IT & Cyber Audit
Password Policy & MFA Coverage
Coverage of multi-factor authentication and password-policy enforcement across critical systems and users.
Why MFA coverage is now a baseline expectation
Multi-factor authentication and enforced password policy are the most effective defences against credential compromise, and their absence on financial and privileged systems is increasingly cited in AGSA IT control findings and POPIA security-safeguard assessments. Coverage gaps, even on a few critical accounts, undermine the whole control. AuditPro Core measures MFA and password-policy enforcement across critical systems and users so blind spots are visible.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
MFA coverage
82%
▲ 14 pts vs prior
Policy-compliant pwd
76%
Privileged without MFA
26
critical exposure
Systems assessed
18
MFA coverage by system
Authentication gaps
| System | MFA % | Weak pwd users | Priority |
|---|---|---|---|
| Legacy billing | 52 | 84 | Critical |
| Payroll | 71 | 41 | High |
| Financial (mSCOA) | 78 | 33 | High |
| 91 | 18 | Medium |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Coverage is only as strong as its weakest gap
MFA protects the institution only where it is actually enforced; a handful of exempted privileged accounts can negate the benefit. Measuring coverage against the full critical-user population is what matters.
Policy enforcement differs from policy existence
A documented password policy means nothing if systems do not technically enforce complexity, rotation and lockout. Assurance comes from confirming enforcement, not from the policy document.
Privileged users are the priority
MFA on administrator and finance-system accounts yields the greatest risk reduction. Prioritising coverage there before general users reflects the actual threat model.
How AuditPro Core Bridges the Gap
- Coverage measurement: AuditPro Core reports MFA and policy enforcement against the defined critical-user and system population.
- Gap identification: uncovered accounts and non-enforcing systems are flagged specifically rather than reported as an average.
- Remediation tracking: closing gaps is assigned and monitored to completion.
- Traceability: coverage evidence supports both the IT controls file and POPIA safeguards assessment.
Key Takeaways
- A few uncovered privileged accounts can negate MFA's benefit.
- Confirm technical enforcement, not just a written policy.
- Prioritise MFA on privileged and finance-system accounts.
- Coverage evidence serves both AGSA and POPIA requirements.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
