Free · Ungated · Anonymous

Could you evidence your Linux access controls to an auditor today?

The free Linux identity maturity assessment: twenty questions on the sudo rules, SSH keys, service accounts and access reviews that NIS2, DORA and the CIS Benchmarks ask you to evidence. Answer for your estate as it is today and get a level from 1 to 4, with the gaps that matter most and where to focus next. No form, no vendor pitch.

5–8 minutes5 capability domains · 20 questionsFor Security, IAM, & Linux infrastructure teams

What you'll get

A maturity level (1–4) across 5 Linux identity domains, with specific gaps and prioritised next steps — no vendor pitch attached.

How to answer

Answer for your Linux environment as it is today, not as it's planned. There are no wrong answers — honesty produces the most useful output.

What we cover

Identity inventory, privilege control, access governance, service accounts & NHI — including the accounts AI agents authenticate as — and compliance & audit readiness across Linux systems.

0/ 80

0 of 20 answered

Not started

The foundation of Linux identity security is knowing what exists. Most organisations discover their biggest risk is simply not knowing — orphaned accounts, undocumented service users, and shared credentials that predate their current team.

How complete is your current inventory of human accounts with Linux access?

Orphaned accounts are the single most common critical finding across Linux environments. You cannot secure what you cannot see.

How quickly could you produce a complete list of every account with local login access to a given Linux server?

Audit teams and incident responders ask this question on short notice. Manual effort of more than an hour is a control gap.

Do you have visibility into accounts that exist on Linux systems but are not linked to a current employee, contractor, or service?

These orphaned or ghost accounts are the most common privilege escalation entry point and often predate current team membership.

How well do you understand group membership across Linux systems — specifically which users are in security-sensitive groups (sudo, wheel, docker, etc.)?

Over-permissive group membership is often invisible. Many privilege escalation paths exist through groups, not individual account settings.