Residual access after termination
Identity still enabled after the recorded termination date, with no unexpired access extension.
CISA CPG 3.D
Control library
13 control objectives from NIST SP 800-53, each with a ready-to-run query for Microsoft Sentinel, AWS Athena and Splunk — 39 in all. Every page states the evidence it needs, the settings you decide, and what a result does not prove.
Validation belongs to each platform path. Select a status to highlight only the matching platform queries within each control.
Showing all 13 controls
Identity still enabled after the recorded termination date, with no unexpired access extension.
CISA CPG 3.D
Privileged role held by an identity with no successful authentication inside the inactivity threshold.
CISA CPG 3.H
Privileged role lacking a documented owner or justification, or overdue for its required review.
CISA CPG 3.H
Privileged identity with no MFA enrolled, or observed authenticating with a single factor.
CISA CPG 3.F
Active credential older than the rotation interval, or approaching hard expiry.
An account exceeded the defined consecutive-failure threshold within the counting window, and no lockout was recorded during the burst or in the hour following it.
CISA CPG 3.E
Audit logging configuration stopped, deleted, or modified; the reviewer determines whether the actor was authorized.
CISA CPG 3.Q
Asset declared as requiring audit logging is producing no observed telemetry in the observation window.
CISA CPG 3.Q, 4.B
Security-relevant configuration differs from the approved baseline with no matching approved change record.
CISA CPG 3.N
Inbound rule permitting unrestricted source access with no current, unexpired entry in the approved exposure register.
CISA CPG 3.S, 3.I
Asset declared as requiring backup has no successful backup within twice its recovery point objective.
CISA CPG 3.O
A device generated authentication or platform telemetry, has been doing so for longer than the registration grace period, and does not appear in the supplied asset inventory.
CISA CPG 3.R, 2.A
An asset still reports an active finding for a CVE in CISA's Known Exploited Vulnerabilities catalogue, after the remediation date CISA published for that entry.
CISA CPG 2.B
No control matches those filters.
Each check finds a specific, defined condition in systems you already run. Resolving what it finds is your work, and a result is not a compliance determination. Every page says what its own result does not establish.
Lab-validated means the query was executed against a real search engine in a controlled instance on a recorded date. Not tenant-validated means it has passed the automated suites but has not been run anywhere real. The distinction is shown per platform rather than averaged away.