Skip to content

Compliance traceability

The published frameworks that codify what this tool does, mapped in both directions: from each requirement to what answers it, and from each design decision to the requirements that informed it. Wordings are paraphrased; exact clause text is verified against the current edition before anything claims conformance.

Requirement What it asks What answers it here
PCI DSS 4.0, 7.2.4 Review all user accounts and privileges at least every six months Review campaigns with due dates and recurrence presets, and the per-campaign evidence export with population and coverage (D-021, D-039); tests/test_campaigns.py and tests/test_reports.py hold them
PCI DSS 4.0, 7.2.5 and 7.2.5.1 Application and system accounts get least privilege and periodic review at a risk-based frequency The non-human inventory with privilege findings attributed to their source, and campaign recurrence, all present
OWASP Non-Human Identities Top 10 (2025) The named risk classes for non-human identities Every finding carries its NHI identifier as the anchor field, from improper offboarding through human use of a non-human identity
NIST SP 800-53, AC-2 Accounts managed, reviewed on a schedule, disabled when inactive The inventory, staleness findings on a minimum observation age, and scheduled campaigns; disabling waits for the action phases by design (D-005)
NIST SP 800-53, AC-6(7) Periodic review of privileges, with removal when no longer fit Privilege findings with source attribution, and the revoke-recommended disposition carrying its reasons into the evidence export
ISO/IEC 27002:2022, 5.16 Identity lifecycle management, explicitly including non-human The whole product
ISO/IEC 27002:2022, 5.18 Access rights reviewed at planned intervals and on change Campaigns with the delta-since-last-certification view, so the review reads what changed rather than re-reading everything
CIS Controls v8, 5.1 and 5.5 An inventory of accounts, and a dedicated, validated service account inventory The inventory, derived from imports, with the as-of statement on every view
CIS Controls v8, 5.3 Dormant accounts disabled after a defined period Staleness findings with the minimum observation age; action itself deferred (D-005)
SOX ITGC and SOC 2 CC6 practice Complete population, independent reviewer, evidence per decision, timely remediation The frozen population statement, attribution on every decision, the evidence export, and a close that refuses gaps, all present
Decision Framework grounding
D-005 enrichment over automation AC-2 and CIS 5.3 name disabling as the goal; this design routes it through a human until the trust ladder earns the action phases
D-006 append-only derived state The SOX completeness and evidence expectations: a population and history that cannot silently change
D-016 immutable identifier keying OWASP NHI reuse risk: a recreated principal must not inherit standing
D-019 identities act, sources grant, both governed ISO 5.18 and universal access review practice certify group memberships, so the group must hold owners and attestations
D-021 the review campaign scope PCI 7.2.4 and 7.2.5, ISO 5.18, AC-2, and audit practice all define the periodic, evidenced review as the unit of governance