100D, Argyris Double-Loop Learning, BSIMM |
| No session recording | 5 | 7 | API 1164, BSI IT-Grundschutz, FFIEC Cybersecurity Assessment Tool (CAT) |
| No periodic refresh | 5 | 6 | AS9100D, ISO 19650, ISO 9001 |
| No screening | 5 | 6 | Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes, CMMC 2.0 |
| no monitoring | 5 | 6 | Azure Security Benchmark, BREEAM, DAMA-DMBOK2 |
| No methodology | 5 | 6 | Azure Security Benchmark, C2M2, ISO/IEC 27004:2016 |
| Correction requests not actioned | 5 | 6 | AICPA Privacy Management Framework (PMF), APPI, Australia Consumer Data Right |
| No exit confirmation AI management, Enterprise risk management | 5 | 6 | ISO 15189:2022, ISO 19011, ISO 27018 |
| Risk register not refreshed on a defined cadence | 5 | 5 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| No documented lawful basis | 5 | 5 | African Union Malabo Convention, Danish Data Protection Act (Databeskyttelsesloven), Data Protection Act 2017 |
| No phishing simulation | 5 | 5 | Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Lloyd's Minimum Standards |
| Requests not actioned | 5 | 5 | Australia eSafety Commissioner, Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), Azerbaijan Law on Personal Data (2010) |
| Claims not handled | 5 | 5 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Module absent | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| Exclusions unjustified | 5 | 5 | AS9100D, AS9100D:2016, ISO 13485 |
| Remediation not tracked | 5 | 5 | AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Bermuda Personal Information Protection Act 2016 (PIPA) |
| No maturity baseline | 5 | 5 | ISO 31000, ISO 37301, ISO 55001 |
| no annual refresh | 5 | 5 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Illinois Biometric Information Privacy Act (BIPA) |
| No phishing tests | 5 | 5 | FedRAMP High, FedRAMP Moderate, ISO 27799 |
| Backups unencrypted | 5 | 5 | 3GPP 5G Security Architecture (TS 33.501), CISA Zero Trust Maturity Model, FedRAMP High |
| Identity verification weak (impersonation risk) | 5 | 5 | Indonesia PDP Law, Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022) |
| Findings not closed | 5 | 5 | BRCGS Global Standard for Food Safety Issue 9, ISO 37001, ISO 37002:2021 |
| Missing FedRAMP banner language | 5 | 5 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW |
| no concentration analysis | 5 | 5 | BS 65000:2014, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook |
| Patches exceed SLA | 5 | 5 | NIS2 Directive, NIS2 Directive Implementing Acts, NIST SP 800-123 |
| unauthenticated scans only | 5 | 5 | Cyber Essentials Plus, FedRAMP High, FedRAMP Moderate |
| Slow response | 5 | 5 | LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data |
| No continuous monitoring | 5 | 5 | Australia IRAP, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-122 |
| No key management | 5 | 5 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2, NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) |
| No independent assurance | 5 | 5 | ISO 22317, ISO 30414:2018, ISO/IEC 29100:2024 |
| Inherent vs residual risk scoring not documented | 5 | 5 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Shared accounts in use | 5 | 5 | BSI IT-Grundschutz, Cyber Essentials Plus, ISO 28001:2007 Supply Chain Security Management |
| No effectiveness check Enterprise risk management | 5 | 5 | AS9100D:2016, ISO 15189:2022, ISO 19011 |
| No age verification | 5 | 5 | Illinois Biometric Information Privacy Act (BIPA), Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Nebraska Data Privacy Act |
| Reasonable care defence undocumented | 5 | 5 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Controls not traced to risks | 5 | 5 | AS9100D, AS9100D:2016, ISO 13485 |
| compliance nominal not operational | 4 | 32 | Oman Personal Data Protection Law (Royal Decree 6/2022), Ontario Accessibility for Ontarians with Disabilities Act (AODA), Open Banking Security |
| Unmanaged endpoints | 4 | 29 | Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, PCI P2PE, PCI PIN Security |
| Scope boundaries unclear for cloud services | 4 | 27 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Change records missing rollback evidence | 4 | 16 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| Operational controls not linked to risks | 4 | 16 | AS9100D, AS9100D:2016, ASIS SPC.1-2009 |
| default credentials | 4 | 16 | NIST SP 800-123, PCI P2PE, PCI PIN Security |
| No exit plan | 4 | 16 | BSI IT-Grundschutz, PCI P2PE, PCI PIN Security |
| Access reviews skipped or rubber-stamped | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Stale or dormant accounts not deprovisioned | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| MFA not enforced for privileged or remote access | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Shared or generic accounts retained | 4 | 14 | BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML) |
| Playbooks untested for major scenarios | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Forensic readiness lacking outside core systems | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Audit findings without closure dates | 4 | 13 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Lessons learned never closed out | 4 | 13 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| stale policies | 4 | 13 | DAMA-DMBOK2, PCI P2PE, PCI PIN Security |
| Policy not communicated | 4 | 13 | AS9100D:2016, EASA Part-IS, ISO 30401 |
| Management review skipped one or more cycles | 4 | 12 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Management review skipped Enterprise risk management | 4 | 12 | EASA Part-IS, ISO 27005, ISO 31000 |
| Lessons not shared | 4 | 11 | ISO 20400:2017, ISO 45001, ISO 9001 |
| Inventory incomplete | 4 | 9 | FBI CJIS Security Policy, ISO/IEC 27004:2016, ISO/IEC 27011:2024 |
| No independent assessment | 4 | 9 | CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-128 |
| No traceability | 4 | 9 | BSIMM, COBIT 2019, ISO 26262:2018 |
