IAM9 finding classesIdentity & Access Management
Who can act, and how strongly is that proven?
The Identity domain covers authentication strength, authorisation scope, and credential lifecycle. Identity is the modern perimeter: in cloud-first estates the majority of privilege-escalation paths are IAM misconfigurations rather than software vulnerabilities, and they carry no CVE to alert on.
What this domain covers
- Multi-factor authentication coverage and enforcement
- Privilege assignment, standing access, and least-privilege posture
- Credential and key lifecycle, rotation, and revocation
- Service account and workload identity governance
- Access review, joiner-mover-leaver, and federation
Distribution across tiers
Typically owned by Identity engineering / IT operations.
BCN-T1-IAM-00124 hoursMissing MFA on Privileged Accounts
Administrative, root, or break-glass accounts authenticate with a single factor.
BCN-T1-IAM-00248 hoursExcessive Standing Privilege
Accounts hold permanent administrative rights far beyond what their role requires.
BCN-T1-IAM-00372 hoursLong-Lived Privileged Credentials
Privileged API keys, access keys, or service credentials that never expire and are not rotated.
BCN-T2-IAM-00130 daysNon-Compliant Authentication Policy
Password and authentication settings that do not meet the applicable regulatory standard.
BCN-T2-IAM-00230 daysMissing Periodic Access Reviews
No recurring, evidenced certification that granted access remains appropriate.
BCN-T2-IAM-00330 daysUngoverned Service Accounts
Non-human identities without owners, documented purpose, or lifecycle management.
BCN-T3-IAM-00190 daysCoarse-Grained Role Design
Roles that are scoped but still broader than the tasks they support.
BCN-T3-IAM-00290 daysManual Credential Lifecycle
Credential provisioning, rotation, and revocation performed by hand rather than automatically.
BCN-T3-IAM-00390 daysFragmented Identity Federation
Applications with local accounts outside the central identity provider.