Kontrollspezifikation
Dual-control key management workflows
HSM Key Vault
Dual-control key management workflows defines an enforceable control requirement inside HSM Key Vault, with measurable checkpoints and operational constraints.
Zweck
Enforce policy and runtime constraints tied to HSM Key Vault so drift and non-compliant operations are blocked early.
Scope-Kontext
Hardware-backed key governance integrated with workload identity and rotation policy.
Eingaben
- Policy requirements and risk appetite definition
- System boundaries and affected components
- Exception handling workflow and escalation owner
Ausgaben
- Control implementation with enforceable policy condition
- Monitoring signal and alerting threshold
- Exception register entry with expiry and audit trace
Abnahmekriterien
- Control blocks or flags non-compliant state changes
- Evidence is exportable for internal or external audit
- Exception path is time-bounded and explicitly approved
Compliance-Evidence-Notizen
- [nDSG] Control objective and test outcome recorded for assurance
- [NIS2] Control objective and test outcome recorded for assurance
Spezifikationsschema
Owner-Rolle
Security and Platform Governance Owner
Freigabe-Sign-off
Governance lead plus founder-level exception approval for bypasses
Versionierungsrichtlinie
Policy revision tags linked to deployment release ID
Review-Rhythmus
Bi-weekly control health review and quarterly deep audit
Evidenzaufbewahrung
Control test evidence retained for at least 18 months
Erforderliche Abschnitte
- Control objective and policy statement
- Trigger conditions and enforcement mechanism
- Monitoring signals and alert thresholds
- Exception process with expiry policy
- Control test method and result capture format