UM-SA-001 · Revision 4.0Where Fernleaf’s controls stand before the audit
A status summary for the audit: the controls we checked, what we found, and the work under way with its calendar time.
Who it’s for
What we checked
Access to production, change control for releases, removal of access, cloud logging and alerting, and backups.
What we found
- Releases could reach production from any branch, under a broader role, and as an image nobody had signed off (CLD-01 to CLD-03).
- People removed from a customer account kept access until their session ended (APP-03).
- Cloud logs are kept, but no one is alerted. Backups run nightly but haven’t been restored in a test.
In place now
- MFA on the cloud console and the code repository for everyone who can deploy.
- Nightly database backups, kept for 14 days.
- Staff laptops enrolled in device management, with disk encryption on.
Planned
- Sign-in security: MFA everywhere, single sign-on, conditional access3 to 4 weeks
- Cloud alerts: routed to the team1 to 2 weeks
- Tested backups: immutable copies and a documented restore test1 week
- Release and access fixes, by Fernleaf’s developers, then our retest4 to 6 weeks
Evidence
Every answer on this page points at an item in the evidence index on page 25: exports, policy files, restore logs.
Questions
Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.
Fictional sample. The company, systems and data are invented; no real client was assessed.