← Back to Portfolio

CRI Threat Mapper v12.0 -- Threat Advisory

PR.AA-01.01 -- Identity and Credential Management

AI-generated research tool for risk analysts. Maps CRI Profile coverage gaps to adversary techniques, regulatory exposure, and remediation options. All findings require professional review before use in risk decisions or regulatory submissions.

Institution
Heritage Community Bank (Simulated)
Charter / Supervision
State-chartered community bank, <$10B, FDIC A
CRI Statement
PR.AA-01.01 D
CRI Profile
v2.2 (2026)
Analysis Date
2026-07-20
Generated By
Claude Fable 5
Gap Profile Input
PR.AA-01.01 Coverage Assessment (5 Full, 11 Partial, 0 Gap)
Classification
Advisory -- Research Input
A Assessed input (CRI Coverage Assessment) D Documentary (published frameworks) I Inferred (AI-generated analysis)

Section 1 -- Coverage Summary

5
Full (31.3%)
11
Partial (68.8%)
0
Gap (0.0%)
RGRequirementCoverage
RG-1Allow access by authorized individuals and devicesPartial
RG-2Disallow access by all othersFull
RG-3Consider role-based access control to simplify management activitiesPartial
RG-4Access authorized only to individuals whose identity is establishedFull
RG-5Limit activities to minimum required for business purposes (least privilege)Partial
RG-6Asset owners regularly review access roles and authorized individualsPartial
RG-7Access controls include password complexityFull
RG-8Limitation of password attempts before lockoutFull
RG-9Prohibition of the reuse of passwordsPartial
RG-10Complex passwords for default administration passwordsPartial
RG-11Default passwords changed per system implementation guidelinesPartial
RG-12Changes to access privileges of critical systems continuously monitoredPartial
RG-13Access privilege changes alert and notify the security teamPartial
RG-14Access management activities automated where possiblePartial
RG-15Policies/procedures establish a process for terminating usersFull
RG-16Terminated individuals' access removed immediatelyPartial

Overall: 5 Full / 11 Partial / 0 Gap -- 16 requirements

Section 1A -- Coverage Strengths

Before examining gaps, it is important to recognize the capabilities that are demonstrably in place. The following requirements are fully satisfied, providing a foundation that the advisory recommendations build upon.

RGCapabilitySignificance
RG-2Disallow access by all othersDefault-deny posture is enforced — unauthorized identities and devices are blocked by policy and technical controls. This is a foundational access control principle.
RG-4Identity-established access authorizationAccess is granted only after identity is verified, demonstrating that the institution has functioning identity proofing and authentication controls before provisioning.
RG-7Password complexity requirementsPassword composition rules are technically enforced, reducing the risk of weak credential-based attacks such as brute force and credential stuffing.
RG-8Account lockout after failed attemptsLockout thresholds are configured and operational, providing an active defense against automated password attacks and unauthorized access attempts.
RG-15User termination policies and proceduresFormal procedures exist for removing access upon employment termination, establishing the policy foundation that RG-16 (immediate revocation) depends on for execution.

Section 1B -- Executive Highlights

Statementclick to expand

PR.AA-01.01 -- Identity and Credential Management  |  Coverage: 5 Full, 11 Partial, 0 Gap / 16

Statement

PR.AA-01.01 -- Identity and Credential Management  |  Coverage: 5 Full, 11 Partial, 0 Gap / 16

Heritage Community Bank has sound identity fundamentals -- identities are verified, passwords are complex, and outsiders are kept out -- but the lifecycle around those identities is weak: access is granted without documented business justification, reviewed by IT rather than business owners, monitored through an alert pipeline that staff have learned to ignore, and removed days (not hours) after termination.

Residual Risk

Critical

Residual Risk

If unaddressed, a departed employee, an over-privileged insider, or an attacker holding one stolen password can operate inside bank systems for days without the changes to their access being noticed, investigated, or revoked -- the classic precondition for insider fraud, account-takeover of member/customer data, and ransomware staging.

Top Threats

T1078 (Valid Accounts), T1098 (Account Manipulation), T1078.001 (Default Accounts), T1110.004 (Credential Stuffing), T1136 (Create Account)

Top Threats

Enabled: Abuse of valid accounts -- lingering terminated-staff access, unchanged default admin credentials, and over-provisioned rights give attackers working credentials without exploitation.

Not prevented: Password guessing against default/admin accounts; stolen credentials from unmanaged BYOD/contractor devices with no device-trust barrier.

Not detected: Account manipulation and unauthorized account creation -- alert pipeline exists but is deprioritized with no investigation process.

Prolonged: Dwell time extends because asset owners do not review access outside core banking, and manual deprovisioning leaves orphaned access.

Highest Risk Gap

RG-10 (Default admin password governance) and RG-16 (Termination revocation delay)

Highest Risk Gap

G-011 (RG-16) -- 2-3 business-day standard termination lag plus non-synchronized removal of physical access and third-party application access. G-006 (RG-10) -- No elevated standard for default admin credentials and no build-time verification that defaults have been changed.

Regulatory Flag

FFIEC MRA/MRIA potential on RG-5, RG-10, RG-12, RG-16

Regulatory Flag

Interagency Guidelines Establishing Information Security Standards (12 CFR Part 364, Appendix B, III.C.1.a -- access controls on customer information systems) are directly implicated. FFIEC IT Examination Handbook Information Security booklet (September 2016) guidance on access administration and monitoring is the relevant examiner lens. Access-lifecycle deficiencies of this type commonly attract examiner attention.

CIS Hardening

CIS Controls v8.1 Safeguards 4.7, 5.1-5.6, 6.1-6.8; CIS Windows Server 2022 Benchmark password and account policies

CIS Hardening

Priority hardening themes: manage default accounts (Safeguard 4.7), establish access granting/revoking processes (6.1, 6.2), centralize account management (5.6), and enforce Windows password-history/complexity baselines per the CIS Microsoft Windows Server Benchmark.

Top Remediation

Quick Win -- Deploy default credential scan + SIEM privilege change rules (Phase 1, 0-30 days). Strategic -- IGA platform deployment + RBAC documentation (Phase 3, 90-180 days).

Top Remediation

Quick Win: Same-day termination revocation runbook covering AD, physical access, and third-party apps (G-011); default-credential attestation step added to the build checklist (G-006/G-007).

Strategic: Automated joiner-mover-leaver lifecycle -- ServiceNow-triggered AD provisioning/deprovisioning with auto-revocation on role change (G-008), and an asset-owner access recertification program beyond Symitar (G-001).

Detection Gaps

Privilege-change monitoring degraded (alert fatigue, no investigation process); terminated-account and default-account logons not detected

Detection Gaps

Privilege-change monitoring exists but is functionally degraded: alert fatigue, no critical-system prioritization, and no documented investigation process (G-002/G-003). Terminated-account usage and default-account logons are not currently detected use cases.

Cross-CRI Dependencies

PR.AA-05 (least privilege), PR.AA-03 (authentication), DE.CM (monitoring), ID.AM (asset inventory), PR.PS (platform hardening)

Cross-CRI Dependencies

PR.AA-05 (access permissions/least privilege), PR.AA-03 (authentication of users/devices), DE.CM-series (continuous monitoring), ID.AM-series (asset and account inventory), and PR.PS-series (platform hardening/configuration baselines). Adjacent CRI Profile v2.2 statement families -- verify exact statement IDs against the institution's profile scoping.

Section 2 -- Gap Analysis

Analysis covers only Partial-rated requirements. Related gaps are analyzed individually; gap descriptions quoted are assessed facts A; mappings and judgments are inference I unless tagged D.

Mapping Roles Enables — gap directly allows the technique to succeed Fails-to-Prevent — gap removes a preventive barrier the technique would otherwise face Fails-to-Detect — gap removes a detective control that would expose the technique Prolongs — gap extends attacker dwell time or delays response
Partial RG-1 -- Allow access by authorized individuals and devices
Gap A: Domain-joined devices authenticate via Kerberos. Non-domain devices (BYOD, mobile, contractor laptops) lack equivalent authorization. MDM covers email only.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078Valid AccountsFails-to-PreventHighI A stolen user credential is usable from any unmanaged device; no device-trust barrier stops credential replay from attacker hardware.D T1078
T1133External Remote ServicesFails-to-PreventMediumI Remote/VPN access from BYOD or contractor laptops is not gated by device authorization, so compromised personal devices become entry points.D T1133
T1199Trusted RelationshipEnablesMediumI Contractor laptops explicitly lack authorization controls; a compromised contractor device inherits the contractor's access with no device posture check.D T1199

Excluded: brute-force techniques (T1110) -- existing complexity (RG-7) and lockout (RG-8) controls mitigate; this gap concerns the device, not the credential I.

2B. D3FEND Countermeasures

  • D3-MFA -- Multi-factor Authentication D: Reduces the value of a bare stolen password from unmanaged devices. URL: d3f:MultifactorAuthentication
  • Certificate-based device authentication (Verify ID) I: Issuing device certificates (or equivalent conditional-access device compliance checks) extends the Kerberos-domain trust model to non-domain endpoints. D3FEND v1.4.0 taxonomy entry -- Verify ID before citing.
  • D3-AI -- Asset Inventory D (Verify ID): A complete inventory of authorized devices is the precondition for enforcing device authorization.

2C. Control Type Gap

I Missing Preventive control (device authorization/posture gate for non-domain endpoints) and the supporting Detective control (visibility of which unmanaged devices are touching bank resources). Kerberos covers domain devices only; MDM's email-only scope means no corrective lever (quarantine/wipe) exists for non-email access paths. Why it matters: preventive device trust is the control that makes credential theft insufficient on its own.

2D. Regulatory Relevance and Examination Perspective

Regulatory Relevance D: Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 364, Appendix B, III.C.1.a -- access controls on customer information systems (binding for FDIC-supervised state nonmember banks). FFIEC IT Examination Handbook, Information Security booklet (September 2016), Section II.C "Risk Mitigation" -- access and network control guidance addresses restricting access to authorized devices (subsection: Verify section number). FFIEC handbooks are examiner guidance, not binding regulation; the connection is that the booklet describes device authorization and remote-access controls the gap leaves unimplemented for non-domain endpoints.

Examination Perspective I: Unmanaged BYOD/contractor access paths to systems holding customer information commonly attract examiner attention during IT examinations, particularly where MDM scope is limited. No prediction of specific supervisory outcomes is made.

2E. KPIs

MetricTargetFrequencySource
% of devices accessing bank resources that are inventoried and authorized (domain, MDM, or certificate) I>95%MonthlyAD + MDM + NAC/DHCP logs
Count of non-domain devices with access beyond email ITrend to 0 unmanagedMonthlyVPN/proxy logs, MDM
Contractor devices onboarded through a documented device-authorization step I100%QuarterlyOnboarding records

2F. Evidence of Closure

  • I Updated remote-access/BYOD standard requiring device authorization for all endpoint classes, with approval date.
  • I MDM or conditional-access enrollment report showing coverage beyond email (VPN, file, application access).
  • I Sample of contractor onboarding tickets showing device registration/posture verification.

2G. SIEM Log Sources

TechniqueSourceTypeKey FieldsCollection
T1078Windows Security Event Log (DCs)AuthenticationEventID 4624, LogonType, WorkstationName, IpAddress, TargetUserName DWEF/agent to SIEM
T1133VPN concentrator logsRemote accessusername, client IP, device ID/hostname, posture result ISyslog
T1199VPN + AD logs filtered to contractor OU/accountsRemote accessaccount, source device, session duration ISyslog + WEF

2H. Detection Specifications

D-2.1-1 -- Logon from unregistered device I

  • Description: Successful authentication where the source workstation is not in the authorized-device inventory.
  • Detection Classification: Compensating Detection (detects what the missing preventive control would block).
  • Specification (pseudo-code):
WHERE EventID=4624 AND LogonType IN (3,10) AND WorkstationName NOT IN device_inventory_lookup -> alert
  • Severity/Threshold: Medium; alert on first occurrence per user-device pair per 24h.
  • False-positive sources: Incomplete device inventory; hostname randomization on personal devices.
  • Required log fields: 4624 with WorkstationName, IpAddress, TargetUserName; maintained device inventory lookup.
  • Validation test: Authenticate from a lab machine not in inventory; confirm alert within SLA.

D-2.1-2 -- VPN session without posture/MDM record I

  • Description: VPN session established by a device with no MDM enrollment or posture assessment.
  • Detection Classification: Control Failure Detection.
  • Specification:
JOIN vpn_sessions TO mdm_enrollment ON device_id WHERE mdm_enrollment IS NULL -> alert
  • Severity/Threshold: Medium; daily digest, immediate alert for privileged accounts.
  • False-positive sources: MDM sync latency; device-ID mismatch across sources.
  • Required log fields: VPN device identifier, username; MDM enrollment export.
  • Validation test: Connect a non-enrolled test device to VPN; verify detection.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 1.1 "Establish and Maintain Detailed Enterprise Asset Inventory" and Safeguard 1.2 "Address Unauthorized Assets" -- prerequisite and enforcement for device authorization.
  • D CIS Controls v8.1, Safeguard 6.4 "Require MFA for Remote Network Access" -- compensates for absent device trust on remote paths.
  • I Platform benchmark: CIS Microsoft Windows Server Benchmark (current version per platform) network-access sections apply to domain enforcement points; specific recommendation numbers -- Verify ID.

2K. Incident Scenario

I A contractor's personal laptop, already infected with an infostealer, connects to the bank VPN using valid contractor credentials. Because no device authorization or posture check exists outside domain join, the session is indistinguishable from a sanctioned one. The malware harvests the contractor's cached bank credentials and session tokens, and the attacker returns after hours from their own infrastructure using the same account. With MDM limited to email, no quarantine or wipe lever exists, and the intrusion is discovered only when the contractor reports unrelated fraud on the device.

2L. Compensating Controls Assessment

I Without: Medium-High exposure. With enforced MFA on all remote access (if RG-7/RG-8-adjacent MFA exists -- verify deployment): revised to Medium. Limitation: MFA authenticates the person, not the device -- it does not stop session-token theft or malware-resident access from a compromised unmanaged endpoint. With network segmentation restricting BYOD/contractor VLANs to limited destinations: revised to Medium-Low. Limitation: segmentation is only as good as the destination allow-list and does not cover VPN full-tunnel access.

2N. Data Classification Impact

I At risk via unmanaged devices: customer NPI and PII accessible through user sessions (email attachments beyond MDM control paths, file shares, browser-cached data), and authentication secrets (cached credentials, session tokens) on unmanaged endpoints. Financial records exposure is bounded by the user's application entitlements -- which RG-5's least-privilege gap widens.

2Q. Audit Test Procedures

  • I Obtain the device inventory and reconcile against 30 days of VPN and 4624 authentication logs; investigate unmatched device identifiers. Evidence: reconciliation workpaper, exception listing.
  • I Select a sample of contractor onboarding records; verify a device-authorization step was performed. Evidence: onboarding tickets, MDM/certificate enrollment records.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID against the institution's EEE evidence layer.
Partial RG-3 -- Role-based access control
Gap A: Role definitions not formally documented. AD security groups provide functional RBAC but role-to-group mappings exist informally.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1098Account ManipulationFails-to-DetectMediumI Without documented role-to-group mappings, an attacker's addition of an account to a sensitive group cannot be judged anomalous -- there is no authoritative "should-be" state to compare against.D T1098
T1078.002Valid Accounts: Domain AccountsProlongsMediumI Undocumented roles slow incident scoping ("what should this account access?"), extending attacker dwell time during response.D T1078.002

Excluded: discovery techniques (T1069 Permission Groups Discovery) -- the gap does not make discovery easier; AD group enumeration is available to attackers regardless of documentation state I.

2B. D3FEND Countermeasures

  • D3-DAM -- Domain Account Monitoring D (Verify ID): Monitoring domain accounts against a documented baseline turns informal mappings into detectable deviations.
  • D3-UAP -- User Account Permissions D (Verify ID): Formal role definitions enable systematic permission restriction per role.

2C. Control Type Gap

I This is primarily a missing Detective enabler: the preventive mechanism (AD groups) works, but without documented mappings there is no baseline for review (RG-6), monitoring (RG-12/13), or recertification to compare against. It is the documentation keystone on which three other RGs depend.

2D. Regulatory Relevance

Regulatory Relevance D: 12 CFR Part 364, Appendix B, III.C.1.a (access controls). FFIEC IT Examination Handbook, Information Security booklet (September 2016), Section II.C -- guidance describes defining access rights by role/job function as part of access-rights administration (subsection: Verify section number). Guidance, not binding regulation; the connection is that informal role definitions fall short of the described administration discipline.

Examination Perspective I: Examiners commonly test whether access rights administration is documented and repeatable; informal tribal-knowledge mappings tend to draw follow-up requests. No specific supervisory outcome is predicted.