| Tabletop exercises not run in last 12 months | 4 | 8 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Metrics not tied to outcomes | 4 | 8 | ISO 30401, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| Detection coverage not mapped to MITRE ATT&CK | 4 | 8 | AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) |
| Annual-only review | 4 | 8 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Coverage gaps | 4 | 7 | BSIMM, CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, NIST SP 800-171 |
| No independent review | 4 | 6 | APRA CPS 230 Operational Risk Management, Canada Artificial Intelligence and Data Act (AIDA), IEC 62304:2015 Medical Device Software Lifecycle Processes |
| Inventory stale | 4 | 6 | Australian Energy Sector Cyber Security Framework (AESCSF), C2M2, FFIEC Cybersecurity Assessment Tool (CAT) |
| no key rotation | 4 | 6 | FFIEC IT Examination Handbook, ISO/IEC 27010:2015, NIST SP 800-171 Rev 3 |
| No automated-decision opt-out | 4 | 5 | Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| No verification step | 4 | 5 | FedRAMP High, ISO 22313:2020, ISO 22320:2018 |
| Drift not detected | 4 | 5 | AWS Well-Architected Security Pillar, NIST SP 800-137, NIST SP 800-171 |
| Inadequate security measures | 4 | 5 | APPI, Argentina Law 25.326 (Personal Data Protection Law), Azerbaijan Law on Personal Data (2010) |
| Actions not tracked | 4 | 5 | ISO 22000, ISO 37001, ISO 37002:2021 |
| No correction workflow | 4 | 5 | ISO 27018, ISO/IEC 27018:2019, NIST SP 800-53 Rev 5 LOW |
| Methodology inconsistent | 4 | 5 | EASA Part-IS, GHG Protocol, NIST SP 800-171 |
| Late notification | 4 | 5 | ISO/IEC 27007:2020, NIST SP 800-122, Nigeria Data Protection Regulation (NDPR) |
| Alerts not triaged | 4 | 5 | ASIC Cyber Resilience Good Practices, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), IEC 62351 |
| Audit trail incomplete | 4 | 5 | ASEAN Guide on AI Governance and Ethics, French Sapin II Law (Law No. 2016-1691), ISO/IEC 17025:2017 |
| Manual ticket-only provisioning | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| RTO undefined | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Siloed plans | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Manual inventory | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No spam protection | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Findings closed without verification | 4 | 4 | ISO 15189:2022, ISO/IEC 17025:2017, NY DFS 23 NYCRR 500 |
| Timeout over 15 minutes | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Lawful mechanism not chosen per transfer | 4 | 4 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Subject notification skipped (high-risk underestimated) | 4 | 4 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Sensitive categories not identified | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| No enhanced safeguards | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Transfers not inventoried | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Resources allocated only at start of year Occupational health and safety | 4 | 4 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011 |
| Effectiveness not measured | 4 | 4 | Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, ISO/SAE 21434, NIST SP 800-181 |
| No documented review cadence | 4 | 4 | FBI CJIS Security Policy, HIPAA Security Rule, NIST SP 800-172 |
| No PbD in development | 4 | 4 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Inadequate logging | 4 | 4 | Australian Energy Sector Cyber Security Framework (AESCSF), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, NIST SP 800-123 |
| Retention shorter than required | 4 | 4 | ISO 13485, ISO 15189:2022, ISO 19011 |
| No drift detection | 4 | 4 | DISA Security Technical Implementation Guides (STIGs), ISO 27017, Lloyd's Minimum Standards |
| No leading indicators | 4 | 4 | ASIS SPC.1-2009, ISO 37001, ISO 45001 |
| No processor contracts | 4 | 4 | Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| No portability format | 4 | 4 | Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Sensitive data unencrypted | 4 | 4 | AICPA SOC 3, APRA CPS 234, ASIC Cyber Resilience Good Practices |
| no completion tracking | 4 | 4 | C5 (Germany), Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017 |
| Definitions not applied | 4 | 4 | Botswana Data Protection Act (2024), Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020) |
| No remediation tracking | 4 | 4 | BIMCO Cyber Security, CFTC System Safeguards (17 CFR 37, 38, 39, 49), NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) |
| Emergency accounts persist | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No risk assessment | 4 | 4 | Australia My Health Records Act 2012, Authorised Economic Operator (AEO) Programmes, NIST Privacy Framework |
| No method statement Occupational health and safety | 4 | 4 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011 |
| Corrections not actioned | 4 | 4 | Canadian PIPEDA, Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA) |
| No communication plan Enterprise risk management | 4 | 4 | APRA CPS 230 Operational Risk Management, ASIC Cyber Resilience Good Practices, Australian Energy Sector Cyber Security Framework (AESCSF) |
| register incomplete | 4 | 4 | FBI CJIS Security Policy, FFIEC IT Examination Handbook, ISO 27799 |
| No access controls | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Children without parental consent | 4 | 4 | LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020) |
| Consent not demonstrable | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Processing wrongly scoped out | 4 | 4 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Annual cycle ad-hoc | 4 | 4 | GLI-33, GS1 Global Standards, Global Cross-Border Privacy Rules (Global CBPR) Forum |
| Multi-theory integration ad-hoc | 4 | 4 | Full Range Leadership Model (Bass & Avolio), Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework |
| No remote session logging | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Transfers without mapping (cloud sprawl) | 4 | 4 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| 30-day SLA frequently missed | 4 | 4 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Downstream propagation absent (siloed responses) | 4 | 4 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Personal containers unencrypted | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No application control | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No security on CAB | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No pre-prod testing | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No travel device program | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No independent ConMon | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Stack traces exposed | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Backups never restored | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| All admins see all logs | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No detection rules | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Command text not captured | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No sharing review process | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No bastion enforcement | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Non-accredited assessor | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Split tunneling allowed | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Non-FIPS ciphers enabled | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Setuid binaries unaudited | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No PAM session logs | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Undocumented sec-admin access | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No rollback capability | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| USB unrestricted | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No allowlisting | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No automated expiry | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Inactive accounts active over 35 days | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No alerts on account changes | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No data inventory | 4 | 4 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No verification | 4 | 4 | FedRAMP High, NIST SP 800-53 Revision 5.1 HIGH, New Jersey Data Privacy Act |
| Stale notice | 4 | 4 | NIST Privacy Framework, Nebraska Data Privacy Act, New Hampshire Data Privacy Act |
| No peer review | 4 | 4 | Argyris Double-Loop Learning, IAIS Insurance Core Principles (ICPs), ISO 27019 |
| stale review | 4 | 4 | Azure Security Benchmark, BREEAM, BS 65000:2014 |
| TI not actioned | 4 | 4 | BSI IT-Grundschutz, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE |
| No automated deprovisioning | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No coordination with HR/legal | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Independent testing only | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| Admins browse with admin | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No rogue detection | 4 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE |
| No exec sponsor | 4 | 4 | Azure Security Benchmark, ISO 22313:2020, ISO 22318 |
| Untested backups | 3 | 70 | Australian Information Security Manual, Azure Security Benchmark, NERC CIP |
| No awareness training | 3 | 55 | Australian Information Security Manual, BSIMM, NAIC Insurance Data Security Model Law (MDL-668) |
| Stakeholder needs not refreshed annually | 3 | 26 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No data classification | 3 | 21 | BSIMM, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Lloyd's Minimum Standards |
| Consent not granular | 3 | 19 | NIST SP 800-53 Rev 5, SOC 2, SSAE 18 |
| Weak authentication | 3 | 18 | Brazil Open Finance (Resolução Conjunta No. 1/2020), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-123 |
| single vendor dependency | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| missing comms tree | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Critical systems not forwarding logs | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No tamper-evident protections on logs | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| late notifications | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| no card brand contact | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| missing AOCs | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| weak key rotation | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| weak forensic preservation | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Retention shorter than regulatory minimum | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| weak responsibility matrix | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Time drift on legacy systems | 3 | 15 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| expired attestations | 3 | 15 | PCI P2PE, PCI PIN Security, PCI SSF |
| Operating criteria not documented for SEUs | 3 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Commissioning does not verify energy performance | 3 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| undefined accountability | 3 | 12 | PCI P2PE, PCI PIN Security, PCI SSF |
| Root cause analysis is symptomatic only | 3 | 12 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Design briefs silent on energy | 3 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No penetration testing | 3 | 12 | BSIMM, CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 |
| missing risk appetite | 3 | 12 | PCI P2PE, PCI PIN Security, PCI SSF |
| No life cycle cost analysis | 3 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Maintenance focused on uptime not energy | 3 | 12 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No baselines | 3 | 11 | Australian Energy Sector Cyber Security Framework (AESCSF), CMMC 2.0, NIST Privacy Framework |
| Logs not reviewed | 3 | 11 | Australia My Health Records Act 2012, BIMCO Cyber Security, CMMC 2.0 |
| No automated drift detection | 3 | 11 | BSI IT-Grundschutz, Belgium CyberFundamentals, NIST SP 1800-32 |
| Policy not reviewed annually | 3 | 10 | BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 27043 |
