Practical resource

Secure Cloud Control Matrix

Twenty questions to expose gaps in access, privileged identity, workload trust and recurring control evidence across a Microsoft Cloud environment.

How to use itAnswer each question with evidence—not intent.
RecordRisk · control · test · evidence · owner · action.
PrioritizeStart with access to the resources that matter most.

Control domain

Identity & authentication

Know which identities can begin a path to critical resources and under which conditions.

  1. 01

    Which human, guest and emergency identities can reach each critical resource?

    Evidence example: Named identity inventory linked to resource ownership

  2. 02

    Is phishing-resistant authentication required for privileged and high-risk access?

    Evidence example: Authentication method policy and sign-in evidence

  3. 03

    Do Conditional Access policies cover every relevant access path without unmanaged exclusions?

    Evidence example: Policy map, exclusions and tested scenarios

  4. 04

    Are legacy authentication and unmanaged access paths blocked or explicitly risk-accepted?

    Evidence example: Protocol settings, exceptions and owner approval

  5. 05

    Can the team explain how device trust affects access to sensitive workloads and data?

    Evidence example: Compliance policy, device state and access test

Control domain

Privileged access

Reduce standing privilege and make elevation deliberate, time-bound and reviewable.

  1. 06

    Which privileged roles are permanent, eligible, unused or assigned outside the expected process?

    Evidence example: Role export, PIM status and last-used evidence

  2. 07

    Does privilege activation require justification, approval and strong authentication where appropriate?

    Evidence example: PIM configuration and activation history

  3. 08

    Are administrative duties separated from everyday user accounts and endpoints?

    Evidence example: Admin account model and privileged workstation controls

  4. 09

    Are emergency access accounts protected, monitored and tested without weakening normal controls?

    Evidence example: Break-glass procedure and last test evidence

  5. 10

    Who reviews privileged access, how often and what happens when ownership is unclear?

    Evidence example: Review schedule, decisions and removal record

Control domain

Workloads & data

Make non-human access and data dependencies visible before they become hidden risk.

  1. 11

    Which service principals, managed identities and applications can reach critical resources?

    Evidence example: Workload identity inventory and permission graph

  2. 12

    Does every high-impact application permission have a business and technical owner?

    Evidence example: Owner register and consent rationale

  3. 13

    Are secrets, certificates and keys inventoried with expiry and rotation responsibilities?

    Evidence example: Key and certificate inventory with lifecycle data

  4. 14

    Can cryptographic dependencies be replaced without redesigning the dependent service?

    Evidence example: Crypto-agility assessment and dependency map

  5. 15

    Are critical data paths logged well enough to investigate misuse or control failure?

    Evidence example: Logging coverage, retention and test query

Control domain

Evidence & continuous governance

Keep controls effective as configuration, people and operational exceptions change.

  1. 16

    Which controls are material enough to validate every month or quarter?

    Evidence example: Approved control baseline and validation cadence

  2. 17

    Can each control produce evidence without a manual reconstruction exercise?

    Evidence example: Repeatable query, report or validation procedure

  3. 18

    Who owns failed checks, exceptions and remediation deadlines?

    Evidence example: Named owner, due date and escalation path

  4. 19

    How is drift from the approved baseline detected and risk-ranked?

    Evidence example: Configuration comparison and risk criteria

  5. 20

    Can management see control status, open risk and remediation progress in one concise view?

    Evidence example: Current evidence pack and prioritized backlog

Next step

Several uncertain answers usually indicate an evidence or ownership gap

Enki Tech can turn the matrix into a scoped trust-path assessment, prioritized remediation plan and repeatable governance baseline.

Explore the assessment