Control · ACC-01
MFA and SSO enforced for workforce access
Access ControlSOC 2 · ISO 27001 · ITGC · RBIRisk High
Requirement to validation
Requirement
ISO-A.5.17 · ISO-A.8.5 · ITGC-AM-04 · RBI-ITGRCA-2023-7.1 · SOC2-CC6.1
mapped
Policy
Access Control Policy
pol-access
Control
ACC-01
MFA and SSO enforced for workforce access
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · GitHub Enterprise Cloud
mapped
Evidence · Q3
6 items
6 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-RBI-ACC-01 · High confidence
Finding
None
Action
None
Validation
Not planned
What should be true
All workforce access to corporate and production systems is authenticated through Microsoft Entra ID SSO with phishing-resistant MFA enforced by conditional access.
- Requirements
- ISO-A.5.17 A.5.17 · Authentication informationISO-A.8.5 A.8.5 · Secure authenticationITGC-AM-04 ITGC-AM-04 · Authentication and password / MFA configurationRBI-ITGRCA-2023-7.1 RBI-ITGRCA-2023 §7.1 · Access control — least privilege, privileged access management, periodic review (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC6.1 CC6.1 · Logical access security software, infrastructure and architectures
- Third parties
- —
- Testing procedure
- Entra conditional access + federation of AWS and GitHub to Entra. Tests: Microsoft Entra ID: Conditional access requires MFA for all users; Amazon Web Services (ap-south-1): AWS IAM Identity Center federated to Entra; GitHub Enterprise Cloud: GitHub org enforces SAML SSO. Frequency continuous.
Findings (0)
○ No data available
Evidence (8)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-001 | Microsoft Entra ID · configuration report (Q2) | ACC-01 | Microsoft Entra ID | 8 Jun 2026 | Accepted |
| Q2-EV-002 | Amazon Web Services (ap-south-1) · ticket sample (Q2) | ACC-01 | Amazon Web Services (ap-south-1) | 13 Jun 2026 | Accepted |
| RBI-REQ-003 | Microsoft Entra ID: Conditional access requires MFA for all users | ACC-01 | Microsoft Entra ID | 7 Oct 2026 | Accepted |
| RBI-REQ-004 | AWS: AWS IAM Identity Center federated to Entra | ACC-01 | 6 Oct 2026 | Accepted | |
| RBI-REQ-005 | GitHub: GitHub org enforces SAML SSO | ACC-01 | 5 Oct 2026 | Accepted | |
| SOC2-REQ-001 | Microsoft Entra ID: Conditional access requires MFA for all users | ACC-01 | Microsoft Entra ID | 9 Oct 2026 | Accepted |
| SOC2-REQ-002 | AWS: AWS IAM Identity Center federated to Entra | ACC-01 | 8 Oct 2026 | Accepted | |
| SOC2-REQ-003 | GitHub: GitHub org enforces SAML SSO | ACC-01 | 7 Oct 2026 | Accepted |
Tests (3)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-RBI-ACC-01 | ACC-01 · MFA and SSO enforced for workforce access | Q3 2026 Unified Program Review | 3 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Pass | High |
| TST-SOC2-ACC-01 | ACC-01 · MFA and SSO enforced for workforce access | Q3 2026 Unified Program Review | 3 Oct 2026 | Laura Bennett · Kestrel Assurance LLP | Pass | High |
| TST-Q2-ACC-01 | ACC-01 · MFA and SSO enforced for workforce access | Q2 2026 Unified Program Review | 12 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Pass | High |