| Effectiveness checks not performed | 3 | 10 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Setpoints drift between shifts | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Energy specifications not communicated to suppliers | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Suppliers not assessed against energy criteria | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Procurement decisions based on capex only | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Outsourced providers have no energy obligations | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Continual improvement not demonstrated through EnPIs | 3 | 9 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Decisions undocumented | 3 | 8 | ISO 27043, ISO 27799, ISO/IEC 27014:2020 |
| Benefits not tracked | 3 | 7 | Authorised Economic Operator (AEO) Programmes, COBIT 2019, ISO 9001 |
| Risk appetite undefined | 3 | 7 | C2M2, COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT) |
| Environmental excursions not investigated | 3 | 6 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Control implemented without explicit link to the EnMS | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Top management oversight not evidenced | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Change management bypasses energy review | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Energy performance impact not assessed | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No life cycle energy assessment for purchases | 3 | 6 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Policy not aligned to control statement | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Keys stored alongside encrypted data | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No simulations | 3 | 5 | FedRAMP High, ISO/IEC 27011:2024, NIST SP 800-53 Revision 5.1 HIGH |
| No SLA tracking | 3 | 5 | COBIT 2019, ISO 27018, ISO/IEC 27004:2016 |
| Procedure undocumented | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Use of deprecated ciphers or self-signed certificates | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| No periodic monitoring | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| SCCs not updated to current versions | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| No transfer impact assessment performed | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Reliance on adequacy without supplementary measures | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| Sub-processor transfers untracked | 3 | 5 | Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019 |
| No documented rotation schedule | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| Consent records lack timestamp or version | 3 | 5 | AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017 |
| Inconsistent encryption coverage across data stores | 3 | 5 | BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals |
| split tunneling enabled | 3 | 4 | FedRAMP High, FedRAMP Moderate, NIST SP 800-171 Rev 3 |
| No verification vs validation distinction | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| Emergency changes bypass review | 3 | 4 | FBI CJIS Security Policy, NIST SP 800-171 Rev 3, NIST SP 800-53 Rev 5 |
| Supplier de-listing not executed | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| Auditors not independent of audited area | 3 | 4 | ISO 15189:2022, ISO 37301, ISO/IEC 17025:2017 |
| Critique not engaged | 3 | 4 | Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework, Hersey & Blanchard Situational Leadership Model |
| Lessons learned not actioned | 3 | 4 | EASA Part-IS, NIST SP 800-171 Rev 3, PCI DSS 4.0 |
| Sectoral coordination ad-hoc | 3 | 4 | FTC GLBA Safeguards Rule (16 CFR Part 314), Georgia Law on Personal Data Protection (2012), Ghana Data Protection Act 2012 (Act 843) |
| No customer notification | 3 | 4 | ISO 27018, ISO/IEC 27018:2019, Nigeria Open Banking Regulatory Framework (CBN, 2023) |
| Selection undocumented | 3 | 4 | Canada ITSG-33, ISO/IEC 27007:2020, MARS-E |
| Out of date records | 3 | 4 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No drift monitoring AI risk management | 3 | 4 | Canada Artificial Intelligence and Data Act (AIDA), ISO/IEC 23894:2023, PCI DSS 4.0 |
| Findings not tracked to closure | 3 | 4 | Automotive SPICE (ASPICE) v4.0, ISO 37000:2021, Illinois Biometric Information Privacy Act (BIPA) |
| Scrap not physically destroyed | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No MRB for use-as-is | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No flowdown of customer reqs | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| Contractors not screened | 3 | 4 | ISO 27019, NIST SP 800-171 Rev 3, PCI DSS 4.0 |
| weak governance | 3 | 4 | Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-122 |
| no egress filtering | 3 | 4 | AWS Well-Architected Security Pillar, Azure Security Benchmark, NIST SP 800-171 Rev 3 |
| Supervisory engagement weak | 3 | 4 | HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM, HKMA TM-G-1 |
| No performance evidence | 3 | 4 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Responsibilities undefined | 3 | 4 | Botswana Data Protection Act (2024), Brazil Open Finance (Resolução Conjunta No. 1/2020), C2M2 |
| Records incomplete | 3 | 4 | EASA Part-IS, FBI CJIS Security Policy, NIST SP 800-53 Rev 5 |
| Lessons not captured | 3 | 4 | ISO 37000:2021, ISO 37001, ISO/IEC 27003:2017 |
| Missing insurance coverage | 3 | 4 | ISO/IEC 17025:2017, ISO/IEC 27006:2024, South Korea PIPA |
| No measurement of effectiveness | 3 | 4 | HIPAA Security Rule, ISO/IEC 27007:2020, NIST SP 800-66 Rev 2 |
| No defined review cadence | 3 | 4 | Bahrain PDPL, Barbados Data Protection Act 2019, ISO/IEC 27031:2011 |
| No risk appetite statement | 3 | 4 | APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), COBIT 2019 |
| No attestation | 3 | 4 | Azure Security Benchmark, ISO 27017, NIST SP 800-144 |
| No access mechanism | 3 | 4 | APPI, Angola Personal Data Protection Law (Law No. 22/11), Argentina Law 25.326 (Personal Data Protection Law) |
| Late changes uncontrolled | 3 | 4 | AS9100D, AS9100D:2016, ISO/IEC 27003:2017 |
