How to resolve Sprinto check for collecting evidence against configured login protection mechanism

About

Sprinto Check: Periodic review of login protection methods for critical system {critical system name}

The primary compliance requirement for access control on critical systems is establishing login protection methods. Once you've defined the methods used to control access, the next step is to provide implementation evidence.

Purpose

The purpose of this check is to collect evidence for the login protection methods defined for the critical systems. The collected evidence is submitted for the compliance audit.

The check is periodic and becomes active six months after the last evidence submission. You can adjust the check activation frequency if necessary.

How to Resolve

To resolve this check, you need to upload evidence for the login protection methods configured for the critical system.

Here is the evidence you can upload for this check:

Login Protection Method

Evidence type

Multi-Factor Authentication (MFA)

Upload a screenshot showcasing the MFA configuration for this system. Additionally, you can upload screenshots or reports demonstrating MFA enabled for the relevant user accounts.

Complex Password

Upload a screenshot illustrating the password complexity requirements set up for this system.

Single Sign-On (SSO)

Upload a screenshot displaying the configured SSO provider for this system.

Virtual Private Network (VPN)

Upload a screenshot presenting the configured VPN provider for this system.

Procedure

  1. Log in to Sprinto as an administrator.

  2. Navigate to Data Library > Access, then select the critical system you want to address.

  3. Choose the Access Review tab and select the Evidence should be uploaded for selected login methods within the critical system {critical system name} check.

  4. On the Fix it page, choose one of the following options to upload a file.

    • File: To upload evidence files from your computer.

    • Link: If the evidence is stored online, paste the shareable link.

  5. Select the evidence record date, then click Save.

Last updated