Findings

Deficiencies raised against controls, ordered by severity then remediation SLA

13 findings

FND-1044CriticalOpenCVE-2026-21841Unmapped40d overdue

Critical container base image patches exceed 30-day SLA

Nine production container images are running base layers with unpatched critical CVEs first detected between 41 and 78 days ago, exceeding the one-month patch window required by PCI DSS 6.3.3.

Remediation Rebuild affected images against the hardened base tag 2026.08 and enable the automated base-image bump job.

Automated scanregistry/northwind/*opened 14 Jun 2026
FND-1041CriticalRemediatingUnmapped5d overdue

Three terminated contractors retained SSO access beyond 24-hour window

Access reconciliation for the July sample identified three contractor accounts that remained active in the identity provider for 6, 9, and 14 days after their termination date. All three retained group membership granting read access to the production data warehouse.

Remediation Wire the HRIS termination webhook directly to the IdP deprovisioning job and add a daily reconciliation alert for orphaned accounts.

Manual testokta/northwind-prodopened 4 Aug 2026
FND-1039CriticalOpenUnmapped3d overdue

Standing AdministratorAccess role assigned to 11 engineers

Eleven engineering accounts hold a permanently attached AdministratorAccess policy in the production AWS account rather than obtaining privileges through just-in-time elevation. Standing privilege contradicts the documented least-privilege model.

Remediation Migrate all eleven principals to Teleport JIT roles with a four-hour maximum session and approval-on-elevation.

Automated scanaws/prod-458821opened 6 Aug 2026
FND-1043CriticalAwaiting verificationCVE-2026-31022Unmappeddue 25 Aug 2026

Two internet-facing services affected by known-exploited RCE

Two internet-facing services depend on a library version affected by a remote code execution vulnerability listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Patch to 4.9.2 in both services, then confirm remediation with an authenticated rescan before closing.

Automated scansvc-gateway, svc-webhooksopened 11 Aug 2026
FND-1029HighOpenUnmapped54d overdue

Four active vendors processing customer data without current security review

The vendor register lists four vendors with expired security reviews that continue to process customer personal data under active contracts.

Remediation Complete refreshed security reviews and suspend data flows for any vendor not cleared within 30 days.

Manual testvendor-registeropened 14 May 2026
FND-1032HighOpenUnmapped7d overdue

IAM role drift between declared matrix and deployed assignments

Twenty-two role assignments in production do not appear in the approved role definition matrix. Six of them grant write access to payment service configuration.

Remediation Reconcile the role matrix, revoke unapproved assignments, and enforce matrix changes through Terraform review.

Automated scanaws/prod-458821opened 19 Jul 2026
FND-1046HighRemediatingUnmappeddue 1 Sep 2026

Seven production repositories not enrolled in SCA scanning

Scanner enrolment reconciliation shows seven repositories deploying to production without software composition analysis configured, so dependency vulnerabilities in those services are never detected.

Remediation Apply the shared compliance CI template at group level and set the scanning job to required rather than opt-in.

Automated scangitlab/northwindopened 18 Aug 2026
FND-1047HighOpenUnmappeddue 2 Sep 2026

Vulnerability register missing risk ranking for 34 findings

The vulnerability register contains 34 entries with no assigned risk ranking or owner, so they are excluded from SLA tracking entirely. PCI DSS 6.3.1 requires a risk ranking on every identified vulnerability.

Remediation Backfill rankings using the CVSS-plus-exploitability rubric and reject scanner output that lacks a ranking.

External audittrivy/registry-scanopened 19 Aug 2026
FND-1018MediumOpenUnmapped36d overdue

Post-incident review missing for INC-2340

A severity-2 incident from June closed without a documented post-incident review, so root cause and corrective actions were never recorded.

Remediation Produce the retrospective review and block incident closure in the tooling until the review is attached.

Manual testINC-2340opened 18 Jun 2026
FND-1035MediumRemediatingUnmappeddue 27 Aug 2026

Configuration drift on 14 EC2 hosts against CIS baseline

Fourteen hosts have drifted from the declared baseline, most commonly re-enabled password authentication over SSH and disabled audit daemon.

Remediation Re-apply the hardening playbook and enable drift auto-remediation for the sshd and auditd resources.

Automated scanaws/prod-458821opened 30 Jul 2026
FND-1022MediumRemediatingUnmappeddue 29 Aug 2026

Threat models absent for three services released this period

Three services reached production without a recorded threat model, contrary to the secure development lifecycle requirement.

Remediation Complete retrospective threat models and add the artifact as a release checklist gate.

Manual testsvc-ledger, svc-notify, svc-searchopened 1 Jul 2026
FND-1027MediumRemediatingUnmappeddue 30 Aug 2026

DLP policy not applied to two sanctioned file-sharing channels

Two approved external sharing channels operate without DLP inspection, leaving an unmonitored egress path for regulated data.

Remediation Extend the DLP policy set to both channels and validate with a synthetic regulated-data test file.

Manual testnetskope/policiesopened 30 Jun 2026
FND-1049MediumOpenUnmappeddue 15 Sep 2026

Q3 internal vulnerability scan not evidenced as clean

The Q3 internal scan was executed but no rescan evidence was retained to demonstrate that high-risk findings were resolved and verified.

Remediation Re-run the internal scan and archive both the initial and clean rescan reports to the evidence store.

External auditqualys/internal-scopeopened 20 Aug 2026