Domain 4 of 4 · Chapter 4 of 4

Architect identity accounting

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • What identity accounting has to prove
  • Accountability, detection, and forensics ask differently
  • Deriving the event set and defending it
  • Forensic requirements raise the bar on the same records
  • Four obligations that reshape the requirement set
  • What a single audit record must contain
  • Control-plane events and resource events
  • Time stamps and the ordering problem
  • Correlation identifiers across system boundaries
  • Keeping secrets and excess personal data out of records
  • Choosing which events warrant a notification
  • The response path behind an alert
  • Correlating before concluding
  • Reporting control outcomes, not event counts
  • The five functions of a log management infrastructure
  • Central collection without losing provenance
  • Transport obligations and the one that gets assumed
  • Capacity and the audit failure mode
  • Separation of duties over the audit store
  • Integrity, immutability, and controlled disposition
  • Retention across competing duties
  • Reading the stem: which accounting decision is under test

How four recurring obligations shape the same IAM audit record

Audit design questionFISMAPCI DSSHIPAA Security RuleGDPR
What sets the scopeFederal information systems and the risk they carry to agency operationsSystem components in and connected to the cardholder data environmentSystems that create, receive, maintain, or transmit ePHIProcessing of personal data, which includes IAM records that identify a user
What the record must supportOngoing visibility into assets, threats, vulnerabilities, and control effectivenessIndividual accountability for access to system components and cardholder dataRecording and examining activity in systems that contain or use ePHIDemonstrating that processing stayed within its stated purpose and safeguards
Position on identityAuthorization decisions and ongoing assessment of implemented controlsUnique user identification, so shared accounts defeat attributionUnique user identification alongside the audit-control mechanismsIdentifiable activity data is itself personal data and must be minimized
What drives retentionThe frequency and duration set in the organization's continuous-monitoring strategyA defined retention period for audit history, with recent records kept readily available for reviewNo log-retention period is specified; the six-year rule covers required documentationStorage limitation, so records are kept only as long as the stated purpose requires
How the design typically failsAn annual control assessment treated as a substitute for continuous monitoringA shared operations account used because every team member is authorized anywayNetwork-device logs relied on for applications that actually handle ePHISecurity monitoring invoked as a blanket reason to keep all user activity forever

Decision tree

Was the event recorded at all? 1. Requirements Derive the event set from the use cases Does the record settle what happened? 2. Audit events Content, time stamps, correlation Did a named responder act in time? 3. Alerts and notifications Recipient, escalation, response time Is the record still complete and trustworthy? 4. Log management Transport, capacity, integrity, retention All four parts hold Accountability, detection, and forensics are supported No Yes No Yes No Yes No Yes

Cheat sheet

  • Audit events should be selected from accountability, detection, and forensic use cases
  • An audit record needs enough context to reconstruct the event
  • IAM control-plane changes are high-value audit events
  • Consistent time sources are required for cross-system reconstruction
  • Correlation identifiers connect identity activity across system boundaries
  • Central collection should preserve original event provenance
  • Log transport must address confidentiality, integrity, authentication, and delivery failure
  • Log administrators should not control the activities they audit
  • Audit capacity exhaustion requires an explicit fail-safe response
  • Logs should capture evidence without collecting unnecessary secrets
  • Alerts should prioritize high-impact identity and privilege events
  • Every material audit alert needs an owned response path
  • IAM analysis should correlate control-plane and resource activity
  • Audit reporting should measure control outcomes and unresolved exceptions
  • FISMA architecture uses continuous monitoring to maintain risk visibility
  • Log retention should reconcile investigation, legal, regulatory, and privacy needs
  • Audit evidence needs tamper protection and controlled disposition
  • PCI DSS requires individual accountability and protected audit trails around cardholder data
  • HIPAA audit controls must record and examine activity involving electronic protected health information
  • GDPR logging must balance accountability with data minimization and storage limitation

Unlock with Premium — includes all practice exams and the complete study guide.

References

  1. ISSAP Certification Exam Outline
  2. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
  3. NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response Whitepaper
  4. NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
  5. NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
  6. NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations Whitepaper
  7. PCI DSS: Payment Card Industry Data Security Standard
  8. NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide Whitepaper
  9. GDPR Article 5: Principles relating to processing of personal data Whitepaper
  10. GDPR Article 32: Security of processing Whitepaper
  11. RFC 5905: Network Time Protocol Version 4: Protocol and Algorithms Specification Whitepaper
  12. NIST SP 800-63C-4, Digital Identity Guidelines: Federation and Assertions Whitepaper
  13. OWASP Logging Cheat Sheet
  14. RFC 5425: Transport Layer Security (TLS) Transport Mapping for Syslog Whitepaper
  15. RFC 5424: The Syslog Protocol Whitepaper
  16. RFC 6012: Datagram Transport Layer Security (DTLS) Transport Mapping for Syslog Whitepaper