2E. KPIs

MetricTargetFrequencySource
% of AD security groups with a documented owning role definition I100% for critical systems within 2 quartersQuarterlyRole catalog vs AD export
% of workforce whose group memberships match their documented role I>95%QuarterlyRecertification results

2F. Evidence of Closure

  • I Approved role catalog (role -> AD group -> entitlement) with owner and review date.
  • I Reconciliation report of AD group memberships against the catalog, with dispositioned exceptions.

2G. SIEM Log Sources

TechniqueSourceTypeKey FieldsCollection
T1098Windows Security Event Log (DCs)Directory changeEventID 4728/4732/4756 (member added to security group), SubjectUserName, TargetUserName, group name DWEF/agent
T1078.002DC authentication logsAuthentication4624/4768/4769, account, source host DWEF/agent

2H. Detection Specifications

D-2.2-1 -- Group membership deviation from role catalog I

  • Description: Account added to a group not associated with the account's documented role.
  • Detection Classification: Control Monitoring.
  • Specification:
WHERE EventID IN (4728,4732,4756) AND (TargetUser.role, GroupName) NOT IN role_catalog -> alert
  • Severity/Threshold: High for Tier-0/critical-system groups, Medium otherwise; alert per event.
  • False-positive sources: Catalog staleness after reorganizations; temporary project access.
  • Required log fields: 4728/4732/4756 with group and subject; maintained role-catalog lookup.
  • Validation test: Add a test account to an out-of-role group; confirm alert and catalog lookup fire correctly.
  • Dependency note: This rule is only buildable after G-009 remediation -- the catalog is the detection content.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 6.8 "Define and Maintain Role-Based Access Control" -- directly on point.
  • D CIS Controls v8.1, Safeguard 5.1 "Establish and Maintain an Inventory of Accounts" -- supporting inventory discipline.

2K. Incident Scenario

I An attacker who has phished a helpdesk account quietly adds a controlled user to the "FIN-Wires" AD group. The SOC sees the group-change event but, with no documented mapping of which roles belong in which groups, the analyst cannot tell whether the change is routine and closes it. Weeks later the account is used to stage fraudulent wire templates. Post-incident review finds the change was visible on day one -- it was undetectable only because "correct" membership was never written down.

2L. Compensating Controls

I Without: Medium. With functional AD group hygiene plus quarterly IT-led membership eyeballing: revised to Medium-Low. Limitation: reviewers without documented role definitions substitute personal judgment, which drifts with staff turnover -- the informal knowledge this gap describes is itself the single point of failure.

2N. Data Classification Impact

I Indirect but broad: undocumented mappings make over-grants to NPI/financial-record groups (core banking, wire, loan systems) invisible. Highest-consequence data is whatever the least-well-documented critical group protects.

2Q. Audit Test Procedures

  • I Request formal role definitions; if unavailable, document as designed-control absence. Evidence: policy/standard extract or absence memo.
  • I Select 3 critical systems; have management articulate role-to-group mapping and compare to actual AD membership. Evidence: interview notes, AD group export, variance analysis.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-5 -- Least privilege
Gap A: No business purpose justification required for access grants. Privilege creep from role changes addressed reactively, not proactively.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.002Valid Accounts: Domain AccountsEnablesHighI Privilege creep means any single compromised account carries accumulated entitlements from prior roles -- the gap directly inflates the blast radius of the most common financial-sector intrusion vector.D T1078.002
T1021Remote ServicesFails-to-PreventMediumI Excess entitlements (server logon rights, share access retained from old roles) give lateral-movement paths that least privilege would have closed.D T1021
T1213Data from Information RepositoriesEnablesMediumI Grants issued without business justification tend to over-scope repository access (shares, intranet, document systems), enlarging what one account can exfiltrate.D T1213

2B. D3FEND Countermeasures

  • D3-UAP -- User Account Permissions D (Verify ID): Restricting permissions to job need is the direct countermeasure to creep.
  • Job Function Access Pattern Analysis (Verify ID) I: Comparing actual access patterns to job function surfaces dormant excess entitlements for removal. D3FEND v1.4.0 user-behavior-analysis family -- Verify ID.

2C. Control Type Gap

I Missing Preventive control at grant time (business-purpose justification gate) and missing Corrective control at role change (proactive entitlement re-baseline). Detective coverage is also thin because RG-6 reviews are Symitar-only. Why it matters: least privilege is the control that caps consequence when any other identity control fails; its absence is a risk multiplier for every other gap in this statement.

2D. Regulatory Relevance

Regulatory Relevance D: 12 CFR Part 364, Appendix B, III.C.1.a (access controls consistent with the sensitivity of customer information). FFIEC IT Examination Handbook, Information Security booklet (September 2016), Section II.C -- the booklet's access-rights guidance describes granting access based on job need and least privilege (subsection: Verify section number). Guidance, not binding regulation; the gap is a direct shortfall against that described practice.

Examination Perspective I: Absent business-need justification for access grants is a finding pattern examiners commonly probe via user-access sampling. Appropriately hedged; no supervisory outcome predicted.

2E. KPIs

MetricTargetFrequencySource
% of access requests with recorded business justification I100% of new grantsMonthlyServiceNow
Entitlements removed per role-change event (creep cleanup rate) IRe-baseline within 30 days of role changeQuarterlyHR change feed vs AD diff
Dormant entitlements (unused >90 days) on critical systems IDownward trendQuarterlyApp/AD last-use data

2F. Evidence of Closure

  • I ServiceNow workflow screenshot/config showing mandatory business-justification field with approver.
  • I Role-change procedure requiring entitlement re-baseline, plus samples of executed re-baselines.
  • I Before/after entitlement reduction report for a pilot department.

2G-2Q. Remaining Analysis

2G. SIEM Log Sources

TechniqueSourceTypeKey FieldsCollection
T1078.002DC auth logsAuthentication4624, 4768/4769, account, host DWEF/agent
T1021Member server security logsLateral movement4624 LogonType 3/10, source IP, account DWEF/agent
T1213File server / SharePoint auditData accessobject accessed, account, volume of reads INative audit to SIEM

2H. Detection Specifications

D-2.3-1 -- First-use of dormant entitlement I

  • Description: Account exercises an entitlement (server logon, share access) unused by that account in >90 days.
  • Detection Classification: Threat Detection.
  • Specification:
WHERE access_event.account+resource NOT IN last_90d_baseline -> score; alert when resource is critical-system tagged
  • Severity/Threshold: Medium; High if resource tagged critical.
  • False-positive sources: Seasonal duties (year-end processing), returning from leave.
  • Validation test: Use a test account's stale share permission; confirm alert.

D-2.3-2 -- Volume anomaly on repository reads I

  • Description: Account reads from information repositories at volumes far above its own baseline.
  • Detection Classification: Threat Detection.
  • Specification:
WHERE daily_read_count(account, repository) > N x rolling_30d_median(account) -> alert
  • Severity/Threshold: Medium; N=5 initial, tune per repository.
  • False-positive sources: Legitimate bulk exports, migrations, audit pulls.
  • Validation test: Scripted bulk read by test account; confirm alert at threshold.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 6.1 "Establish an Access Granting Process" and 6.2 "Establish an Access Revoking Process".
  • D CIS Controls v8.1, Safeguard 5.4 "Restrict Administrator Privileges to Dedicated Administrator Accounts".
  • D CIS Controls v8.1, Safeguard 3.3 "Configure Data Access Control Lists".

2K. Incident Scenario

I A lending officer transfers to marketing; her loan-system and shared-drive entitlements are never removed because re-baselining is reactive. Eight months later her credentials are phished. The attacker, expecting marketing collateral, instead finds live access to loan files and the servicing share, exfiltrates borrower NPI, and uses retained server logon rights to move laterally toward the imaging system. The breach scope is defined not by her current job, but by every job she ever held.

2L. Compensating Controls

I Without: Medium-High. With Symitar annual review (RG-6 partial coverage): revised to Medium for core banking entitlements only. Limitation: the review is annual (long creep window) and Symitar-only -- network shares, lending, and ancillary systems retain unreviewed creep.

2N. Data Classification Impact

I Direct: customer NPI and financial records (loan files, account data, wire templates) -- creep concentrates multi-department data access in single accounts. PII of employees (HR shares) similarly exposed.