| No behavior baseline | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| Reference material traceability not documented to SI where applicable | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No SCRM strategy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Over-collection beyond stated purpose | 3 | 3 | China Personal Information Protection Law (PIPL), Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA) |
| Stale compliance review | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, Nigeria Data Protection Act 2023 (NDPA) |
| No subprocessor visibility | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Missing NIST alignment | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| No minimisation justification | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| No applicability memo | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Overseas disclosure without safeguards | 3 | 3 | Australia Consumer Data Right, Australian Privacy Principles (APPs), Consumer Data Right (CDR) Framework (Australia) |
| POA&Ms stale | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No CI mapping for the organization | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No board visibility | 3 | 3 | BS 65000:2014, Illinois Biometric Information Privacy Act (BIPA), PCI DSS 4.0 |
| Trends not reviewed in management review | 3 | 3 | 21 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017 |
| Budget not tracked separately | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No data discovery | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No Code of Conduct adoption | 3 | 3 | Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Lithuania Law on Legal Protection of Personal Data (2018) |
| Complaints not handled or escalated | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Reassessment intervals not defined | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Role split between functions | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Statutory timeframes missed | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Plan stale or generic | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Risk monitoring siloed | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Roadmap not tracked | 3 | 3 | GAMP 5, Global Cross-Border Privacy Rules (Global CBPR) Forum, HKMA Cyber Resilience Assessment Framework (C-RAF) |
| Lot bridging absent for critical assays | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical suppliers single sourced | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Performance verification skipped after relocation | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Subcontracted personnel competence not verified | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Surge capacity not planned for outbreak scenarios | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Locum induction not recorded | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical reagents single sourced without contingency | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Referral labs used without accreditation evidence | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Critical suppliers not risk assessed | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Backup analysers not maintained to same standard | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Traceability chain broken to manufacturer working calibrators | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Reference material lot changes not bridged | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Storage of patient samples not segregated from reagents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No periodic review of agreements | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No outcome metrics | 3 | 3 | ISO 26000:2010, ISO 37000:2021, LEADS in a Caring Environment |
| Records dispersed and not centrally managed | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| No 72-hour notification capability | 3 | 3 | Egypt Personal Data Protection Law (Law No. 151 of 2020), Malta Data Protection Act (Cap. 586, 2018), Montenegro Law on Personal Data Protection (2023) |
| Material changes not notified | 3 | 3 | Authorised Economic Operator (AEO) Programmes, Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Kenya Data Protection Act |
| Sensitive data uncategorised (treated as general) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Lawful basis selected after processing (consent bias) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| RoPA missing or incomplete | 3 | 3 | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), Fiji Data Protection Bill (2020), Georgia Law on Personal Data Protection (2012) |
| Notice misaligned with actual processing | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Privacy notices out of date | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Monitoring gaps | 3 | 3 | COBIT 2019, FBI CJIS Security Policy, ISO 22000 |
| Disposal informal | 3 | 3 | COBIT 2019, ISO 27043, ISO 27799 |
| No feedback loop | 3 | 3 | COBIT 2019, ISO 20400:2017, Kotter 8-Step Change Model |
| plan untested | 3 | 3 | AWS Well-Architected Security Pillar, FFIEC IT Examination Handbook, ISO 28001:2007 Supply Chain Security Management |
| No external comms | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| No benchmarking | 3 | 3 | ISO 39001:2012, ISO 45001, ISO 55001 |
| No accountability | 3 | 3 | AWS Well-Architected Security Pillar, C2M2, ISO 22000 |
| No federation | 3 | 3 | AWS Well-Architected Security Pillar, MARS-E, NIST SP 800-144 |
| No segmentation | 3 | 3 | AWS Well-Architected Security Pillar, BIMCO Cyber Security, Nevada Gaming Control Board Cybersecurity Requirements |
| stale strategy | 3 | 3 | Azure Security Benchmark, NIST SP 800-137, NIST SP 800-161 Rev 1 |
| short retention | 3 | 3 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Azure Security Benchmark, PCI DSS 4.0 |
| keys not rotated | 3 | 3 | C5 (Germany), NIST SP 800-150, PCI DSS 4.0 |
| reviews overdue | 3 | 3 | C5 (Germany), ISO 15189:2022, ISO/IEC 17025:2017 |
| Training stale | 3 | 3 | ISO 27043, ISO 27799, PCI DSS 4.0 |
| No restore tests | 3 | 3 | ISO 22317, ISO 27019, PCI DSS 4.0 |
| Supplier performance not monitored | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No DPA register | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Purpose creep | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Brazil Open Finance (Resolução Conjunta No. 1/2020), New Hampshire Data Privacy Act |
| No stress testing | 3 | 3 | APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), IAIS Insurance Core Principles (ICPs) |
| No community engagement | 3 | 3 | Australia NHMRC National Statement on Ethical Conduct in Human Research, BREEAM, LEADS in a Caring Environment |
| No root cause | 3 | 3 | ISO 28001:2007 Supply Chain Security Management, ISO/IEC 25012:2008, ISO/IEC 27003:2017 |
| Documentation only for notified breaches | 3 | 3 | Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act |
| Visitor escorts not enforced | 3 | 3 | HIPAA Security Rule, NIST Cybersecurity Framework 2.0, NIST SP 800-66 Rev 2 |
| Certificates of destruction not retained | 3 | 3 | HIPAA Security Rule, ISO/IEC 27701:2019, NIST SP 800-66 Rev 2 |
| Removable media unrestricted | 3 | 3 | Cyber Essentials Plus, HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| No tracking of completion | 3 | 3 | C5 (Germany), HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| Re-screening not performed | 3 | 3 | HIPAA Security Rule, ISO 37001, NIST SP 800-66 Rev 2 |
| No BCR approval procedure | 3 | 3 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Reviews not performed | 3 | 3 | ISO 22318, NIST SP 800-171, PCI DSS 4.0 |
| Generic training only | 3 | 3 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NFPA 1600, NIST SP 800-171 |
| No certificate of destruction | 3 | 3 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FBI CJIS Security Policy, NIST SP 800-171 |
| No annual pen test | 3 | 3 | BSI IT-Grundschutz, Lloyd's Minimum Standards, New Zealand Information Security Manual (NZISM) |
| DSAR portal absent (email-only handling) | 3 | 3 | Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act |
| no breach response | 3 | 3 | Australian Privacy Principles (APPs), FFIEC IT Examination Handbook, Nevada Gaming Control Board Cybersecurity Requirements |
| Briefings irregular | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| Auditors not independent | 3 | 3 | ISO 22313:2020, ISO 30401, ISO 9001 |
| No Whistleblower integration | 3 | 3 | Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) |
| No configuration baselines | 3 | 3 | ASIC Cyber Resilience Good Practices, C2M2, CFTC System Safeguards (17 CFR 37, 38, 39, 49) |
| Changes made without change control | 3 | 3 | Annex 11 to EU GMP, Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2 |
| Sectoral coordination weak | 3 | 3 | GS1 Global Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM |
| no remediation | 3 | 3 | Argyris Double-Loop Learning, ISO 37002:2021, PCI DSS 4.0 |
| Standing privileged access | 3 | 3 | Azure Security Benchmark, CISA Zero Trust Maturity Model, DoD Zero Trust Reference Architecture |
| No access logging | 3 | 3 | Australia My Health Records Act 2012, Laos Law on Prevention and Combating Cybercrime (2015), PCI DSS 4.0 |
| Templates outdated | 3 | 3 | ISO 22313:2020, ISO 22317, NIST SP 800-161 |
| No management review | 3 | 3 | BIMCO Cyber Security, ISO/IEC 27003:2017, Illinois Biometric Information Privacy Act (BIPA) |
| No lessons captured | 3 | 3 | ISO 27043, ISO 56002, NIST SP 800-150 |
| no annual review evidence | 3 | 3 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NIST SP 800-61, NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems |
| Lessons learned not captured Enterprise risk management | 3 | 3 | ISO 31000:2018, NIST SP 800-128, Space ISAC (Information Sharing and Analysis Center) |
| Coverage incomplete | 3 | 3 | Australian Privacy Principles (APPs), BSIMM, PCI DSS 4.0 |
| International cooperation absent | 3 | 3 | French Sapin II Law (Law No. 2016-1691), Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843) |
| Contractors missing NDA Enterprise risk management | 3 | 3 | ISO 15189:2022, ISO 19011, ISO 31000:2018 |
| Use cases focused on IT, missing SWIFT-specific scenarios | 3 | 3 | ISO 13485, ISO 15189:2022, ISO 19011 |
| Reviews not minuted Enterprise risk management | 3 | 3 | ISO 13485, ISO 19011, ISO 31000:2018 |
| No purposing analysis | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Contractors untrained | 3 | 3 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO 22000, ISO 28001:2007 Supply Chain Security Management |
| No anonymous channel | 3 | 3 | 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), EASA Part-IS, ISO 37301 |
| No tracked SLA | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| De-identification public commitment missing | 3 | 3 | Maryland Online Data Privacy Act of 2024, Minnesota Consumer Data Privacy Act, Montana Consumer Data Privacy Act |
| Missing risk analysis | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| No formal ConMon strategy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No risk executive function | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No written programme | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Missing notice elements | 3 | 3 | Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Framing assumptions undocumented | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| DGB exists in name only | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Missing exemption documentation | 3 | 3 | NAIC Insurance Data Security Model Law (MDL-668), Nebraska Data Privacy Act, New Hampshire Data Privacy Act |
| No complaints process | 3 | 3 | Australia Consumer Data Right, Australia NHMRC National Statement on Ethical Conduct in Human Research, Australian Privacy Principles (APPs) |
| No collection notice | 3 | 3 | Australian Privacy Principles (APPs), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| EA not maintained | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No aging metric | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Dependencies not mapped | 3 | 3 | APRA CPS 230 Operational Risk Management, ISO 22313:2020, ISO/IEC 29134:2023 |
| Notifiable breaches not reported | 3 | 3 | Australian Energy Sector Cyber Security Framework (AESCSF), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO) |
| External comms ad hoc AI risk management | 3 | 3 | ISO 37002:2021, ISO/IEC 23894:2023, ISO/IEC 27003:2017 |
| Sampling plan not statistically justified | 3 | 3 | 21 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017 |
| Sectoral application gaps | 3 | 3 | GS1 Global Standards, HITECH Act, Hersey & Blanchard Situational Leadership Model |
| SPOFs unmitigated | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| CAPA backlog from prior inspections | 3 | 3 | EU Clinical Trials Regulation (CTR 536/2014), EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Medical Devices Regulation (MDR 2017/745) |
| Same metro zone | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No objection mechanism | 3 | 3 | African Union Malabo Convention, Angola Personal Data Protection Law (Law No. 22/11), Data Protection Act 2017 |
| Local-only logs | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| Unlimited concurrent sessions | 3 | 3 | FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH |
| No oversight of data matching | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Calibration providers not assessed for competence | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Surge capacity not planned | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Subcontracted resources not included in plan | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No disclosure register | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Appetite not approved at board level | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Cleaning frequency not based on risk | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Authorization granted without practical assessment | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No change triggers | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Budget cycles not aligned with method changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No SLA monitoring | 3 | 3 | AWS Well-Architected Security Pillar, CCPA/CPRA, NIST SP 800-144 |
| Plan unwritten | 3 | 3 | AS9100D:2016, ISO 20000-1, ISO 27005 |
| no governance | 3 | 3 | Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-144 |
| Flat OT network | 3 | 3 | IEC 62351, ISO 27019, NIST SP 800-82 Rev 3 |
| KPIs not defined Enterprise risk management | 3 | 3 | ISO 13485, ISO 19011, ISO 31000:2018 |
| No appeal process | 3 | 3 | Colorado Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act |
| Consent records weak (bundled + pre-ticked) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| Lessons learned not implemented | 3 | 3 | NIST SP 800-171, NIST SP 800-171A Rev 3, NIST SP 800-53 Rev 5 |
| Updates not communicated | 3 | 3 | ASEAN Data Management Framework, HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| Findings unremediated | 3 | 3 | COBIT 2019, HIPAA Security Rule, NIST SP 800-66 Rev 2 |
| No data subject breach notification | 3 | 3 | LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP) |
| Exceptions never expire | 3 | 3 | NIST SP 800-128, NIST SP 800-171, NIST SP 800-218 |
| lessons not implemented | 3 | 3 | FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook, NIST SP 800-82 Rev 3 |
| Feedback collected but not acted on | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ITIL 4 |
| No crisis communication plan | 3 | 3 | Belgium CyberFundamentals, DORA, EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) |
| No criminal-risk register | 3 | 3 | Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), South Korea PIPA |
| No DPIA for high-risk | 3 | 3 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA |
| No documented risk assessment | 3 | 3 | AICPA SOC 3, C-TPAT, NAIC Insurance Data Security Model Law (MDL-668) |
| keys never rotated | 3 | 3 | AWS Well-Architected Security Pillar, EASA Part-IS, PCI DSS 4.0 |
| Configuration drift unmanaged | 3 | 3 | ASIC Cyber Resilience Good Practices, AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF) |
| No transition plan | 3 | 3 | Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020), CDP (formerly Carbon Disclosure Project) |
| No regulatory mapping | 3 | 3 | ISO 15189:2022, ISO 27005, ISO/IEC 25012:2008 |
| Restore never tested | 3 | 3 | AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, ISO 27799 |
| No maturity assessment | 3 | 3 | BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150 |
| Non-APL products | 3 | 3 | FedRAMP High, FedRAMP Moderate, New Zealand Information Security Manual (NZISM) |
| Scope misunderstood | 3 | 3 | Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843), HITECH Act |
| No prior consultation | 3 | 3 | Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Nigeria Data Protection Act 2023 (NDPA) |
| Follow-ups close on promise not evidence Enterprise risk management | 3 | 3 | ISO 15189:2022, ISO 19011, ISO 31000:2018 |
| Logs collected but not parsed by SIEM | 3 | 3 | ISO 13485, ISO 15189:2022, ISO 19011 |
| Sampling not representative Enterprise risk management | 3 | 3 | 21 CFR Part 211, ISO 19011, ISO 31000:2018 |
| Context not refreshed AI risk management | 3 | 3 | ISO 30401, ISO/IEC 23894:2023, ISO/IEC 27003:2017 |
| No matching agreements | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Authorization stale | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No priority clauses | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Security not documented | 3 | 3 | Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO) |
| No revocation mechanism | 3 | 3 | Botswana Data Protection Act (2024), Connecticut Data Privacy Act (CTDPA), Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP |
| Correspondence not tracked | 3 | 3 | Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024) |
| Competence reassessment intervals not defined | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Authorization tied to job title rather than verified competence | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No evidence of practical assessment for new methods | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Training records missing for locum or agency staff | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Measurement uncertainty not estimated | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Resource gaps not surfaced before incidents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No link between scope changes and resource updates | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No external privacy reporting | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Evaluation criteria not documented | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Specifications not updated after method changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Supplier performance not reviewed annually | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Out of service equipment used for urgent work | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Production data copied to test | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Maintenance done by unqualified staff | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Software versions not tracked per analyser | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Segregation between incompatible activities unclear | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Access controls not enforced for visitors | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No record of authorization changes when methods change | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Workload not measured against capacity | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Resource gaps surfaced only after incidents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Reassessment overdue for long serving staff | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| New starter checklist incomplete | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Competence on rare assays not maintained | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Lot to lot verification skipped under pressure | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Expired reagents found in active stock | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Storage temperature deviations not actioned | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No process for handling unaccredited referral results | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Out of service status not flagged in LIS | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Maintenance carried out by users without training | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No verification after software upgrades | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Calibration intervals not justified by data | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| No measurement uncertainty estimate per assay | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Containment level not validated for new agents | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Cleaning and decontamination logs incomplete | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Agreements not updated when scope changes | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Turnaround time commitments not monitored | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Sample acceptance criteria not in writing | 3 | 3 | ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024 |
| Training not delivered | 3 | 3 | ISO 22739:2024, ISO 26000:2010, Kuwait Data Privacy Protection Regulation (KDPPR, 2021 |
| Modifications bypass design review | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Renewable or low carbon options not evaluated | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Energy considered only after design freeze | 3 | 3 | ISO 22313:2020, ISO 39001:2012, ISO 41001:2018 |
| Improvements not tracked | 3 | 3 | COSO Enterprise Risk Management (ERM) Framework (2017), ISO 20400:2017, ISO/IEC 17025:2017 |
| No 10-year supply-chain records | 3 | 3 | EU Cyber Resilience Act, EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Machinery Regulation (Regulation (EU) 2023/1230) |
| No breach notification process | 3 | 3 | Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014), Argentina Law 25.326 (Personal Data Protection Law), Data Protection Act 2017 |
| no remediation plan | 3 | 3 | Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FFIEC Cybersecurity Assessment Tool (CAT), PCI DSS 4.0 |
| Board reporting infrequent or absent | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V) |
| Breach detection passive (manual reports only) | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| Processor notification absent in contracts | 3 | 3 | Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act |
| SSN used as primary key | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Health PII commingled | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No SORN for in-scope systems | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Purposes drift after launch | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No authority assessment | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Vague lawful basis | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No privacy-specific policy | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No privacy program plan distinct from security | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No CUI clauses in contracts | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No threat-sharing memberships | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Testing siloed by system | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No role-based pathway | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No HR/Legal/IT working group | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Privacy considered only at the end | 3 | 3 | NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No transaction replay | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Unencrypted backups | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| No criticality tiers | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |
| Bluetooth/Wi-Fi enabled by default | 3 | 3 | FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH |