Elke dag audit-klaar, niet alleen in de auditweek
De meeste compliance-tools laten je dingen over jezelf beweren en tonen die beweringen daarna terug als score. De uil test wat te testen is en citeert voor de rest de bepaling uit je eigen beleid. Hij blijft controleren nadat de audit getekend is. Je score scheidt wat bewezen is van wat op een document rust. Een getal dat die twee door elkaar haalt zegt niets over je beveiliging.
De weergave van een control.
Hoe één control aan zijn uitkomst komt: de checks van de agent, het gekoppelde bewijs en waar het oordeel op rust.
The entity implements logical access security software and infrastructure over protected information assets
What must be true
Access to production systems is granted through a managed identity, is removed when that identity is removed, and cannot be obtained by any route that bypasses it.
Why this outcome
Access Control Policy v4, line 41: single sign-on is mandatory for all production systems and local accounts are prohibited. The agent then verified that claim against the identity provider — 5 of 5 production systems are federated and no local account exists on any of them. The policy states the obligation; the test is what passes the control.