- Environments in Scope*
- Tenant data separation approach*
- Authorization model*
- Tenant-scoped access enforcement consistency*
- Access control maturity by dimension*
- Is tenant data encrypted at rest?*
- Is tenant data encrypted in transit?*
- Are backups segregated by tenant?*
- Is network segmentation enforced between tenants?*
- Firewall and security group isolation effectiveness*
- Are container or virtual machine isolation controls applicable in this environment?*
- Container or virtual machine isolation safeguards
- Shared service protections
- Resource quotas and noisy-neighbor protections*
- Audit logging coverage*
- Tenant-specific log separation*
- Alerting and monitoring coverage*
- Detection of cross-tenant access attempts*
- Applicable compliance requirements*
- Security review status*
- Identified risks and remediation priorities*
- Should be Empty: