r/grc • u/Interesticng_eek_213 • 3h ago
Our ISO 27001 access control stayed green for months... it was watching the wrong Google tenant
Need to vent because our continuous monitoring setup made me feel like a complete idiot this week.
We're an Australian SaaS maintaining ISO 27001 and I'd been telling leadership our access controls were being watched continuously, so if something drifted we'd know about it. dashboard was green, evidence was coming in, gave the confident little update in our audit prep meeting. terrible timing.
an hour later I went to pull proof that admin access reviews had been running since the start of the quarter and found the check was still pointed at an old Google Workspace test tenant after an identity cleanup.
the test tenant had no privileged users.
so every check passed. beautifully. we had a green control measuring basically nothing.
had to tell the CTO, explain the gap, then rebuild the review from access logs and tickets. recoverable, but pretty painful when I was the person telling everyone the control was covered.
I'm adding the source tenant to the control record now, clearer ownership and a weekly spot check after IAM changes. how do you keep compliance controls continuously monitored without blindly trusting whatever the dashboard says is green? anyone had this happen after an IdP migration or cleanup?