About this program
The Twitter, LinkedIn, Instagram and TikTok accounts your brand depends on get over-shared, under-protected and almost never audited. Quick check.
Risks addressed
- High Shared password across the marketing team leaks
- High Departed agency or contractor retains access
- Critical Account takeover damages brand or distributes malware
Controls (7)
-
Inventory of every corporate social account + owner
HighThis control requires the organization to maintain a centralized, current inventory of all social media accounts owned or operated on behalf of the organization, including platform name, account handle, business purpose, and designated account owner/custodian. The inventory must cover official…
How to test + evidence
Testing procedure: List every official handle, platform, owner and approval workflow.
Evidence to collect: Social account register.
-
MFA on every social account (hardware key for Tier-1)
CriticalThis control mandates the activation of multi-factor authentication (MFA) on all corporate and business-related social media accounts, with hardware-based authentication keys (e.g., FIDO2 U2F tokens) required for Tier-1 accounts. Tier-1 typically includes accounts with high visibility, executive access, or brand…
How to test + evidence
Testing procedure: Verify 2FA / passkey on every account; X / Meta / LinkedIn / TikTok / YouTube.
Evidence to collect: MFA status screenshots.
-
No shared / personal email used for account recovery
HighThis control prohibits the use of shared mailboxes or personal email addresses (e.g., Gmail, Yahoo, Outlook.com) as recovery mechanisms for privileged, service, or corporate user accounts. Instead, recovery options must leverage corporate-controlled email infrastructure, hardware tokens, or authenticated administrative workflows.…
How to test + evidence
Testing procedure: Recovery email points to a managed corporate mailbox, not an individual.
Evidence to collect: Account recovery settings.
-
Posting via central tool (Hootsuite / Sprout / etc.)
MediumThis control requires that all corporate social media posts be published through a centralized social media management platform (e.g., Hootsuite, Sprout Social, Buffer) rather than directly via native platform interfaces. Centralized tools enforce approval workflows, log all posting activity with…
How to test + evidence
Testing procedure: Posters do not have direct platform login; tool brokers access via OAuth.
Evidence to collect: Tool config + access list.
-
Access reviewed quarterly + removed at offboarding
HighThis control requires organizations to conduct formal reviews of user access rights on a quarterly basis and immediately revoke access upon employee termination or role change. The quarterly review ensures access privileges remain aligned with current job responsibilities and the…
How to test + evidence
Testing procedure: Quarterly recert + offboarding checklist explicitly revokes social access.
Evidence to collect: Recert report + JML checklist.
-
Documented response plan for account takeover
HighThis control requires the organization to maintain a documented, approved incident response plan specifically addressing account takeover (ATO) scenarios. The plan must define roles, responsibilities, detection criteria, containment procedures, communication protocols, and recovery steps when user accounts are compromised through…
How to test + evidence
Testing procedure: Playbook: who calls the platform, who notifies legal, how to communicate to followers.
Evidence to collect: Playbook + most recent test.
-
Login activity alerts on each account
MediumThis control requires that each user account be configured to generate and deliver real-time or near-real-time alerts upon login events, including successful and failed authentication attempts. Alerts may be delivered via email, SMS, mobile push notification, or in-app notification to…
How to test + evidence
Testing procedure: Platform-level alerts for new logins / device changes piped to a monitored inbox.
Evidence to collect: Alert config + sample.