• Multi-Tenant Security Architecture Assessment Form

    Use this form to evaluate the security architecture of a multi-tenant system, including tenant isolation, access control, data segregation, shared-resource protections, monitoring, and overall risk posture.
  • Assessment Scope and Environment

  • Environments in Scope*
  • Tenant Isolation and Access Control

  • Tenant data separation approach*
  • Authorization model*
  • Tenant-scoped access enforcement consistency*
    Rows
  • Access control maturity by dimension*
    Rows
  • Data Protection and Segregation

  • Is tenant data encrypted at rest?*
  • Is tenant data encrypted in transit?*
  • Are backups segregated by tenant?*
  • Network, Platform, and Shared Resource Controls

  • Is network segmentation enforced between tenants?*
  • Firewall and security group isolation effectiveness*
    Rows
  • Are container or virtual machine isolation controls applicable in this environment?*
  • Container or virtual machine isolation safeguards
    Rows
  • Shared service protections
    Rows
  • Resource quotas and noisy-neighbor protections*
    Rows
  • Logging, Monitoring, and Incident Response

  • Audit logging coverage*
  • Tenant-specific log separation*
  • Alerting and monitoring coverage*
  • Detection of cross-tenant access attempts*
  • Compliance, Risk, and Overall Assessment

  • Applicable compliance requirements*
  • Security review status*
  • Identified risks and remediation priorities*
    Rows
  • Should be Empty:
Select theme: