cc6.1-5-001

CC6.1 · D5 · f1

D5
Difficulty
5
Gaps
0
Red Herrings
55%
Avg Score

Task

You are a SOC 2 auditor evaluating Nimbus Health's logical access controls under Trust Services Criteria CC6.1. Review all provided evidence documents to assess whether access provisioning, access reviews, termination procedures, and identity management controls are operating effectively. This is a healthcare company handling PHI, so consider the sensitivity of the data environment. For each finding, assess its materiality and provide your reasoning on whether the issue represents a significant control deficiency or a minor procedural gap. Several of the issues you will find require professional judgment to determine their severity and significance.

Evidence

Findings

IDTypeSeverityFinding
F-001gaphighTwo Okta Accounts with No Matching HR Records
The Okta user report shows 180 active accounts, but HR records indicate 172 employees plus 6 contractors (178 total). Two accounts do not match any HR record: USR-0179 (platform-monitoring, an integra...
F-002gapmediumAWS Access Review Self-Review by Infrastructure Manager
The Q4 access review for AWS Console (Production) was performed by James Chen, Cloud Infrastructure Lead (AR-Q4-001). James Chen is the individual responsible for managing AWS infrastructure and IAM p...
F-003gapmediumWeekend Termination Access Revocation Delay
Employee Derek Chung (TERM-Q4-004) was terminated Friday December 5 at 5:00 PM EST, but his Okta account was not disabled until Monday December 8 at 9:12 AM EST -- a gap of 64 calendar hours. The acce...
F-004gaplowAWS Access Review Completed 2 Business Days Past SLA
The AWS Console access review (AR-Q4-001) was completed on October 24, 2 business days after the 15-business-day SLA deadline of October 22. The policy (Section 5.1) requires access reviews to be comp...
F-005gapmediumContractor Okta Accounts Missing Expiration Dates
The access control policy (Section 3.3) requires that contractor accounts 'be created with a designated expiration date aligned with the contract end date.' The Okta user report shows 6 active contrac...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic83%100%71%83%5/57
Opus 4.7Anthropic67%100%50%67%5/510
GPT-5.5OpenAI57%80%44%57%4/59
GPT-4.1OpenAI62%80%50%62%4/58
Haiku 4.5Anthropic30%100%18%30%5/528
GPT-4oOpenAI31%40%25%31%2/58