From the control library

How compliance programmes actually fail

689 distinct failure modes, taken from the control libraries themselves. Ranked by how many independent standards warn about the same one.

Updated

Why rank it this way

Every control in our corpus records how implementations commonly fail, written when that control was verified against its source document. Across 20,473 controls that is a large catalogue of what goes wrong, and the useful ordering is not our opinion of severity: it is how many separate standards, written by different bodies in different jurisdictions for different industries, independently warn about the same thing. Twenty-four frameworks converging on one failure is a stronger claim than any score we could invent.

Sorted by how many independent frameworks warn about the same failure, most-converged first. That ordering is a count, not our opinion of severity, and it puts the problems the whole industry agrees on at the top.

Failure modeFrameworks ControlsExamples of who warns
Roles undefined
2427APRA CPS 230 Operational Risk Management, APRA CPS 234, AWS Well-Architected Security Pillar
findings not remediated
1417AS9100D, AS9100D:2016, ASIC Cyber Resilience Good Practices
no annual review
13266th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Australian Information Security Manual, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Tooling fragmented
Enterprise risk management
1313GAMP 5, GHG Protocol, GLI-33
No periodic review
Enterprise risk management
1212COBIT 2019, FedRAMP High, FedRAMP Moderate
Bundled consent
1212Code of Conduct on Data Protection for Research (GDPR Article 40), LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Objectives not measurable
1122AS9100D:2016, ASIS SPC.1-2009, COSO Enterprise Risk Management (ERM) Framework (2017)
No retention schedule
1011ASIS SPC.1-2009, Bermuda Personal Information Protection Act 2016 (PIPA), Brunei Personal Data Protection Order 2022 (PDPO)
No sanctions exposure analysis
1010LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 172-13 on the Protection of Personal Data
No withdrawal mechanism
1010Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
Indefinite retention
910African Union Malabo Convention, Argentina Law 25.326 (Personal Data Protection Law), Armenia Law on Protection of Personal Data (2015)
Transfer without lawful basis
99Kuwait Data Privacy Protection Regulation (KDPPR, 2021, LGPD, Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018)
Flat networks
840Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, FFIEC IT Examination Handbook
no ongoing monitoring
820C-TPAT, C2M2, FFIEC IT Examination Handbook
no trend analysis
813BRCGS Global Standard for Food Safety Issue 9, FFIEC IT Examination Handbook, IEC 62304:2015 Medical Device Software Lifecycle Processes
Multi-framework alignment ad-hoc
810FTC GLBA Safeguards Rule (16 CFR Part 314), GHG Protocol, GRI Standards
Pipeline not tracked
89GLBA, GLI-33, GRI Standards
No inventory
89Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22739:2024, ISO 26000:2010
Tactical only
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
No insider threats
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
Catalogue not refreshed
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
Supplier incidents discovered through news rather than contractual notification
762FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1
Flow down clauses present in master agreements but missing from statements of work
755FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1
Counterfeit detection procedures absent for hardware refresh cycles
742FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1
Sub tier suppliers not identified for critical components
741FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1
Penetration tests scope narrow and exclude key applications
732COSO Internal Control, FedRAMP High, FedRAMP Moderate
Scan coverage gaps for containerised and ephemeral workloads
731COSO Internal Control, FedRAMP High, FedRAMP Moderate
Risk register entries lack named owner or due date
730COSO Internal Control, FedRAMP High, FedRAMP Moderate
No incident response plan
728Australian Information Security Manual, BIMCO Cyber Security, C2M2
Threat intelligence consumed but not operationalised into detections
725COSO Internal Control, FedRAMP High, FedRAMP Moderate
High severity vulnerabilities exceed remediation SLA without risk acceptance
724COSO Internal Control, FedRAMP High, FedRAMP Moderate
Vendor risk tier ratings static despite changes in service scope
721FedRAMP High, FedRAMP Moderate, NIST SP 800-161 Rev 1
Flat network
79AWS Well-Architected Security Pillar, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Annual review skipped
78FSSC 22000, FTC GLBA Safeguards Rule (16 CFR Part 314), French Sapin II Law (Law No. 2016-1691)
Shared admin accounts
783GPP 5G Security Architecture (TS 33.501), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO/IEC 27011:2024
No review cadence
78COBIT 2019, ISO 28001:2007 Supply Chain Security Management, ISO/IEC 27003:2017
Reviews skipped
AI risk management
78COBIT 2019, EASA Part-IS, FFIEC IT Examination Handbook
Register stale
77FBI CJIS Security Policy, FFIEC Cybersecurity Assessment Tool (CAT), ISO 27019
No encryption
77C2M2, LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020)
No certification
77Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Late responses
77NIST SP 800-122, Nebraska Data Privacy Act, Netherlands GDPR Implementation Act (UAVG
Effectiveness not verified
77ISO 28001:2007 Supply Chain Security Management, ISO 37002:2021, ISO 37301
No appeals path
77LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
ROPA incomplete
77BSI IT-Grundschutz, LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Missing training
77BS 65000:2014, NIS2 Directive, NIST Privacy Framework
Evidence is point in time rather than ongoing
6124AS9100D, AS9100D:2016, ASIS SPC.1-2009
Firewall rule base contains stale allow any entries
684FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Internal traffic between services unencrypted within trusted zones
684FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Control owner unclear or vacant
679AS9100D, AS9100D:2016, ASIS SPC.1-2009
No metric tracks control effectiveness
679AS9100D, AS9100D:2016, ASIS SPC.1-2009
Server room doors propped open during cooling failures
673FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Access reviews performed but exceptions never remediated
673FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
CCTV coverage gaps at loading docks and equipment delivery areas
672FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Role definitions drift from documented matrix without change control
667FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Legacy TLS versions remain enabled on external services
667FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Service accounts excluded from periodic recertification
662FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Clock drift across hosts breaks event correlation
659FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Emergency changes bypass CAB and lack retrospective review
659FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Privileged user activity not isolated for independent review
659FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Unauthorised software present on endpoints not flagged by tooling
658FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Federation trust relationships not reviewed when partnerships change
657FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Privileged accounts shared across administrators without individual accountability
657FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Cryptographic keys stored alongside the data they protect
655FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Vendor SOC reports collected but exceptions not analysed
655FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Contractor screening relies on vendor attestation without sampling
653FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
MFA exceptions granted indefinitely without compensating controls
651FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Flat networks expose sensitive workloads without segmentation
650FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Severity criteria inconsistent across teams leading to under reporting
647FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Environmental sensor alerts route to unmonitored mailboxes
646FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Tailgating observed without challenge during walkthroughs
646FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Critical patches deployed beyond the policy SLA without exception
646FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Open source components used without SBOM or licence review
645FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Tabletop exercises lack participation from business owners
645FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Alternate site capacity not validated against current load
645FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
EDR coverage gaps on legacy operating systems
645FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Code scan findings closed without verification of fix
644FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Sanctions applied informally without HR documentation
642FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Baselines exist on paper but production hosts drift without alerting
641FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Critical log sources missing from the SIEM with no detection coverage
641FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Stale accounts retained for terminated personnel beyond the 24 hour SLA
641FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Lessons learned captured but corrective actions not tracked to closure
641FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Continuous monitoring metrics collected but not reported to leadership
640FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Assessment scope omits inherited cloud provider controls
640FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
USB usage permitted without DLP inspection or encryption
639FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Decommissioned drives stored unencrypted while awaiting destruction
639FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Threat modelling performed inconsistently across product teams
639FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Reviewers acknowledge alerts but do not document investigation outcomes
636FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
RTO and RPO targets undefined for tier two systems
636FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Detection coverage gaps allow incidents to be discovered externally
635FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Alert backlog exceeds analyst capacity leading to triage delays
635FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Hardening benchmarks applied at build but not re evaluated annually
635FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Position risk designations not reviewed when responsibilities change
635FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Password complexity enforced but reuse not blocked across systems
635FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Shared accounts authenticate without traceability to individuals
634FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Visitor logs incomplete or escort sign offs missing
633FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
System security plan not refreshed after material system changes
633FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Plan not updated after major architecture changes
633FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Security requirements absent from procurement templates for low value buys
632FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Audit log retention shorter than the policy mandated period
630FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Asset inventory missing cloud workloads and ephemeral resources
629FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Background checks not re run when employees move to higher risk roles
629FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Termination access removal exceeds documented SLA
629FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Privacy considerations addressed separately from security planning
628FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Authorization boundary description does not match the asset inventory
628FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Vendor engineers granted standing access rather than session based access
628FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Rules of behaviour acknowledged once but not refreshed annually
627FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Phishing failures not followed by remedial coaching
625FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Role based training not refreshed when job duties change
625FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
POAM items past due without justification or risk acceptance
624FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Default vendor credentials remain on appliances and IoT devices
624FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Third party incident responder retainer expired
623FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Backups taken but restore tests never performed end to end
623FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Maintenance vendors lack signed confidentiality and security clauses
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Reauthorization scheduled past the policy required interval
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Anti malware signatures not updated on isolated network segments
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Remote maintenance sessions unmonitored after initial authentication
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Media classification labels missing on physical assets
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Destruction certificates lack serial numbers tying back to inventory
622FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Training content not reviewed annually for current threat trends
619FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Maintenance tools not sanitised before removal from secure areas
618FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Contractors and third parties not enrolled in mandatory training
618FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Notification timelines miss jurisdictional regulatory deadlines
618FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Planning artefacts lack version history and approval signatures
617FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Input validation handled inconsistently across microservices
617FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Backup tapes shipped without tamper evident packaging
617FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
no executive sponsor
616API 1164, ISO 8000, NIST SP 800-161
Architecture diagrams missing third party and SaaS dependencies
616FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
No evidence policies were communicated to staff
616AS9100D, AS9100D:2016, ASIS SPC.1-2009
Policies past their review date
616AS9100D, AS9100D:2016, ASIS SPC.1-2009
No procedure
611Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Internal traffic unencrypted
68AWS Well-Architected Security Pillar, ISO 27018, ISO/IEC 27018:2019
No role-based training
68CMMC 2.0, FedRAMP High, ISO 22313:2020
No audit trail
67Authorised Economic Operator (AEO) Programmes, ISO 27018, ISO 27043
Lessons not actioned
66Argyris Double-Loop Learning, ISO 22313:2020, ISO 22318
Metrics gaps
66GLI-33, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, GS1 Global Standards
no board reporting
66AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), FFIEC IT Examination Handbook, ISO 37002:2021
Visitor logs incomplete
66BRCGS Global Standard for Food Safety Issue 9, HIPAA Security Rule, NIST SP 800-171
Emergency maintenance performed without retrospective documentation
66FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5
Marketing without opt-in
66Law on Personal Data Protection (Official Gazette No. 42/2020), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018), Ley Orgánica de Protección de Datos Personales (LOPDP)
Metrics not tracked
66French Sapin II Law (Law No. 2016-1691), GAMP 5, GHG Protocol
Design-only testing
66AS9100D, AS9100D:2016, ISO 13485
shadow IT not captured
Enterprise risk management
66FFIEC Cybersecurity Assessment Tool (CAT), ISO 31000:2018, NIST SP 800-172
No tabletop exercises
66Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Kuwait National Cybersecurity Framework
No annual training
66Laos Law on Prevention and Combating Cybercrime (2015), Law on Personal Data Protection (Official Gazette No. 42/2020), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018)
IP register incomplete, ownership disputes likely
595ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Time allocation for innovation crowded out by BAU
585ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation budget not ring-fenced from operating budget
585ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Strategic intelligence siloed in one team
585ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Trend scanning is ad hoc and undocumented
580ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Stakeholder map omits external innovation partners (universities, startups)
580ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Partnership agreements lack IP and confidentiality clauses
580ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Competence requirements for innovation roles not defined
580ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Knowledge from past projects not captured or reused
575ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No resource plan tied to portfolio priorities
575ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Portfolio biased toward horizon 1 incremental projects
570ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Tools and methods inconsistent across teams
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation strategy disconnected from corporate strategy
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Executive sponsorship limited to lip service, no time committed
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Context analysis treated as one-off, not refreshed annually
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No clear accountability for innovation outcomes
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Opportunities and risks tracked separately with no link to objectives
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Lagging indicators only, no leading indicators
565ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Evaluation criteria differ across portfolio without rationale
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation maturity baseline never established
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Strategic intelligence not feeding into innovation decisions
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Roles and responsibilities for innovation undefined
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation objectives lack measurable targets
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Initiative prioritisation done by HiPPO not criteria
560ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Management reviews skip innovation as an agenda item
555ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
IMS scope undefined or inconsistent across business units
555ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Internal capability gaps not assessed against strategy
555ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Internal audits of IMS not scheduled
550ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Governance forum lacks decision-making authority
550ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Benchmarking against peers absent
550ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Culture barriers to risk-taking not addressed by leadership
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Root cause analysis stops at symptom level
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Feedback loops from operations back to strategy missing
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Customer feedback not systematically captured
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
KPIs measure activity (idea count) not outcomes (revenue, adoption)
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Risk treatment plans absent for high-uncertainty bets
545ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Roadmap not updated when strategy changes
540ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Maturity reassessment skipped year over year
540ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Lessons learned stored but never reused
540ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Improvement register stale, items older than 12 months unactioned
535ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation policy not formally approved or communicated
535ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Corrective actions closed without verifying effectiveness
530ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Nonconformities not logged or trended
525ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Board reporting cadence not formalised
523AS9100D, AS9100D:2016, ASIS SPC.1-2009
Roles overlap without clear accountable owner
523AS9100D, AS9100D:2016, ASIS SPC.1-2009
Unclear escalation thresholds
514BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Long-lived tokens
514AWS Well-Architected Security Pillar, ISO 27017, ISO 27018
Recovery untested
512AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes
Metrics absent
59COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook
Scope unclear
59GLI-33, HKMA Cyber Resilience Assessment Framework (C-RAF), ISO/IEC 27014:2020
Scope ambiguous
59Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22000, ISO/IEC 23837
Role based training not delivered to high risk teams
59AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Training metrics not reported to leadership
59AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Evidence not retained
58Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Unclear roles
57APRA CPS 234, Azure Security Benchmark, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
No closure tracking
57AS9100D, Argyris Double-Loop Learning, BSIMM
No session recording
57API 1164, BSI IT-Grundschutz, FFIEC Cybersecurity Assessment Tool (CAT)
No periodic refresh
56AS9100D, ISO 19650, ISO 9001
No screening
56Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes, CMMC 2.0
no monitoring
56Azure Security Benchmark, BREEAM, DAMA-DMBOK2
No methodology
56Azure Security Benchmark, C2M2, ISO/IEC 27004:2016
Correction requests not actioned
56AICPA Privacy Management Framework (PMF), APPI, Australia Consumer Data Right
No exit confirmation
AI management, Enterprise risk management
56ISO 15189:2022, ISO 19011, ISO 27018
Risk register not refreshed on a defined cadence
55AS9100D, AS9100D:2016, ASIS SPC.1-2009
No documented lawful basis
55African Union Malabo Convention, Danish Data Protection Act (Databeskyttelsesloven), Data Protection Act 2017
No phishing simulation
55Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Lloyd's Minimum Standards
Requests not actioned
55Australia eSafety Commissioner, Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), Azerbaijan Law on Personal Data (2010)
Claims not handled
55Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Module absent
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Exclusions unjustified
55AS9100D, AS9100D:2016, ISO 13485
Remediation not tracked
55AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Bermuda Personal Information Protection Act 2016 (PIPA)
No maturity baseline
55ISO 31000, ISO 37301, ISO 55001
no annual refresh
556th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Illinois Biometric Information Privacy Act (BIPA)
No phishing tests
55FedRAMP High, FedRAMP Moderate, ISO 27799
Backups unencrypted
553GPP 5G Security Architecture (TS 33.501), CISA Zero Trust Maturity Model, FedRAMP High
Identity verification weak (impersonation risk)
55Indonesia PDP Law, Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022)
Findings not closed
55BRCGS Global Standard for Food Safety Issue 9, ISO 37001, ISO 37002:2021
Missing FedRAMP banner language
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
no concentration analysis
55BS 65000:2014, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook
Patches exceed SLA
55NIS2 Directive, NIS2 Directive Implementing Acts, NIST SP 800-123
unauthenticated scans only
55Cyber Essentials Plus, FedRAMP High, FedRAMP Moderate
Slow response
55LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
No continuous monitoring
55Australia IRAP, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-122
No key management
55Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2, NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding)
No independent assurance
55ISO 22317, ISO 30414:2018, ISO/IEC 29100:2024
Inherent vs residual risk scoring not documented
55AS9100D, AS9100D:2016, ASIS SPC.1-2009
Shared accounts in use
55BSI IT-Grundschutz, Cyber Essentials Plus, ISO 28001:2007 Supply Chain Security Management
No effectiveness check
Enterprise risk management
55AS9100D:2016, ISO 15189:2022, ISO 19011
No age verification
55Illinois Biometric Information Privacy Act (BIPA), Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Nebraska Data Privacy Act
Reasonable care defence undocumented
55Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Controls not traced to risks
55AS9100D, AS9100D:2016, ISO 13485
compliance nominal not operational
432Oman Personal Data Protection Law (Royal Decree 6/2022), Ontario Accessibility for Ontarians with Disabilities Act (AODA), Open Banking Security
Unmanaged endpoints
429Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, PCI P2PE, PCI PIN Security
Scope boundaries unclear for cloud services
427AS9100D, AS9100D:2016, ASIS SPC.1-2009
Change records missing rollback evidence
416AS9100D, AS9100D:2016, ASIS SPC.1-2009
Operational controls not linked to risks
416AS9100D, AS9100D:2016, ASIS SPC.1-2009
default credentials
416NIST SP 800-123, PCI P2PE, PCI PIN Security
No exit plan
416BSI IT-Grundschutz, PCI P2PE, PCI PIN Security
Access reviews skipped or rubber-stamped
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Stale or dormant accounts not deprovisioned
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
MFA not enforced for privileged or remote access
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Shared or generic accounts retained
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Playbooks untested for major scenarios
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Forensic readiness lacking outside core systems
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Audit findings without closure dates
413AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Lessons learned never closed out
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
stale policies
413DAMA-DMBOK2, PCI P2PE, PCI PIN Security
Policy not communicated
413AS9100D:2016, EASA Part-IS, ISO 30401
Management review skipped one or more cycles
412AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Management review skipped
Enterprise risk management
412EASA Part-IS, ISO 27005, ISO 31000
Lessons not shared
411ISO 20400:2017, ISO 45001, ISO 9001
Inventory incomplete
49FBI CJIS Security Policy, ISO/IEC 27004:2016, ISO/IEC 27011:2024
No independent assessment
49CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-128
No traceability
49BSIMM, COBIT 2019, ISO 26262:2018
Tabletop exercises not run in last 12 months
48AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Metrics not tied to outcomes
48ISO 30401, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Detection coverage not mapped to MITRE ATT&CK
48AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Annual-only review
48FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Coverage gaps
47BSIMM, CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, NIST SP 800-171
No independent review
46APRA CPS 230 Operational Risk Management, Canada Artificial Intelligence and Data Act (AIDA), IEC 62304:2015 Medical Device Software Lifecycle Processes
Inventory stale
46Australian Energy Sector Cyber Security Framework (AESCSF), C2M2, FFIEC Cybersecurity Assessment Tool (CAT)
no key rotation
46FFIEC IT Examination Handbook, ISO/IEC 27010:2015, NIST SP 800-171 Rev 3
No automated-decision opt-out
45Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020)
No verification step
45FedRAMP High, ISO 22313:2020, ISO 22320:2018
Drift not detected
45AWS Well-Architected Security Pillar, NIST SP 800-137, NIST SP 800-171
Inadequate security measures
45APPI, Argentina Law 25.326 (Personal Data Protection Law), Azerbaijan Law on Personal Data (2010)
Actions not tracked
45ISO 22000, ISO 37001, ISO 37002:2021
No correction workflow
45ISO 27018, ISO/IEC 27018:2019, NIST SP 800-53 Rev 5 LOW
Methodology inconsistent
45EASA Part-IS, GHG Protocol, NIST SP 800-171
Late notification
45ISO/IEC 27007:2020, NIST SP 800-122, Nigeria Data Protection Regulation (NDPR)
Alerts not triaged
45ASIC Cyber Resilience Good Practices, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), IEC 62351
Audit trail incomplete
45ASEAN Guide on AI Governance and Ethics, French Sapin II Law (Law No. 2016-1691), ISO/IEC 17025:2017
Manual ticket-only provisioning
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
RTO undefined
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Siloed plans
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Manual inventory
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No spam protection
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Findings closed without verification
44ISO 15189:2022, ISO/IEC 17025:2017, NY DFS 23 NYCRR 500
Timeout over 15 minutes
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Lawful mechanism not chosen per transfer
44Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Subject notification skipped (high-risk underestimated)
44Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Sensitive categories not identified
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No enhanced safeguards
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Transfers not inventoried
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Resources allocated only at start of year
Occupational health and safety
44BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011
Effectiveness not measured
44Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, ISO/SAE 21434, NIST SP 800-181
No documented review cadence
44FBI CJIS Security Policy, HIPAA Security Rule, NIST SP 800-172
No PbD in development
44LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Inadequate logging
44Australian Energy Sector Cyber Security Framework (AESCSF), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, NIST SP 800-123
Retention shorter than required
44ISO 13485, ISO 15189:2022, ISO 19011
No drift detection
44DISA Security Technical Implementation Guides (STIGs), ISO 27017, Lloyd's Minimum Standards
No leading indicators
44ASIS SPC.1-2009, ISO 37001, ISO 45001
No processor contracts
44Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
No portability format
44Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Sensitive data unencrypted
44AICPA SOC 3, APRA CPS 234, ASIC Cyber Resilience Good Practices
no completion tracking
44C5 (Germany), Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017
Definitions not applied
44Botswana Data Protection Act (2024), Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020)
No remediation tracking
44BIMCO Cyber Security, CFTC System Safeguards (17 CFR 37, 38, 39, 49), NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Emergency accounts persist
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No risk assessment
44Australia My Health Records Act 2012, Authorised Economic Operator (AEO) Programmes, NIST Privacy Framework
No method statement
Occupational health and safety
44BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011
Corrections not actioned
44Canadian PIPEDA, Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA)
No communication plan
Enterprise risk management
44APRA CPS 230 Operational Risk Management, ASIC Cyber Resilience Good Practices, Australian Energy Sector Cyber Security Framework (AESCSF)
register incomplete
44FBI CJIS Security Policy, FFIEC IT Examination Handbook, ISO 27799
No access controls
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Children without parental consent
44LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020)
Consent not demonstrable
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Processing wrongly scoped out
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Annual cycle ad-hoc
44GLI-33, GS1 Global Standards, Global Cross-Border Privacy Rules (Global CBPR) Forum
Multi-theory integration ad-hoc
44Full Range Leadership Model (Bass & Avolio), Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework
No remote session logging
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Transfers without mapping (cloud sprawl)
44Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
30-day SLA frequently missed
44Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Downstream propagation absent (siloed responses)
44Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Personal containers unencrypted
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No application control
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No security on CAB
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No pre-prod testing
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No travel device program
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No independent ConMon
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Stack traces exposed
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Backups never restored
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
All admins see all logs
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No detection rules
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Command text not captured
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No sharing review process
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No bastion enforcement
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Non-accredited assessor
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Split tunneling allowed
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Non-FIPS ciphers enabled
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Setuid binaries unaudited
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No PAM session logs
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Undocumented sec-admin access
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No rollback capability
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
USB unrestricted
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No allowlisting
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No automated expiry
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Inactive accounts active over 35 days
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No alerts on account changes
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No data inventory
44FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No verification
44FedRAMP High, NIST SP 800-53 Revision 5.1 HIGH, New Jersey Data Privacy Act
Stale notice
44NIST Privacy Framework, Nebraska Data Privacy Act, New Hampshire Data Privacy Act
No peer review
44Argyris Double-Loop Learning, IAIS Insurance Core Principles (ICPs), ISO 27019
stale review
44Azure Security Benchmark, BREEAM, BS 65000:2014
TI not actioned
44BSI IT-Grundschutz, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
No automated deprovisioning
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No coordination with HR/legal
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Independent testing only
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Admins browse with admin
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No rogue detection
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No exec sponsor
44Azure Security Benchmark, ISO 22313:2020, ISO 22318
Untested backups
370Australian Information Security Manual, Azure Security Benchmark, NERC CIP
No awareness training
355Australian Information Security Manual, BSIMM, NAIC Insurance Data Security Model Law (MDL-668)
Stakeholder needs not refreshed annually
326AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No data classification
321BSIMM, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Lloyd's Minimum Standards
Consent not granular
319NIST SP 800-53 Rev 5, SOC 2, SSAE 18
Weak authentication
318Brazil Open Finance (Resolução Conjunta No. 1/2020), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-123
single vendor dependency
315PCI P2PE, PCI PIN Security, PCI SSF
missing comms tree
315PCI P2PE, PCI PIN Security, PCI SSF
Critical systems not forwarding logs
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No tamper-evident protections on logs
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
late notifications
315PCI P2PE, PCI PIN Security, PCI SSF
no card brand contact
315PCI P2PE, PCI PIN Security, PCI SSF
missing AOCs
315PCI P2PE, PCI PIN Security, PCI SSF
weak key rotation
315PCI P2PE, PCI PIN Security, PCI SSF
weak forensic preservation
315PCI P2PE, PCI PIN Security, PCI SSF
Retention shorter than regulatory minimum
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
weak responsibility matrix
315PCI P2PE, PCI PIN Security, PCI SSF
Time drift on legacy systems
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
expired attestations
315PCI P2PE, PCI PIN Security, PCI SSF
Operating criteria not documented for SEUs
312ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Commissioning does not verify energy performance
312ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
undefined accountability
312PCI P2PE, PCI PIN Security, PCI SSF
Root cause analysis is symptomatic only
312AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Design briefs silent on energy
312ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No penetration testing
312BSIMM, CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
missing risk appetite
312PCI P2PE, PCI PIN Security, PCI SSF
No life cycle cost analysis
312ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Maintenance focused on uptime not energy
312ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No baselines
311Australian Energy Sector Cyber Security Framework (AESCSF), CMMC 2.0, NIST Privacy Framework
Logs not reviewed
311Australia My Health Records Act 2012, BIMCO Cyber Security, CMMC 2.0
No automated drift detection
311BSI IT-Grundschutz, Belgium CyberFundamentals, NIST SP 1800-32
Policy not reviewed annually
310BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 27043
Effectiveness checks not performed
310AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Setpoints drift between shifts
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Energy specifications not communicated to suppliers
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Suppliers not assessed against energy criteria
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Procurement decisions based on capex only
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Outsourced providers have no energy obligations
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Continual improvement not demonstrated through EnPIs
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Decisions undocumented
38ISO 27043, ISO 27799, ISO/IEC 27014:2020
Benefits not tracked
37Authorised Economic Operator (AEO) Programmes, COBIT 2019, ISO 9001
Risk appetite undefined
37C2M2, COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT)
Environmental excursions not investigated
36ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Control implemented without explicit link to the EnMS
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Top management oversight not evidenced
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Change management bypasses energy review
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Energy performance impact not assessed
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No life cycle energy assessment for purchases
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Policy not aligned to control statement
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Keys stored alongside encrypted data
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No simulations
35FedRAMP High, ISO/IEC 27011:2024, NIST SP 800-53 Revision 5.1 HIGH
No SLA tracking
35COBIT 2019, ISO 27018, ISO/IEC 27004:2016
Procedure undocumented
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Use of deprecated ciphers or self-signed certificates
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No periodic monitoring
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
SCCs not updated to current versions
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
No transfer impact assessment performed
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Reliance on adequacy without supplementary measures
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Sub-processor transfers untracked
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
No documented rotation schedule
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Consent records lack timestamp or version
35AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Inconsistent encryption coverage across data stores
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
split tunneling enabled
34FedRAMP High, FedRAMP Moderate, NIST SP 800-171 Rev 3
No verification vs validation distinction
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
Emergency changes bypass review
34FBI CJIS Security Policy, NIST SP 800-171 Rev 3, NIST SP 800-53 Rev 5
Supplier de-listing not executed
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
Auditors not independent of audited area
34ISO 15189:2022, ISO 37301, ISO/IEC 17025:2017
Critique not engaged
34Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework, Hersey & Blanchard Situational Leadership Model
Lessons learned not actioned
34EASA Part-IS, NIST SP 800-171 Rev 3, PCI DSS 4.0
Sectoral coordination ad-hoc
34FTC GLBA Safeguards Rule (16 CFR Part 314), Georgia Law on Personal Data Protection (2012), Ghana Data Protection Act 2012 (Act 843)
No customer notification
34ISO 27018, ISO/IEC 27018:2019, Nigeria Open Banking Regulatory Framework (CBN, 2023)
Selection undocumented
34Canada ITSG-33, ISO/IEC 27007:2020, MARS-E
Out of date records
34ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No drift monitoring
AI risk management
34Canada Artificial Intelligence and Data Act (AIDA), ISO/IEC 23894:2023, PCI DSS 4.0
Findings not tracked to closure
34Automotive SPICE (ASPICE) v4.0, ISO 37000:2021, Illinois Biometric Information Privacy Act (BIPA)
Scrap not physically destroyed
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No MRB for use-as-is
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No flowdown of customer reqs
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
Contractors not screened
34ISO 27019, NIST SP 800-171 Rev 3, PCI DSS 4.0
weak governance
34Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-122
no egress filtering
34AWS Well-Architected Security Pillar, Azure Security Benchmark, NIST SP 800-171 Rev 3
Supervisory engagement weak
34HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM, HKMA TM-G-1
No performance evidence
34ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Responsibilities undefined
34Botswana Data Protection Act (2024), Brazil Open Finance (Resolução Conjunta No. 1/2020), C2M2
Records incomplete
34EASA Part-IS, FBI CJIS Security Policy, NIST SP 800-53 Rev 5
Lessons not captured
34ISO 37000:2021, ISO 37001, ISO/IEC 27003:2017
Missing insurance coverage
34ISO/IEC 17025:2017, ISO/IEC 27006:2024, South Korea PIPA
No measurement of effectiveness
34HIPAA Security Rule, ISO/IEC 27007:2020, NIST SP 800-66 Rev 2
No defined review cadence
34Bahrain PDPL, Barbados Data Protection Act 2019, ISO/IEC 27031:2011
No risk appetite statement
34APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), COBIT 2019
No attestation
34Azure Security Benchmark, ISO 27017, NIST SP 800-144
No access mechanism
34APPI, Angola Personal Data Protection Law (Law No. 22/11), Argentina Law 25.326 (Personal Data Protection Law)
Late changes uncontrolled
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No behavior baseline
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
Reference material traceability not documented to SI where applicable
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No SCRM strategy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Over-collection beyond stated purpose
33China Personal Information Protection Law (PIPL), Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA)
Stale compliance review
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, Nigeria Data Protection Act 2023 (NDPA)
No subprocessor visibility
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Missing NIST alignment
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
No minimisation justification
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
No applicability memo
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Overseas disclosure without safeguards
33Australia Consumer Data Right, Australian Privacy Principles (APPs), Consumer Data Right (CDR) Framework (Australia)
POA&Ms stale
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No CI mapping for the organization
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No board visibility
33BS 65000:2014, Illinois Biometric Information Privacy Act (BIPA), PCI DSS 4.0
Trends not reviewed in management review
3321 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017
Budget not tracked separately
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No data discovery
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No Code of Conduct adoption
33Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Lithuania Law on Legal Protection of Personal Data (2018)
Complaints not handled or escalated
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Reassessment intervals not defined
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Role split between functions
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Statutory timeframes missed
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Plan stale or generic
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Risk monitoring siloed
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Roadmap not tracked
33GAMP 5, Global Cross-Border Privacy Rules (Global CBPR) Forum, HKMA Cyber Resilience Assessment Framework (C-RAF)
Lot bridging absent for critical assays
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical suppliers single sourced
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Performance verification skipped after relocation
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Subcontracted personnel competence not verified
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Surge capacity not planned for outbreak scenarios
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Locum induction not recorded
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical reagents single sourced without contingency
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Referral labs used without accreditation evidence
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical suppliers not risk assessed
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Backup analysers not maintained to same standard
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Traceability chain broken to manufacturer working calibrators
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Reference material lot changes not bridged
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Storage of patient samples not segregated from reagents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No periodic review of agreements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No outcome metrics
33ISO 26000:2010, ISO 37000:2021, LEADS in a Caring Environment
Records dispersed and not centrally managed
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No 72-hour notification capability
33Egypt Personal Data Protection Law (Law No. 151 of 2020), Malta Data Protection Act (Cap. 586, 2018), Montenegro Law on Personal Data Protection (2023)
Material changes not notified
33Authorised Economic Operator (AEO) Programmes, Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Kenya Data Protection Act
Sensitive data uncategorised (treated as general)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Lawful basis selected after processing (consent bias)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
RoPA missing or incomplete
33Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), Fiji Data Protection Bill (2020), Georgia Law on Personal Data Protection (2012)
Notice misaligned with actual processing
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Privacy notices out of date
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Monitoring gaps
33COBIT 2019, FBI CJIS Security Policy, ISO 22000
Disposal informal
33COBIT 2019, ISO 27043, ISO 27799
No feedback loop
33COBIT 2019, ISO 20400:2017, Kotter 8-Step Change Model
plan untested
33AWS Well-Architected Security Pillar, FFIEC IT Examination Handbook, ISO 28001:2007 Supply Chain Security Management
No external comms
33AS9100D:2016, ISO 20000-1, ISO 27005
No benchmarking
33ISO 39001:2012, ISO 45001, ISO 55001
No accountability
33AWS Well-Architected Security Pillar, C2M2, ISO 22000
No federation
33AWS Well-Architected Security Pillar, MARS-E, NIST SP 800-144
No segmentation
33AWS Well-Architected Security Pillar, BIMCO Cyber Security, Nevada Gaming Control Board Cybersecurity Requirements
stale strategy
33Azure Security Benchmark, NIST SP 800-137, NIST SP 800-161 Rev 1
short retention
336th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Azure Security Benchmark, PCI DSS 4.0
keys not rotated
33C5 (Germany), NIST SP 800-150, PCI DSS 4.0
reviews overdue
33C5 (Germany), ISO 15189:2022, ISO/IEC 17025:2017
Training stale
33ISO 27043, ISO 27799, PCI DSS 4.0
No restore tests
33ISO 22317, ISO 27019, PCI DSS 4.0
Supplier performance not monitored
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No DPA register
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Purpose creep
33Bermuda Personal Information Protection Act 2016 (PIPA), Brazil Open Finance (Resolução Conjunta No. 1/2020), New Hampshire Data Privacy Act
No stress testing
33APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), IAIS Insurance Core Principles (ICPs)
No community engagement
33Australia NHMRC National Statement on Ethical Conduct in Human Research, BREEAM, LEADS in a Caring Environment
No root cause
33ISO 28001:2007 Supply Chain Security Management, ISO/IEC 25012:2008, ISO/IEC 27003:2017
Documentation only for notified breaches
33Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act
Visitor escorts not enforced
33HIPAA Security Rule, NIST Cybersecurity Framework 2.0, NIST SP 800-66 Rev 2
Certificates of destruction not retained
33HIPAA Security Rule, ISO/IEC 27701:2019, NIST SP 800-66 Rev 2
Removable media unrestricted
33Cyber Essentials Plus, HIPAA Security Rule, NIST SP 800-66 Rev 2
No tracking of completion
33C5 (Germany), HIPAA Security Rule, NIST SP 800-66 Rev 2
Re-screening not performed
33HIPAA Security Rule, ISO 37001, NIST SP 800-66 Rev 2
No BCR approval procedure
33LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Reviews not performed
33ISO 22318, NIST SP 800-171, PCI DSS 4.0
Generic training only
33AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NFPA 1600, NIST SP 800-171
No certificate of destruction
33Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FBI CJIS Security Policy, NIST SP 800-171
No annual pen test
33BSI IT-Grundschutz, Lloyd's Minimum Standards, New Zealand Information Security Manual (NZISM)
DSAR portal absent (email-only handling)
33Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act
no breach response
33Australian Privacy Principles (APPs), FFIEC IT Examination Handbook, Nevada Gaming Control Board Cybersecurity Requirements
Briefings irregular
33AS9100D:2016, ISO 20000-1, ISO 27005
Auditors not independent
33ISO 22313:2020, ISO 30401, ISO 9001
No Whistleblower integration
33Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
No configuration baselines
33ASIC Cyber Resilience Good Practices, C2M2, CFTC System Safeguards (17 CFR 37, 38, 39, 49)
Changes made without change control
33Annex 11 to EU GMP, Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2
Sectoral coordination weak
33GS1 Global Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM
no remediation
33Argyris Double-Loop Learning, ISO 37002:2021, PCI DSS 4.0
Standing privileged access
33Azure Security Benchmark, CISA Zero Trust Maturity Model, DoD Zero Trust Reference Architecture
No access logging
33Australia My Health Records Act 2012, Laos Law on Prevention and Combating Cybercrime (2015), PCI DSS 4.0
Templates outdated
33ISO 22313:2020, ISO 22317, NIST SP 800-161
No management review
33BIMCO Cyber Security, ISO/IEC 27003:2017, Illinois Biometric Information Privacy Act (BIPA)
No lessons captured
33ISO 27043, ISO 56002, NIST SP 800-150
no annual review evidence
33AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NIST SP 800-61, NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Lessons learned not captured
Enterprise risk management
33ISO 31000:2018, NIST SP 800-128, Space ISAC (Information Sharing and Analysis Center)
Coverage incomplete
33Australian Privacy Principles (APPs), BSIMM, PCI DSS 4.0
International cooperation absent
33French Sapin II Law (Law No. 2016-1691), Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843)
Contractors missing NDA
Enterprise risk management
33ISO 15189:2022, ISO 19011, ISO 31000:2018
Use cases focused on IT, missing SWIFT-specific scenarios
33ISO 13485, ISO 15189:2022, ISO 19011
Reviews not minuted
Enterprise risk management
33ISO 13485, ISO 19011, ISO 31000:2018
No purposing analysis
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Contractors untrained
33Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO 22000, ISO 28001:2007 Supply Chain Security Management
No anonymous channel
336th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), EASA Part-IS, ISO 37301
No tracked SLA
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
De-identification public commitment missing
33Maryland Online Data Privacy Act of 2024, Minnesota Consumer Data Privacy Act, Montana Consumer Data Privacy Act
Missing risk analysis
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
No formal ConMon strategy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No risk executive function
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No written programme
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Missing notice elements
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Framing assumptions undocumented
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
DGB exists in name only
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Missing exemption documentation
33NAIC Insurance Data Security Model Law (MDL-668), Nebraska Data Privacy Act, New Hampshire Data Privacy Act
No complaints process
33Australia Consumer Data Right, Australia NHMRC National Statement on Ethical Conduct in Human Research, Australian Privacy Principles (APPs)
No collection notice
33Australian Privacy Principles (APPs), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
EA not maintained
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No aging metric
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Dependencies not mapped
33APRA CPS 230 Operational Risk Management, ISO 22313:2020, ISO/IEC 29134:2023
Notifiable breaches not reported
33Australian Energy Sector Cyber Security Framework (AESCSF), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO)
External comms ad hoc
AI risk management
33ISO 37002:2021, ISO/IEC 23894:2023, ISO/IEC 27003:2017
Sampling plan not statistically justified
3321 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017
Sectoral application gaps
33GS1 Global Standards, HITECH Act, Hersey & Blanchard Situational Leadership Model
SPOFs unmitigated
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
CAPA backlog from prior inspections
33EU Clinical Trials Regulation (CTR 536/2014), EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Medical Devices Regulation (MDR 2017/745)
Same metro zone
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No objection mechanism
33African Union Malabo Convention, Angola Personal Data Protection Law (Law No. 22/11), Data Protection Act 2017
Local-only logs
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
Unlimited concurrent sessions
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
No oversight of data matching
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Calibration providers not assessed for competence
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Surge capacity not planned
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Subcontracted resources not included in plan
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No disclosure register
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Appetite not approved at board level
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Cleaning frequency not based on risk
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Authorization granted without practical assessment
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No change triggers
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Budget cycles not aligned with method changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No SLA monitoring
33AWS Well-Architected Security Pillar, CCPA/CPRA, NIST SP 800-144
Plan unwritten
33AS9100D:2016, ISO 20000-1, ISO 27005
no governance
33Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-144
Flat OT network
33IEC 62351, ISO 27019, NIST SP 800-82 Rev 3
KPIs not defined
Enterprise risk management
33ISO 13485, ISO 19011, ISO 31000:2018
No appeal process
33Colorado Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Consent records weak (bundled + pre-ticked)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
Lessons learned not implemented
33NIST SP 800-171, NIST SP 800-171A Rev 3, NIST SP 800-53 Rev 5
Updates not communicated
33ASEAN Data Management Framework, HIPAA Security Rule, NIST SP 800-66 Rev 2
Findings unremediated
33COBIT 2019, HIPAA Security Rule, NIST SP 800-66 Rev 2
No data subject breach notification
33LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Exceptions never expire
33NIST SP 800-128, NIST SP 800-171, NIST SP 800-218
lessons not implemented
33FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook, NIST SP 800-82 Rev 3
Feedback collected but not acted on
33ISO 15189:2022, ISO/IEC 17025:2017, ITIL 4
No crisis communication plan
33Belgium CyberFundamentals, DORA, EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
No criminal-risk register
33Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), South Korea PIPA
No DPIA for high-risk
33Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA
No documented risk assessment
33AICPA SOC 3, C-TPAT, NAIC Insurance Data Security Model Law (MDL-668)
keys never rotated
33AWS Well-Architected Security Pillar, EASA Part-IS, PCI DSS 4.0
Configuration drift unmanaged
33ASIC Cyber Resilience Good Practices, AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF)
No transition plan
33Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020), CDP (formerly Carbon Disclosure Project)
No regulatory mapping
33ISO 15189:2022, ISO 27005, ISO/IEC 25012:2008
Restore never tested
33AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, ISO 27799
No maturity assessment
33BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150
Non-APL products
33FedRAMP High, FedRAMP Moderate, New Zealand Information Security Manual (NZISM)
Scope misunderstood
33Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843), HITECH Act
No prior consultation
33Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Nigeria Data Protection Act 2023 (NDPA)
Follow-ups close on promise not evidence
Enterprise risk management
33ISO 15189:2022, ISO 19011, ISO 31000:2018
Logs collected but not parsed by SIEM
33ISO 13485, ISO 15189:2022, ISO 19011
Sampling not representative
Enterprise risk management
3321 CFR Part 211, ISO 19011, ISO 31000:2018
Context not refreshed
AI risk management
33ISO 30401, ISO/IEC 23894:2023, ISO/IEC 27003:2017
No matching agreements
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Authorization stale
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No priority clauses
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Security not documented
33Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO)
No revocation mechanism
33Botswana Data Protection Act (2024), Connecticut Data Privacy Act (CTDPA), Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP
Correspondence not tracked
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Competence reassessment intervals not defined
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Authorization tied to job title rather than verified competence
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No evidence of practical assessment for new methods
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Training records missing for locum or agency staff
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Measurement uncertainty not estimated
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Resource gaps not surfaced before incidents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No link between scope changes and resource updates
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No external privacy reporting
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Evaluation criteria not documented
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Specifications not updated after method changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Supplier performance not reviewed annually
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Out of service equipment used for urgent work
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Production data copied to test
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Maintenance done by unqualified staff
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Software versions not tracked per analyser
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Segregation between incompatible activities unclear
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Access controls not enforced for visitors
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No record of authorization changes when methods change
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Workload not measured against capacity
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Resource gaps surfaced only after incidents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Reassessment overdue for long serving staff
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
New starter checklist incomplete
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Competence on rare assays not maintained
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Lot to lot verification skipped under pressure
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Expired reagents found in active stock
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Storage temperature deviations not actioned
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No process for handling unaccredited referral results
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Out of service status not flagged in LIS
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Maintenance carried out by users without training
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No verification after software upgrades
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Calibration intervals not justified by data
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No measurement uncertainty estimate per assay
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Containment level not validated for new agents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Cleaning and decontamination logs incomplete
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Agreements not updated when scope changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Turnaround time commitments not monitored
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Sample acceptance criteria not in writing
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Training not delivered
33ISO 22739:2024, ISO 26000:2010, Kuwait Data Privacy Protection Regulation (KDPPR, 2021
Modifications bypass design review
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Renewable or low carbon options not evaluated
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Energy considered only after design freeze
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Improvements not tracked
33COSO Enterprise Risk Management (ERM) Framework (2017), ISO 20400:2017, ISO/IEC 17025:2017
No 10-year supply-chain records
33EU Cyber Resilience Act, EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Machinery Regulation (Regulation (EU) 2023/1230)
No breach notification process
33Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014), Argentina Law 25.326 (Personal Data Protection Law), Data Protection Act 2017
no remediation plan
33Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FFIEC Cybersecurity Assessment Tool (CAT), PCI DSS 4.0
Board reporting infrequent or absent
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Breach detection passive (manual reports only)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
Processor notification absent in contracts
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
SSN used as primary key
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Health PII commingled
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No SORN for in-scope systems
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Purposes drift after launch
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No authority assessment
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Vague lawful basis
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No privacy-specific policy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No privacy program plan distinct from security
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No CUI clauses in contracts
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No threat-sharing memberships
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Testing siloed by system
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No role-based pathway
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No HR/Legal/IT working group
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Privacy considered only at the end
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No transaction replay
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Unencrypted backups
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No criticality tiers
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Bluetooth/Wi-Fi enabled by default
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH

What this is, and what it is not

It is
A count. 689 failures, each named by three or more frameworks, with the artefacts that close them.
It is not
A prediction, a severity score, or a claim about how often these happen in the wild. We do not measure that and we will not pretend to.
Source
The control libraries of 723 frameworks, 531 of them verified against their source documents.
Threshold
Three frameworks. Below that a phrase is one verifier's wording rather than a general problem.
On each page
What closing that failure also buys you, traversed from 332,959 cross-framework control mappings. One piece of work, counted once, against every obligation it satisfies.

The corpus this comes from

723 frameworks, 20,473 controls, 332,959 cross-framework mappings, 531 frameworks verified against source documents.

See the corpus