Skip to content
IAM9 finding classes

Identity & Access Management

Who can act, and how strongly is that proven?

The Identity domain covers authentication strength, authorisation scope, and credential lifecycle. Identity is the modern perimeter: in cloud-first estates the majority of privilege-escalation paths are IAM misconfigurations rather than software vulnerabilities, and they carry no CVE to alert on.

What this domain covers

  • Multi-factor authentication coverage and enforcement
  • Privilege assignment, standing access, and least-privilege posture
  • Credential and key lifecycle, rotation, and revocation
  • Service account and workload identity governance
  • Access review, joiner-mover-leaver, and federation

Distribution across tiers

Tier 1 · Critical3 · 24–72 hours
Tier 2 · Regulatory3 · 30 days
Tier 3 · Best Practices3 · 90 days

Typically owned by Identity engineering / IT operations.

Tier 1 · CriticalCould an external attacker use this to gain access, escalate privilege, or take data — today, without an insider and without a chain of unlikely events?
Tier 2 · RegulatoryWould a named auditor, regulator, or contractual counterparty record this as a deficiency?
Tier 3 · Best PracticesDoes fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?

Other domains