Drata collects data from your cloud security posture management (CSPM) software to determine if there are active issues related to accounts with excessive administrative privileges.
ASSOCIATED DRATA CONTROL
This test is part of the Privileged Access Restricted and Need-to-know Principle controls that ensures that only authorized personnel have access to system, resources and sensitive data.
WHAT TO DO IF A TEST FAILS
If Drata finds one or more issues from your CSPM, the test will fail. With a failed test, you will receive a list of issues along with associated entities and severity.
To remediate a failed test, you will need to exclude the issues or you will need to communicate to the Security team to fix and close the issues.