2Q. Audit Test Procedures

  • I Sample 25 access grants from the last 12 months; test for documented business justification and approver. Evidence: ServiceNow tickets, exception rate.
  • I Select 10 employees with role changes in the last 18 months; compare current entitlements to current role requirements. Evidence: HR change records, entitlement reports, creep findings.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-6 -- Regular access reviews by asset owners
Gap A: No control assigns access review responsibility to asset or system owners. Annual reviews exist for Symitar only; other systems reviewed ad hoc by IT.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.002Valid Accounts: Domain AccountsProlongsHighI Stale, excessive, or unauthorized access on non-Symitar systems persists indefinitely -- no owner review cycle exists to catch and revoke it.D T1078.002
T1078.003Valid Accounts: Local AccountsProlongsMediumI Local accounts on ancillary systems are the least visible to ad hoc IT review and would surface primarily through owner-driven recertification.D T1078.003
T1136Create AccountFails-to-DetectMediumI An unauthorized account created on a non-core system has no periodic reconciliation against an owner-approved list that would expose it.D T1136

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-DAM -- Domain Account Monitoring D (Verify ID): Continuous account monitoring approximates, between review cycles, what owner recertification does periodically.
  • D3-LAM -- Local Account Monitoring D (Verify ID): Directly addresses unreviewed local accounts on ancillary systems.

2C. Control Type Gap

I Missing Detective control (periodic owner recertification) and its Corrective follow-through (revocation of access the owner does not recertify). IT's ad hoc review is a weaker substitute because IT lacks business context to judge whether access is still needed.

2D. Regulatory Relevance

D 12 CFR Part 364, Appendix B, III.C.1.a and III.C.3. FFIEC Information Security booklet (September 2016), Section II.C -- periodic review of access rights by management/system owners. I User-access review evidence is among the most commonly requested examination artifacts.

2E. KPIs

MetricTargetFrequencySource
% of in-scope systems with a named asset owner I100%QuarterlyAsset inventory
% of critical systems recertified on schedule I100% annually (semi-annual for privileged)Per cycleRecertification tracker
Revocations resulting from reviews (review effectiveness) I>0 with rationale; trend trackedPer cycleReview results

2F. Evidence of Closure

  • I Access-review standard assigning owner responsibility, with system-to-owner matrix.
  • I Completed recertification packages for at least two non-Symitar critical systems, with owner sign-off and revocation actions.

2G. SIEM Log Sources

TechniqueSourceTypeKey FieldsCollection
T1078.002/.003DC + member server security logsAuthentication4624, account, host, LogonType DWEF/agent
T1136Windows Security Event LogAccount lifecycleEventID 4720 (account created), SubjectUserName, TargetUserName DWEF/agent

2H. Detection Specifications

D-2.4-1 -- Dormant enabled account I

  • Description: Enabled account with no authentication in 45+ days.
  • Detection Classification: Compensating Detection.
  • Specification:
WHERE account.enabled = true AND max(lastLogonTimestamp) < now()-45d -> weekly report to IAM queue
  • Severity/Threshold: Low severity, weekly digest; High if the account is privileged.
  • False-positive sources: Leave of absence, seasonal staff, service accounts.

D-2.4-2 -- Account creation outside change window / without ticket I

  • Description: 4720 account-creation event with no matching ServiceNow request.
  • Detection Classification: Control Failure Detection.
  • Specification:
WHERE EventID=4720 AND no servicenow_request within +/-24h for TargetUserName -> alert
  • Severity/Threshold: Medium; alert per event.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 5.1 "Establish and Maintain an Inventory of Accounts" and 5.3 "Disable Dormant Accounts".
  • D CIS Controls v8.1, Safeguard 6.1/6.2 (granting/revoking processes).

2K. Incident Scenario

I During a systems migration two years ago, IT granted a vendor engineer accounts on the loan-imaging and reporting servers. The project ended; the accounts did not. Because neither system has an assigned owner or review cycle, no one ever reconfirms the account list. When the vendor suffers a breach, attackers replay the engineer's reused password against the bank's externally reachable reporting portal and land on a fully privileged, long-forgotten account.

2L. Compensating Controls

I Without: Medium-High. With Symitar annual review: revised to Medium for the core system only. With ad hoc IT review: marginal improvement -- undocumented cadence and no business context.

2N. Data Classification Impact

I Non-Symitar systems typically hold customer NPI and financial records in secondary forms (imaging, reporting, loan origination), plus employee PII.

2Q. Audit Test Procedures

  • I Obtain the system inventory; test for named asset owners and review schedules per system.
  • I For two non-Symitar critical systems, obtain the full user list and ask the business unit to identify each user's need; quantify unrecognized access.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-9 -- Password reuse prohibition
Gap A: 10-password history enforced via AD Group Policy. Policy language does not explicitly prohibit password reuse.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1110.004Brute Force: Credential StuffingEnablesLowI AD history stops sequential reuse inside the domain, but the absent policy prohibition leaves cross-system reuse unaddressed -- the vector credential stuffing exploits. Confidence Low because residual exposure is behavioral.D T1110.004

Excluded: T1110.001/.002 (guessing/cracking) -- RG-7 complexity and RG-8 lockout are rated Full and mitigate these I.

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-SPP -- Strong Password Policy D (Verify ID): Extending policy language to prohibit reuse completes the administrative control.

2C. Control Type Gap

I The Preventive technical control operates; what is missing is the administrative (directive) layer -- explicit policy prohibition. It matters for enforceability, for systems outside AD, and for audit defensibility.

2D. Regulatory Relevance

D FFIEC Information Security booklet (September 2016), Section II.C -- authentication guidance describes password controls established through policy. I Policy-configuration mismatches are low-severity but commonly noted documentation observations.

2E. KPIs

MetricTargetFrequencySource
Policy coverage: password standard explicitly addresses reuse IComplete (binary)At next policy cyclePolicy repository
% of non-AD critical systems enforcing history/reuse controls I100% documentedAnnualConfig attestations

2F. Evidence of Closure

  • I Revised password standard with explicit reuse prohibition, approval minutes.
  • I GPO export (PasswordHistorySize=10 or greater) mapped to the policy clause.

2H. Detection Specification

D-2.5-1 -- Credential-stuffing pattern on external portals I

  • Description: Many distinct usernames with few attempts each from a shared source range.
  • Specification:
WHERE distinct(TargetUserName) > 20 per source_ip per 10min AND failures_per_account <= 3 -> alert
  • Severity/Threshold: High; threshold as stated, tune per portal traffic.

2I. CIS Benchmarks

  • D CIS Microsoft Windows Server 2022 Benchmark, Recommendation 1.1.1 "Ensure 'Enforce password history' is set to '24 or more password(s)'" -- CIS baseline (24) exceeds the bank's current 10 A.
  • D CIS Controls v8.1, Safeguard 5.2 "Use Unique Passwords".

2K. Incident Scenario

I A teller reuses her AD password on a retail website that is later breached. The combo list circulates; an attacker stuffs it against the bank's webmail portal and succeeds -- AD password history never had a chance to intervene because the reuse happened outside the domain.

2L. Compensating Controls

I Without: Low-Medium. With enforced 10-password history: revised to Low for in-domain sequential reuse. Documentation-only gap overall.

2N. Data Classification Impact

I Indirect: whatever the stuffed account reaches -- email (NPI in correspondence) first, then application data per the account's entitlements.

2Q. Audit Test Procedures

  • I Inspect password standard for reuse language; compare to GPO export. Evidence: policy extract, PasswordHistorySize setting.
  • I Inquire whether breached-password screening appears in security awareness content.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-10 -- Default admin password governance
Gap A: No explicit requirement for complex passwords on default administration accounts beyond standard user password policy.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.001Valid Accounts: Default AccountsEnablesHighI Built-in administrator accounts governed only by user-grade policy are exactly the accounts this technique abuses.D T1078.001
T1110.002Brute Force: Password CrackingFails-to-PreventMediumI User-grade length on admin accounts shortens offline cracking time; lockout (RG-8) does not apply offline.D T1110.002

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-SPP -- Strong Password Policy D: Distinct, stronger standard for admin accounts.
  • Credential Rotation I: LAPS for local admin passwords removes long-lived shared secrets.
  • D3-MFA D: MFA on administrative access reduces dependence on password strength alone.

2C. Control Type Gap

I Missing Preventive control: an elevated administrative-credential standard. Default admin accounts are shared, well-known usernames with total system control.

2D. Regulatory Relevance

D 12 CFR Part 364, Appendix B, III.C.1.a/c. FFIEC Information Security booklet guidance describes stronger controls for privileged access. I Privileged-credential management is a recurring examiner focus area.

2E. KPIs

MetricTargetFrequencySource
% of default admin accounts meeting elevated standard (length >= 20 or vaulted) I100%QuarterlyPAM/LAPS reports
Default admin accounts with passwords unchanged >12 months I0QuarterlypwdLastSet / device audit

2F. Evidence of Closure

  • I Administrative credential standard distinct from user policy, approved.
  • I LAPS/PAM deployment evidence covering local administrator accounts.
  • I Sample verification (pwdLastSet, vault records) for built-in accounts on critical systems.

