ACCOUNT-TAKEOVER REVIEW WORKSHEET Tervaq Security Intelligence Version: 2026-10-06 Blank planning template. Use only with appropriate authorization. Do not enter live credentials or unnecessary personal data. SCOPE AND PERMISSION Agree on the environment and the authority to test. A completed worksheet is not authorization by itself. System, environment, release, and accountable owner: [Complete within your approved internal environment] Written authorization reference and permitted dates: [Complete within your approved internal environment] Approved test identities and data-handling restrictions: [Complete within your approved internal environment] Request limits, prohibited actions, and stop conditions: [Complete within your approved internal environment] ENROLLMENT AND IDENTITY BOUNDARIES Distinguish finding a record from establishing the applicant’s right to claim it. Evidence required before digital access is issued: [Complete within your approved internal environment] Information disclosed before identity verification: [Complete within your approved internal environment] Expected outcomes for existing, unregistered, and unsupported test records: [Complete within your approved internal environment] Owner of each handoff between record matching, verification, and access issuance: [Complete within your approved internal environment] RECOVERY AND SENSITIVE CHANGES Review the routes around the initial sign-in decision, including support-assisted exceptions. Evidence required for account recovery: [Complete within your approved internal environment] Controls for changing contact details or adding devices: [Complete within your approved internal environment] Independent authorization for sensitive account actions: [Complete within your approved internal environment] Support exceptions and the approvals governing them: [Complete within your approved internal environment] OBSERVATION AND LEGITIMATE USE A blocked action is only part of the outcome. Check whether the customer and the investigator can still complete their work. Expected and observed result for each approved test: [Complete within your approved internal environment] Events and timestamps visible to the investigating team: [Complete within your approved internal environment] Legitimate customer paths, accessibility needs, and failure handling: [Complete within your approved internal environment] Sensitive data excluded from logs and shared evidence: [Complete within your approved internal environment] REMEDIATION AND CLOSURE Tie closure to a result observed in an identified release, not merely to a configuration change. Finding, proposed mitigation, and change owner: [Complete within your approved internal environment] Retest release, configuration, and evidence references: [Complete within your approved internal environment] Result: verified / partial / not reproduced / not assessed: [Complete within your approved internal environment] Residual risk, acceptance owner, and follow-up review date: [Complete within your approved internal environment] Source: https://tervaq.com/resources/account-takeover-review