| critical | Users without MFA enrolled | TITANBAD_STALE | HIPAA 164.312(d) Person or Entity Authentication; CIS Snowflake 1.4 | 90 |
| critical | Users without MFA enrolled | TITANBAD_NOMFA2 | HIPAA 164.312(d) Person or Entity Authentication; CIS Snowflake 1.4 | 90 |
| critical | Users without MFA enrolled | TITANBAD_NOMFA1 | HIPAA 164.312(d) Person or Entity Authentication; CIS Snowflake 1.4 | 90 |
| critical | Users without MFA enrolled | TITANADMIN | HIPAA 164.312(d) Person or Entity Authentication; CIS Snowflake 1.4 | 90 |
| critical | Users without MFA enrolled | SVC_TITANBAD_BROAD | HIPAA 164.312(d) Person or Entity Authentication; CIS Snowflake 1.4 | 90 |
| high | Users authenticating with password instead of RSA key | TITANADMIN | CIS Snowflake 1.6; NIST 800-53 IA-5 | 75 |
| high | Users authenticating with password instead of RSA key | TITANBAD_NOMFA1 | CIS Snowflake 1.6; NIST 800-53 IA-5 | 75 |
| high | Users authenticating with password instead of RSA key | TITANBAD_NOMFA2 | CIS Snowflake 1.6; NIST 800-53 IA-5 | 75 |
| high | Users authenticating with password instead of RSA key | TITANBAD_STALE | CIS Snowflake 1.6; NIST 800-53 IA-5 | 75 |
| high | Users authenticating with password instead of RSA key | SVC_TITANBAD_BROAD | CIS Snowflake 1.6; NIST 800-53 IA-5 | 75 |
| medium | Stale users (no login in 90 days) | SVC_TITANBAD_BROAD | CIS Snowflake 1.10; NIST 800-53 AC-2(3) | 55 |
| medium | Stale users (no login in 90 days) | TITANBAD_NOMFA2 | CIS Snowflake 1.10; NIST 800-53 AC-2(3) | 55 |
| medium | Stale users (no login in 90 days) | TITANBAD_STALE | CIS Snowflake 1.10; NIST 800-53 AC-2(3) | 55 |
| medium | Stale users (no login in 90 days) | TITANBAD_NOMFA1 | CIS Snowflake 1.10; NIST 800-53 AC-2(3) | 55 |
| high | Account-level network policy not configured | account | HIPAA 164.312(e)(1) Transmission Security; CIS Snowflake 1.13 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.PATIENT_ID | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT.MEMBER_PII_SSN | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.SSN | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.MEMBER_ID | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.DOB | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.MRN | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.PHONE | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT.MEMBER_PII_DOB | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| high | Likely-PHI / PII columns without a masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.EMAIL | HIPAA 164.502 Uses and Disclosures of PHI; CIS Snowflake 4.5 | 75 |
| medium | Sensitive tables without a row-access policy | SNOWFLAKE.TRUST_CENTER.ACCOUNT_NOTIFICATION_RECIPIENTS | HIPAA 164.312(a)(1); CIS Snowflake 4.6 | 55 |
| medium | Sensitive tables without a row-access policy | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT | HIPAA 164.312(a)(1); CIS Snowflake 4.6 | 55 |
| medium | Sensitive tables without a row-access policy | SNOWFLAKE.TRUST_CENTER_STATE.ACCOUNT_NOTIFICATION_METADATA | HIPAA 164.312(a)(1); CIS Snowflake 4.6 | 55 |
| medium | Sensitive tables without a row-access policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI | HIPAA 164.312(a)(1); CIS Snowflake 4.6 | 55 |
| medium | Sensitive tables without a row-access policy | SNOWFLAKE.TRUST_CENTER_STATE.ACCOUNT_NOTIFICATION_HISTORY | HIPAA 164.312(a)(1); CIS Snowflake 4.6 | 55 |
| high | Authentication policy not configured at account level | account | PCI-DSS 8.2; NIST 800-53 IA-2; HIPAA 164.308(a)(5)(ii)(D) | 75 |
| medium | Session policy missing or idle timeout above 60 minutes | no_session_policy | PCI-DSS 8.1.8; NIST 800-53 AC-11; HIPAA 164.312(a)(2)(iii) | 55 |
| medium | Sensitive tables with Time Travel retention below 7 days | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI | HIPAA 164.316(b)(2)(i); PCI-DSS 10.5.3; SOC 2 CC7.3 | 55 |
| high | Customer-managed encryption keys (Tri-Secret Secure) not enabled | account | HIPAA 164.312(a)(2)(iv); FedRAMP SC-12; PCI-DSS 3.5.2 | 75 |
| medium | No replication or failover groups for HIPAA / PCI workloads | account | HIPAA 164.308(a)(7) Contingency; PCI-DSS 12.10.1; SOC 2 A1.2 | 55 |
| medium | Recent Cortex AI calls invoked from likely-PHI tables | TITANADMIN | HIPAA 164.502; NIST AI RMF GV-2 | 55 |
| high | Users without MFA enrolled | SVC_TITANBAD_BROAD | HIPAA 164.312(d); CIS Snowflake 1.4 | 75 |
| critical | Users without MFA enrolled | TITANADMIN | HIPAA 164.312(d); CIS Snowflake 1.4 | 90 |
| high | Users without MFA enrolled | TITANBAD_NOMFA1 | HIPAA 164.312(d); CIS Snowflake 1.4 | 75 |
| high | Users without MFA enrolled | TITANBAD_NOMFA2 | HIPAA 164.312(d); CIS Snowflake 1.4 | 75 |
| high | Users without MFA enrolled | TITANBAD_STALE | HIPAA 164.312(d); CIS Snowflake 1.4 | 75 |
| critical | PUBLIC role granted on regulated data object | TITAN_DEMO.PUBLIC_BAD | HIPAA 164.502; PCI-DSS 7.1; CIS Snowflake 2.1 | 90 |
| critical | PUBLIC role granted on regulated data object | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT | HIPAA 164.502; PCI-DSS 7.1; CIS Snowflake 2.1 | 90 |
| critical | PUBLIC role granted on regulated data object | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI | HIPAA 164.502; PCI-DSS 7.1; CIS Snowflake 2.1 | 90 |
| medium | Role holds 10 distinct privileges | R_TITANBAD_EXPLOSION | NIST 800-53 AC-6 Least Privilege; CIS Snowflake 2.5 | 55 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.EMAIL | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.MEMBER_ID | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.DOB | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.SSN | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.PHONE | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT.MEMBER_PII_DOB | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.PATIENT_ID | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.MEMBER_ACCOUNT.MEMBER_PII_SSN | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | PHI / PII column without masking policy | TITAN_DEMO.PUBLIC_BAD.PATIENT_PHI.MRN | HIPAA 164.502; CIS Snowflake 4.5 | 75 |
| high | External stage without server-side encryption | TITAN_DEMO.PUBLIC_BAD.BAD_EXT_STAGE | HIPAA 164.312(a)(2)(iv); CIS Snowflake 4.2 | 75 |