2H. Detection Specification

D-2.6-1 -- Default-account logon I

  • Description: Any interactive/network logon by a built-in or known-vendor default account name.
  • Detection Classification: Threat Detection.
  • Specification:
WHERE EventID IN (4624,4625) AND TargetUserName IN default_account_list -> alert (success=High, failure burst=Medium)
  • Severity/Threshold: High on success from non-admin subnet; per event.
  • Validation test: Controlled logon with a lab default account; confirm alert.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 4.7 "Manage Default Accounts on Enterprise Assets and Software".
  • D CIS Controls v8.1, Safeguard 5.4 "Restrict Administrator Privileges".
  • D CIS Microsoft Windows Server 2022 Benchmark -- rename/disable built-in Administrator and Guest (Section 2.3.1).

2K. Incident Scenario

See combined scenario under 2.7 (RG-11) -- the two gaps compound.

2L. Compensating Controls

I Without: Medium-High. With RG-7 complexity + RG-8 lockout: revised to Medium -- online guessing is constrained. Limitation: lockout does not protect against offline cracking or vendor-published default credentials.

2N. Data Classification Impact

I Total-scope: default admin credentials confer platform-level access -- all data classes on the affected system plus authentication secrets enabling domain-wide escalation.

2Q. Audit Test Procedures

  • I Inspect password/privileged-access standard for an elevated admin-credential requirement.
  • I For a sample of servers and network devices, verify built-in account password age and vaulting status.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-11 -- Default password change verification
Gap A: Build checklist is inconsistent. Does not reference formal hardening documentation. No automated verification that defaults have been changed.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.001Valid Accounts: Default AccountsEnablesHighI Inconsistent checklists with no automated verification mean some systems reach production with factory credentials intact.D T1078.001
T1190Exploit Public-Facing ApplicationEnablesLowI Unhardened builds can retain default admin consoles/management interfaces.D T1190

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-ACH -- Application Configuration Hardening D: Formal hardening baselines referenced by the build checklist.
  • Platform hardening and scripted build verification I: Automated post-build compliance scanning (e.g., CIS-CAT) closes the "no automated verification" element.

2C. Control Type Gap

I Missing Detective/verification control on an unreliable Preventive one: the checklist exists but executes inconsistently, and nothing verifies its outcome. Unverified preventive controls fail silently.

2D. Regulatory Relevance

D FFIEC Architecture, Infrastructure, and Operations booklet (June 2021) -- configuration and change management. FFIEC Information Security booklet, Section II.C -- secure configuration guidance.

2E. KPIs

MetricTargetFrequencySource
% of new builds passing automated default-credential scan before production I100%Per buildScan reports
Build checklist completion rate with hardening-doc reference I100%MonthlyChange tickets
Default credentials found on production by periodic scan I0QuarterlyVulnerability scans

2F. Evidence of Closure

  • I Versioned build standard referencing named hardening baselines (e.g., CIS Benchmarks per platform).
  • I Automated post-build scan reports gating promotion, for a sample of recent builds.
  • I Quarterly default-credential scan results with zero findings or tracked remediation.

2H. Detection Specification

D-2.7-1 -- New asset with default credentials (scan-based) I

  • Description: Vulnerability scan detects factory credentials on a recently provisioned asset.
  • Detection Classification: Control Failure Detection.
  • Specification:
WHERE scan_finding.category = default_credentials AND asset.first_seen < 30d -> alert to build team + security
  • Severity/Threshold: High; per finding.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 4.1 "Establish and Maintain a Secure Configuration Process".
  • D CIS Controls v8.1, Safeguard 4.7 "Manage Default Accounts on Enterprise Assets and Software".
  • I Adopt the platform-specific CIS Benchmark as the "formal hardening documentation" the checklist currently lacks.

2K. Incident Scenario (combined G-006/G-007)

I A new branch network appliance is deployed under time pressure; the technician's copy of the build checklist is an older version without the credential-change step, and no scan verifies the result. The appliance sits on the internal network with its documented factory login. Months later, commodity malware on a workstation scans the subnet, tries vendor defaults from a public list, and gains the appliance's management plane -- traffic capture and a pivot point -- without triggering a single failed-password lockout. Because no elevated admin-credential standard exists (G-006), the same sweep also lands on two servers whose local Administrator passwords were set years ago to a shared, user-grade value.

2L. Compensating Controls

I Without: Medium-High. With network segmentation: revised to Medium. With quarterly vulnerability scanning including default-credential checks: revised to Medium-Low. Limitation: quarterly cadence leaves up to 90-day exposure windows.

2N. Data Classification Impact

I Platform-dependent: network appliances expose traffic containing NPI in transit; servers with default credentials expose whatever they store plus local authentication secrets for lateral movement.

2Q. Audit Test Procedures

  • I Compare build checklists in use across recent deployments for version consistency and hardening references.
  • I Re-perform: select 5 recently deployed assets and test for default credentials (with authorization).
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-12 -- Continuous monitoring of privilege changes
Gap A: Monitoring is not continuous. High alert volume degrades effectiveness. Critical systems not prioritized for detection.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1098Account ManipulationFails-to-DetectHighI Privilege manipulation on critical systems drowns in noise; volume-driven desensitization and no critical-system prioritization.D T1098
T1136.002Create Account: Domain AccountFails-to-DetectHighI Attacker-created persistence accounts generate events the pipeline deprioritizes.D T1136.002
T1078.002Valid Accounts: Domain AccountsProlongsMediumI Undetected privilege changes extend dwell time.D T1078.002

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-DAM -- Domain Account Monitoring D: Continuous, baselined monitoring tiered by system criticality.
  • D3-LAM -- Local Account Monitoring D: Extends coverage to local privilege changes on critical servers.

2C. Control Type Gap

I The Detective control exists but is Execution-Limited: intermittent coverage, no criticality tiering, and analyst desensitization. A detective control that fires but is not watched protects the record, not the bank.

2D. Regulatory Relevance

D 12 CFR Part 364, Appendix B, III.C.3 -- monitoring systems (binding). FFIEC Information Security booklet, Section II.C -- risk-prioritized monitoring. I "Alerts generated but not worked" is a pattern examiners commonly identify.

2E. KPIs

MetricTargetFrequencySource
% of critical systems with privilege-change events onboarded and tiered I100%MonthlySIEM coverage report
Median time-to-triage for critical-system privilege alerts I< 4 business hoursMonthlySIEM/SOAR metrics
Alert volume reduction from tuning I>50% noise reduction without coverage lossQuarterlySIEM statistics

2H. Detection Specifications

D-2.8-1 -- Privileged group modification on critical system (tiered) I

  • Description: Any addition to Tier-0/critical-system administrative groups.
  • Specification:
WHERE EventID IN (4728,4732,4756) AND GroupName IN tier0_or_critical_groups -> page on-call; all other groups -> daily digest
  • Severity/Threshold: High; per event for tiered groups (tiering IS the remediation of the volume problem).
  • Validation test: Add test account to a tiered group with and without a matching ticket; verify page vs suppression.

D-2.8-2 -- Off-hours privilege change I

  • Description: Privilege or account change outside business hours by a non-on-call admin.
  • Specification:
WHERE EventID IN (4720,4728,4732,4756) AND hour NOT IN business_hours AND SubjectUserName NOT IN oncall_roster -> alert
  • Severity/Threshold: Medium-High; per event.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 8.2 "Collect Audit Logs", 8.9 "Centralize Audit Logs", 8.11 "Conduct Audit Log Reviews".
  • D CIS Microsoft Windows Server 2022 Benchmark -- "Audit Security Group Management" and "Audit User Account Management" (Section 17).

2K. Incident Scenario

See combined scenario under 2.9 (RG-13) -- the two gaps are one failure chain.

2L. Compensating Controls

I Without: High. With existing (degraded) alerting: revised to Medium-High -- events are collected, enabling retrospective investigation. Compensation is forensic, not protective.

2Q. Audit Test Procedures

  • I Obtain SIEM rule inventory and coverage mapping for privilege-change events per critical system.
  • I Select 20 privilege-change alerts from the last quarter; test disposition and timeliness.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-13 -- Alert and notification for privilege changes
Gap A: Alerts deprioritized due to false positives. No documented investigation process for triggered privilege change alerts.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1098Account ManipulationProlongsHighI Absence of investigation process means no reliable path from alert to containment.D T1098
T1136.002Create Account: Domain AccountFails-to-DetectMediumI A deprioritized alert with no investigation owner is operationally equivalent to no alert.D T1136.002

2B-2Q. Full Analysis

2C. Control Type Gap

I The Corrective/response linkage is missing: detection without a documented response procedure breaks the detect-to-respond chain. RG-12 and RG-13 jointly demonstrate that Heritage owns the tooling but not the operating discipline.

2D. Regulatory Relevance

D 12 CFR Part 364, Appendix B, III.C.3 (monitoring) and III.C.1.g (response programs) -- binding. FFIEC Information Security booklet, Section II.C -- incident identification and response. I Examiners commonly trace sampled alerts to their disposition.

2E. KPIs

MetricTargetFrequencySource
% of privilege-change alerts dispositioned per the runbook I100%MonthlyTicketing/SOAR
False-positive rate on privilege alerts I<30% and fallingMonthlySIEM metrics
Alerts escalated to incident with documented outcome I100% traceableQuarterlyIncident records

2F. Evidence of Closure

  • I Approved privilege-alert investigation runbook (triage steps, escalation criteria, SLA, evidence handling).
  • I Quarter of ticketing records showing runbook-conformant dispositions.
  • I Tabletop or live test of the runbook with lessons-learned record.

2H. Detection Specification

D-2.9-1 -- Alert aging without triage (meta-detection) I

  • Description: Privilege-change alert exceeding its triage SLA with no assignee action -- detects the failure of the response process itself.
  • Specification:
WHERE alert.category = privilege_change AND alert.age > SLA AND disposition IS NULL -> escalate to ISO
  • Severity/Threshold: Medium; evaluated hourly.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 8.11 "Conduct Audit Log Reviews" and Control 17 "Incident Response Management".

2K. Incident Scenario (combined G-002/G-003)

I An attacker with a phished IT-support credential creates a new domain account at 7:40 p.m. and adds it to a server-operators group. Both events generate SIEM alerts -- into a queue averaging hundreds of daily entries with no criticality tiering. The analyst on rotation, conditioned by months of false positives, bulk-acknowledges the overnight queue. No investigation process exists to force a second look. The persistence account operates for six weeks, staging data from the loan-imaging server, until an unrelated storage alert exposes the transfer volume. The post-incident timeline shows the bank detected the intrusion on day one and processed that detection as noise.

2L. Compensating Controls

I Without: High. With alert generation intact: revised to Medium-High -- forensically recoverable, operationally blind.

2Q. Audit Test Procedures

  • I Request the documented investigation process for privilege alerts; absence is the finding.
  • I Walk through the five most recent triggered privilege alerts end-to-end with the analyst.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-14 -- Access management automation
Gap A: Provisioning and deprovisioning remain entirely manual. ServiceNow captures requests but does not trigger automated AD changes. No auto-revocation on role change.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.002Valid Accounts: Domain AccountsProlongsHighI Manual deprovisioning and no auto-revocation extend the lifetime of excess and orphaned access.D T1078.002
T1078.002(provisioning-error facet)EnablesMediumI Manual AD changes from tickets invite transcription errors (wrong group, wrong template), creating unintended entitlements.D T1078.002

Note: this gap is a risk multiplier for G-005 (creep) and G-011 (termination lag) I.

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • D3-UAP -- User Account Permissions D: Automated, template-driven permission assignment.
  • Authentication/credential eviction I: Automated revocation on lifecycle events.

2C. Control Type Gap

I Missing automation of preventive and corrective execution: the design (ServiceNow request -> approval) is sound, but the execution hop into AD is human.

2D. Regulatory Relevance

D The CRI text makes automation an explicit expectation ("actively managed or automated"). FFIEC guidance contemplates timely, accurate provisioning/deprovisioning. I Manual processes are not findings in themselves; examiners focus on whether the manual process achieves timely revocation.

2E. KPIs

MetricTargetFrequencySource
% of provisioning actions executed via automated workflow I>80% within 12 months of go-liveQuarterlyServiceNow/IGA reports
Provisioning error rate I<2%QuarterlyQA sampling
Mean time from HR role-change to entitlement re-baseline I<5 business days interimMonthlyHR feed vs AD change log

2H. Detection Specification

D-2.10-1 -- AD change without corresponding request I

  • Description: Provisioning-class AD change with no approved ServiceNow request -- detects out-of-process manual changes.
  • Specification:
WHERE EventID IN (4720,4728,4732,4756) AND no approved_request match on TargetUserName within +/-48h -> alert
  • Severity/Threshold: Medium (High for privileged groups); per event.
  • Validation test: Perform a ticketless test group-add; confirm alert. Perform a ticketed one; confirm suppression.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 5.6 "Centralize Account Management" and 6.7 "Centralize Access Control".

2K. Incident Scenario

I A ServiceNow ticket approves "read access to the credit-analysis share" for a new analyst. The administrator manually picks the adjacent group -- "CreditAdmin" instead of "CreditAnalyst." Nothing reconciles executed changes against approved requests, no owner reviews the share (G-001), and no alert distinguishes the grant. The analyst holds administrative rights over the credit data for a year; when her account is later compromised, the attacker inherits admin control the bank never knew it had granted.

2L. Compensating Controls

I Without: Medium. With ServiceNow request capture (existing): revised to Medium-Low for traceability. With D-2.10-1 reconciliation rule (buildable now): further reduced.

2Q. Audit Test Procedures

  • I Reconcile 25 executed AD changes against approved ServiceNow requests (existence and match).
  • I Inspect for any auto-revocation capability on role change; absence is the finding.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.
Partial RG-16 -- Termination access revocation
Gap A: Standard terminations take 2-3 business days. High-risk can be immediate. Non-AD systems (physical access, third-party apps) not simultaneously removed.

2A. ATT&CK Techniques

IDNameMapping RoleConfidenceRationaleSource
T1078.002Valid Accounts: Domain AccountsEnablesHighI A departed employee's AD credential remains valid 2-3 business days -- a defined, recurring window of authorized-looking access.D T1078.002
T1078.004Valid Accounts: Cloud AccountsEnablesHighI Third-party/SaaS apps "not simultaneously removed" -- cloud access can outlive AD revocation entirely if the app does not federate.D T1078.004
T1133External Remote ServicesFails-to-PreventMediumI VPN/webmail paths remain open during the lag window; remote channels are how an ex-employee would exercise residual access.D T1133

Physical access badge retention is a real exposure A but not modeled in ATT&CK Enterprise terms; treated in scenario and remediation I.

2B-2Q. Full Analysis

2B. D3FEND Countermeasures

  • Account Locking I: Immediate lock at HR-effective time is the direct countermeasure.
  • Authentication Cache Invalidation I: Killing active sessions/tokens at termination closes the gap left when only the password is disabled.
  • D3-MFA D: Deactivating the MFA token provides a second revocation lever.

2C. Control Type Gap

I The Corrective control exists but is Execution-Limited in speed and Scope-Limited in coverage: 2-3 days for AD; unsynchronized for physical and third-party access. The CRI text's standard is "immediately" D.

2D. Regulatory Relevance

D 12 CFR Part 364, Appendix B, III.C.1.a and III.C.2. FFIEC Information Security booklet, Section II.C -- prompt removal of access upon termination. I Termination-timeliness testing is one of the most standard examiner and auditor procedures; a systematic 2-3 day lag commonly draws attention.

2E. KPIs

MetricTargetFrequencySource
Median time HR-termination-effective to AD disable ISame business day (<4 hours)MonthlyHR records vs AD timestamps
% of terminations with physical badge + third-party apps revoked within 1 business day I100%MonthlyTermination checklist audit
Orphaned third-party accounts found in reconciliation I0QuarterlySaaS user exports vs HR roster

2F. Evidence of Closure

  • I Revised termination runbook with same-day SLA and a named executor per access class.
  • I Three months of termination-timeliness reporting meeting SLA.
  • I Quarterly third-party app reconciliation results against the HR active roster.

2H. Detection Specifications

D-2.11-1 -- Terminated-user authentication attempt I

  • Description: Any authentication event by an identity on the HR terminated list.
  • Detection Classification: Compensating Detection.
  • Specification:
WHERE auth_event.identity IN hr_terminated_list AND event_time > termination_effective -> alert High
  • Severity/Threshold: High; per event, immediate notification.
  • Validation test: Add a test identity to the terminated feed, authenticate; confirm High alert. This is the single highest-value new rule in this advisory.

D-2.11-2 -- Orphaned SaaS account reconciliation I

  • Description: Scheduled comparison of third-party app user lists against HR active roster.
  • Detection Classification: Control Failure Detection.
  • Specification:
WHERE saas_user NOT IN hr_active_roster AND saas_user.status = active -> weekly report
  • Severity/Threshold: Medium; weekly digest with per-app owner routing.

2I. CIS Benchmarks

  • D CIS Controls v8.1, Safeguard 6.2 "Establish an Access Revoking Process".
  • D CIS Controls v8.1, Safeguard 5.3 "Disable Dormant Accounts".

2K. Incident Scenario

I A back-office employee resigns after a dispute and works a final Friday. Her AD account is queued for the standard process -- disable expected Tuesday or Wednesday. Over the weekend she logs into webmail and the third-party loan-participation portal (never on the termination checklist), downloads customer statements and pipeline data, and badges into the operations area on Saturday because physical access is handled by facilities on its own schedule. Every action authenticates successfully as an authorized user; nothing alerts because no terminated-user detection exists. The bank learns of the exfiltration when a competitor's outreach to customers triggers complaints.

2L. Compensating Controls

I Without: High. With the immediate high-risk path (existing): revised to Medium-High -- the worst-case hostile termination is covered if HR correctly classifies risk. With D-2.11-1 compensating detection (buildable in days): revised to Medium.

2N. Data Classification Impact

I Highest-materiality gap for data exposure in this statement: customer NPI and financial records (email, core, loan systems, third-party portals), employee PII, and authentication secrets (active sessions, cached credentials, MFA tokens still enrolled). Physical access adds paper records and unattended-workstation exposure.

2Q. Audit Test Procedures

  • I Obtain the HR termination list for the trailing 6 months; compare termination-effective dates to AD disable timestamps, badge deactivation, and third-party app removal dates. Evidence: HR extract, AD whenChanged/disable logs, badge records, SaaS admin logs; lag distribution schedule.
  • I For 5 sampled terminations, test for post-termination authentication events in any log source.
  • I CRI EEE Package: PR.AA-01.01 evidence package -- Verify package ID.

Section 3 -- Cross-Requirement Threat Summary

3A. Compound Risks -- Techniques Spanning Multiple Gaps

TechniqueGaps Where It AppearsCompound Effect I
T1078.002 Valid Accounts: Domain Accounts DG-001, G-002/G-003, G-004, G-005, G-008, G-009, G-011The dominant compound risk. One compromised or residual domain credential is: usable from unmanaged devices (G-004), over-privileged (G-005), never owner-reviewed (G-001), manipulable without effective detection (G-002/G-003), deprovisioned slowly and manually (G-008, G-011), and hard to scope against undocumented roles (G-009). Seven gaps converge on a single attack primitive.
T1078.001 Valid Accounts: Default Accounts DG-006, G-007Reinforcing pair: weak standard for default admin passwords plus unverified removal at build time. Either alone is survivable; together they make persistent default-credential presence in production statistically expectable.
T1098 Account Manipulation DG-002, G-003, G-009Manipulation is hard to judge (no role baseline), inconsistently monitored, and un-investigated when alerted -- the full detect-decide-respond chain is degraded.
T1136 / T1136.002 Create Account DG-001, G-002/G-003Unauthorized accounts evade both the periodic control (owner review) and the continuous one (monitoring/alerting) -- no independent layer remains to find them.

3B. Highest Residual Risk

Highest Residual Risk I

G-011 (RG-16 -- termination revocation lag and scope) carries the highest residual risk. Rationale: (1) it is the only gap that guarantees a recurring, schedulable window of authorized-looking access for people with maximal insider knowledge and, in some cases, motive; (2) exposure requires no attacker sophistication -- the "exploit" is logging in; (3) its blast radius is amplified by G-005 (creep-accumulated entitlements) and its detectability is suppressed by G-002/G-003 (no terminated-user detection, degraded alerting); (4) the non-AD scope hole (third-party apps, physical) means even perfect AD execution would not close it. Deficiency class is execution, not design -- which also makes it the most tractable to fix.

3C. Cross-CRI Dependencies

I Remediation of PR.AA-01.01 gaps depends on, and feeds, adjacent CRI Profile v2.2 statement families (verify exact statement IDs):

  • PR.AA-05 (access permissions/least privilege): G-005 and G-009 remediations are shared deliverables.
  • PR.AA-03 (user/device authentication): G-004 device-trust work belongs jointly here.
  • ID.AM (asset management): G-001 owner assignment and G-004 device inventory require the asset inventory.
  • DE.CM (security continuous monitoring): G-002/G-003 tuning, tiering, and runbooks are DE.CM deliverables.
  • PR.PS (platform security/configuration): G-006/G-007 hardening standards and build verification.
  • PR.IP/HR-linked termination controls: G-011 requires an HR-to-IT event feed.

3D. Dependency Map

I Derived from gap prerequisite chains, amplification paths, and detection suppression relationships identified in Sections 2-3C.

  CHAIN 1 — Role Governance → Lifecycle
  ┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐
  │ G-009 (RG-3)     │────▶│ G-005 (RG-5)     │────▶│ G-001 (RG-6)     │
  │ Role Catalog     │     │ Least Privilege   │     │ Access Reviews   │
  └──────────────────┘     └────────┬─────────┘     └────────┬─────────┘
                                    │                         │
                                    └────────┐   ┌────────────┘
                                             ▼   ▼
                                    ┌──────────────────┐     ┌──────────────────┐
                      ┌────────────▶│ G-008 (RG-14)    │────▶│ G-011 (RG-16)    │
                      │             │ Lifecycle Automat.│     │ Termination Lag  │
                      │             └──────────────────┘     └──────────────────┘
                      │
  ┌──────────────────┐│
  │ G-004 (RG-1)     ││  CHAIN 2 — Default Credentials → Detection
  │ Device Trust     │◀┘  ┌──────────────────┐     ┌──────────────────┐
  └──────────────────┘    │ G-006 (RG-10)    │────▶│ G-007 (RG-11)    │
                          │ Admin Cred Std.  │     │ Build Verificatn │
                          └──────────────────┘     └────────┬─────────┘
                                                            │
                                                            ▼
                                                   ┌──────────────────┐     ┌──────────────────┐
                                                   │ G-002 (RG-12)    │────▶│ G-003 (RG-13)    │
                                                   │ Monitoring       │     │ Alert/Investigate │
                                                   └──────────────────┘     └──────────────────┘
                                                            ▲                        │
                                                            │    SUPPRESSES          │
                                                            └──── DETECTION ─────────┘
                                                                 OF G-011

  INDEPENDENT
  ┌──────────────────┐
  │ G-010 (RG-9)     │  No inbound/outbound dependencies.
  │ Password Reuse   │  Administrative closure candidate.
  └──────────────────┘

  ──────────────────────────────────────────────────────────────
  LEGEND
    ────▶  Prerequisite (fix source before target is effective)
    ◀────  Feeds into (automation enables device-trust scope)
    SUPPRESSES DETECTION  Degraded alerting masks exploitation
    HUB: G-008 (RG-14)   Highest fan-in — blocks 3 downstream gaps

Section 4 -- Risk Prioritization Assessment

Three-part model. No composite scores; ratings are analyst inference I grounded in assessed gap text A.

GapRGDeficiency SeverityThreat ExposurePriority
G-011RG-16Execution-Limited (speed) + Scope-Limited (non-AD)High1
G-006RG-10Documentation-Only (no elevated standard; unverified)High2
G-007RG-11Execution-Limited (inconsistent checklist, no verification)High2
G-002RG-12Execution-Limited (exists, degraded)High3
G-003RG-13Capability-Absent (no investigation process)High3
G-001RG-6Scope-Limited (Symitar only; no owner assignment)Medium4
G-004RG-1Scope-Limited (domain devices only)Medium5
G-005RG-5Capability-Absent (no justification) with adjacent controlsMedium6
G-008RG-14Capability-Absent (no automation)Medium7
G-009RG-3Documentation-Only (functional RBAC, informal mappings)Low-Med8
G-010RG-9Documentation-Only (technical control operating)Low9

Rationale notes I: Priority ranks weight (a) directness of exploitability, (b) consequence tier of affected accounts/data, (c) whether the gap suppresses detection of other gaps, and (d) remediation tractability. G-002/G-003 rank third despite High exposure because remediation partially depends on G-009's role catalog; G-009 itself ranks low standalone but is a scheduling prerequisite.

