Critical
CC6.1.3
Multi-factor authentication for privileged accounts
Security
2 admin accounts missing MFA
Due: Jan 25, 2025
High
CC7.2.1
Security incident response plan testing
Security
Annual test overdue by 15 days
Overdue
High
PI1.3.2
Data processing agreement documentation
Processing Integrity
3 vendors missing DPAs
Due: Feb 1, 2025
Medium
C1.2.4
Data classification policy review
Confidentiality
Policy review pending approval
Due: Feb 15, 2025
Medium
P3.1.1
Privacy notice updates
Privacy
Privacy policy needs update for new data collection
Due: Feb 28, 2025