Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Control Specification

Automated rotation and expiry enforcement

HSM Key Vault

Automated rotation and expiry enforcement defines an enforceable control requirement inside HSM Key Vault, with measurable checkpoints and operational constraints.

nDSGNIS2

Purpose

Enforce policy and runtime constraints tied to HSM Key Vault so drift and non-compliant operations are blocked early.

Scope Context

Hardware-backed key governance integrated with workload identity and rotation policy.

Inputs

- Policy requirements and risk appetite definition

- System boundaries and affected components

- Exception handling workflow and escalation owner

Outputs

- Control implementation with enforceable policy condition

- Monitoring signal and alerting threshold

- Exception register entry with expiry and audit trace

Acceptance Criteria

- Control blocks or flags non-compliant state changes

- Evidence is exportable for internal or external audit

- Exception path is time-bounded and explicitly approved

Compliance Evidence Notes

- [nDSG] Control objective and test outcome recorded for assurance

- [NIS2] Control objective and test outcome recorded for assurance

Specification Schema

Owner Role

Security and Platform Governance Owner

Approval Sign-Off

Governance lead plus founder-level exception approval for bypasses

Versioning Policy

Policy revision tags linked to deployment release ID

Review Cadence

Bi-weekly control health review and quarterly deep audit

Evidence Retention

Control test evidence retained for at least 18 months

Required Sections

- Control objective and policy statement

- Trigger conditions and enforcement mechanism

- Monitoring signals and alert thresholds

- Exception process with expiry policy

- Control test method and result capture format