Architect identity accounting
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- What identity accounting has to prove
- Accountability, detection, and forensics ask differently
- Deriving the event set and defending it
- Forensic requirements raise the bar on the same records
- Four obligations that reshape the requirement set
- What a single audit record must contain
- Control-plane events and resource events
- Time stamps and the ordering problem
- Correlation identifiers across system boundaries
- Keeping secrets and excess personal data out of records
- Choosing which events warrant a notification
- The response path behind an alert
- Correlating before concluding
- Reporting control outcomes, not event counts
- The five functions of a log management infrastructure
- Central collection without losing provenance
- Transport obligations and the one that gets assumed
- Capacity and the audit failure mode
- Separation of duties over the audit store
- Integrity, immutability, and controlled disposition
- Retention across competing duties
- Reading the stem: which accounting decision is under test
How four recurring obligations shape the same IAM audit record
| Audit design question | FISMA | PCI DSS | HIPAA Security Rule | GDPR |
|---|---|---|---|---|
| What sets the scope | Federal information systems and the risk they carry to agency operations | System components in and connected to the cardholder data environment | Systems that create, receive, maintain, or transmit ePHI | Processing of personal data, which includes IAM records that identify a user |
| What the record must support | Ongoing visibility into assets, threats, vulnerabilities, and control effectiveness | Individual accountability for access to system components and cardholder data | Recording and examining activity in systems that contain or use ePHI | Demonstrating that processing stayed within its stated purpose and safeguards |
| Position on identity | Authorization decisions and ongoing assessment of implemented controls | Unique user identification, so shared accounts defeat attribution | Unique user identification alongside the audit-control mechanisms | Identifiable activity data is itself personal data and must be minimized |
| What drives retention | The frequency and duration set in the organization's continuous-monitoring strategy | A defined retention period for audit history, with recent records kept readily available for review | No log-retention period is specified; the six-year rule covers required documentation | Storage limitation, so records are kept only as long as the stated purpose requires |
| How the design typically fails | An annual control assessment treated as a substitute for continuous monitoring | A shared operations account used because every team member is authorized anyway | Network-device logs relied on for applications that actually handle ePHI | Security monitoring invoked as a blanket reason to keep all user activity forever |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
References
- ISSAP Certification Exam Outline
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
- NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response Whitepaper
- NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
- NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
- NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations Whitepaper
- PCI DSS: Payment Card Industry Data Security Standard
- NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide Whitepaper
- GDPR Article 5: Principles relating to processing of personal data Whitepaper
- GDPR Article 32: Security of processing Whitepaper
- RFC 5905: Network Time Protocol Version 4: Protocol and Algorithms Specification Whitepaper
- NIST SP 800-63C-4, Digital Identity Guidelines: Federation and Assertions Whitepaper
- OWASP Logging Cheat Sheet
- RFC 5425: Transport Layer Security (TLS) Transport Mapping for Syslog Whitepaper
- RFC 5424: The Syslog Protocol Whitepaper
- RFC 6012: Datagram Transport Layer Security (DTLS) Transport Mapping for Syslog Whitepaper