Section 5 -- Remediation Recommendations

#Gap(s)Action TypeRecommendation ITimelineCross-CRI
R1G-011Procedural EnhancementSame-day termination runbook: HR-effective-time trigger; parallel checklist covering AD disable, session/MFA revocation, badge deactivation, and every third-party app; named executor and evidence capture per class.Quick Win (<90d)HR/PR.IP
R2G-011, G-002CIS Hardening (detection)Deploy terminated-user authentication detection (D-2.11-1) and quarterly SaaS orphan reconciliation (D-2.11-2) as compensating detection while R1 lands.Quick Win (<90d)DE.CM
R3G-006, G-007Expand Existing + CIS HardeningElevated admin-credential standard; adopt platform CIS Benchmarks; deploy LAPS; automated default-credential scan as build gate and quarterly network scan.Quick Win (standard) / Strategic (LAPS)PR.PS
R4G-002, G-003Procedural EnhancementTier critical systems in SIEM; Tier-0 privilege changes to per-event paging with ticket suppression; investigation runbook; monthly tuning program.Quick Win (runbook) / Strategic (tuning)DE.CM
R5G-009Procedural EnhancementFormalize role catalog: role-to-AD-group mappings for critical systems; catalog ownership; versioning. Prerequisite for R4 baselines and R6 reviews.Quick Win (<90d)PR.AA-05
R6G-001New Risk StatementOwner-driven access recertification: system-to-owner matrix, annual cadence (semi-annual for privileged), revocation SLA; extend beyond Symitar.StrategicID.AM, PR.AA-05
R7G-005Expand ExistingMandatory business-justification field in ServiceNow; role-change entitlement re-baseline step in mover process.Quick Win (field) / Strategic (mover)PR.AA-05
R8G-004New Risk StatementExtend device trust beyond domain: expand MDM/conditional access past email; contractor device registration; MFA on all remote paths.StrategicPR.AA-03, ID.AM
R9G-008New Risk StatementIdentity-lifecycle automation: ServiceNow-to-AD integration; auto-revocation on role change. Interim: deploy D-2.10-1 reconciliation rule now.Strategic (rule: Quick Win)PR.AA-05, DE.CM
R10G-010Procedural EnhancementAmend password standard to prohibit reuse explicitly; consider raising history toward CIS baseline (24); add reuse guidance to awareness training.Quick Win (<90d)--

No Action items: none -- all eleven gaps warrant at least a procedural response I.

Priority Order I: R1 -> R2 -> R3 -> R4 -> R5 -> R7 -> R6 -> R8 -> R9 -> R10.
(R5 sequenced ahead of R6 because the role catalog is input content for both recertification and monitoring baselines.)

Section 6 -- Detection Coverage Summary

6A. Log Source Inventory

SourceStatus IFeeds Rules
Windows Security Event Log -- DCs DLikely collected (alerting exists); verify completenessD-2.1-1, D-2.2-1, D-2.4-1/2, D-2.6-1, D-2.8-1/2, D-2.10-1, D-2.11-1
Member server security logsVerify coverageD-2.3-1, D-2.6-1
VPN concentratorVerify onboardingD-2.1-2, D-2.11-1
MDM enrollment dataNew collection (export/API)D-2.1-2
ServiceNow request/approval dataNew collection (API join)D-2.4-2, D-2.10-1
HR termination/roster feedNew collection (highest leverage)D-2.11-1, D-2.11-2
Third-party/SaaS sign-in logsNew collection; availability variesD-2.11-1/2
Badge/physical access systemNew collectionD-2.11-1 (extended)
Vulnerability scanner findingsVerify default-credential checksD-2.7-1
File server / repository audit logsNew or partialD-2.3-2
Symitar admin/security logsVerify export capabilityD-2.8 core system coverage

6B. Detection Rule Summary by Classification

ClassificationRules
Threat DetectionD-2.3-1, D-2.3-2, D-2.5-1, D-2.6-1, D-2.8-1, D-2.8-2
Control MonitoringD-2.2-1, D-2.10-1
Control Failure DetectionD-2.1-2, D-2.4-2, D-2.7-1, D-2.9-1, D-2.11-2
Compensating DetectionD-2.1-1, D-2.4-1, D-2.11-1

6C. Quick Wins vs New Collection

I Buildable now on existing Windows/DC telemetry: D-2.6-1 (default-account logon), D-2.8-1/2 (tiered and off-hours privilege changes), D-2.4-1 (dormant accounts) -- largest immediate detection uplift, directly attacks the G-002/G-003 noise problem.

Requires one new feed each: D-2.11-1 (HR feed -- the single highest-value integration in this advisory), D-2.10-1 and D-2.4-2 (ServiceNow join), D-2.7-1 (scanner findings).

Longer lead time: D-2.2-1 (needs the R5 role catalog), D-2.3-2 (repository audit enablement), D-2.11-2 (per-vendor SaaS exports).

Section 7 -- Sources

Framework / InstrumentVersion / EditionURL
CRI Profilev2.2 (2026)cyberriskinstitute.org
MITRE ATT&CK Enterprisev19.1 (Apr 2026)attack.mitre.org
MITRE D3FENDv1.4.0 (Mar 2026)d3fend.mitre.org
NIST SP 800-53Rev. 5 Acsrc.nist.gov
CIS Controlsv8.1cisecurity.org
CIS Benchmarks (Windows Server)Current per platformcisecurity.org
FFIEC IT Handbook -- Information SecuritySeptember 2016ithandbook.ffiec.gov
FFIEC IT Handbook -- Architecture, Infrastructure, and OperationsJune 2021ithandbook.ffiec.gov
Interagency Guidelines -- Information Security Standards12 CFR Part 364, Appendix B (FDIC)ecfr.gov

Note: NIST SP 800-88 Rev. 2 (media sanitization) is listed in the methodology's framework set but was not referenced in this analysis and is excluded per the "only frameworks actually referenced" rule.

Section 8 -- Analytical Provenance

Provenance Table

Content ClassTagSourceExamples in This Advisory
Coverage ratings, gap descriptions, institution profileACoverage Assessment v7, Section 4 (human-assessed)Section 1 table; all "Gap" blocks; G-xxx text
Framework identifiers, event IDs, taxonomy names, citationsDPublished frameworks (ATT&CK v19.1, D3FEND v1.4.0, CIS v8.1, FFIEC, 12 CFR 364 App B)Technique IDs/URLs, Windows event IDs, safeguard numbers
Mappings, confidence, detection specs, scenarios, prioritization, remediationIAI-generated analysis (this run)All of Sections 2A-2Q analysis prose, 3, 4, 5, 6

Human Review Block

Status: Unreviewed Draft

This advisory is a research tool generated by an AI-assisted methodology (CRI Threat Mapper v12.0). No human analyst has validated the technique mappings, detection specifications, regulatory citations, or prioritization judgments. It is not an audit opinion, examination finding, or risk acceptance basis. Required before operational use: (1) analyst review of every I-tagged mapping and confidence rating; (2) verification of every "Verify ID" / "Verify section number" item against the cited framework version; (3) validation of environmental assumptions flagged "verify"; (4) sign-off by the assessment owner.

Limitations

  • Heritage Community Bank is fictional; all input data is simulated. No real-institution inference is valid.
  • ATT&CK/D3FEND mappings are inference from gap text, not from telemetry, threat intelligence, or incident history.
  • D3FEND v1.4.0 identifiers and several CIS Benchmark recommendation numbers, and FFIEC booklet subsection numbers, are flagged "Verify" where the exact identifier could not be asserted with confidence; none were fabricated.
  • Detection specifications are pseudo-code design artifacts, not executable queries; thresholds are starting points.
  • Compensating-control revised ratings assume the compensating control operates as described; several are marked "verify."
  • Coverage of "Full" requirements was accepted as assessed; this advisory did not re-test them.
  • Regulatory analysis is limited to instruments applicable to a state-chartered, FDIC-supervised community bank under $10B; OCC Heightened Standards were deliberately excluded.

Runtime Metadata

FieldValue
Analysis Date2026-07-18
CRI Threat Mapper Versionv12.0
AI ModelClaude Fable 5
CRI Profile Versionv2.2 (2026)
Input DataRequirements table (16 reqs), Gap descriptions (Yes), NIST mapping (AC-1, AC-2, AC-3, AC-5, AC-6, AC-7, IA-1, IA-2, IA-4, IA-5, IA-8)
Analysis ModeFull (descriptions provided)
Sections Generated1, 1B, 2A-2Q, 3, 4, 5, 6, 7, 8
Framework VersionsCRI v2.2 (2026), ATT&CK v19.1, D3FEND v1.4.0, CIS Controls v8.1, FFIEC current, 12 CFR 364 App B

DISCLAIMER: Heritage Community Bank is a FICTIONAL institution. All data in this advisory is simulated for research and demonstration purposes. No real-institution inference is valid. This document is not an audit opinion, examination finding, or risk acceptance basis.

Jones & Associates -- CRI Threat Mapper v12.0 | PR.AA-01.01 | 2026-07-20
--- END OF ANALYSIS ---