Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Specification de capacite

Segregated key governance boundaries

HSM Key Vault

Segregated key governance boundaries defines a core capability outcome delivered by HSM Key Vault, including implementation intent and execution coverage.

nDSGNIS2

Objectif

Translate HSM Key Vault intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.

Contexte de perimetre

Hardware-backed key governance integrated with workload identity and rotation policy.

Entrees

- Current-state architecture and operating model

- Approved bundle scope and target compliance obligations

- Delivery constraints, timeline, and responsible owners

Sorties

- Implemented capability increment with ownership mapping

- Execution notes and evidence pointers for review

- Operational handover requirements for production use

Criteres d acceptation

- Capability can be demonstrated in a controlled walkthrough

- Owner, scope, and change boundaries are explicit

- Linked controls and evidence references are complete

Notes de preuve de conformite

- [nDSG] Capability execution mapped in HSM Key Vault control evidence

- [NIS2] Capability execution mapped in HSM Key Vault control evidence

Schema de specification

Role responsable

Capability Stream Owner

Validation finale

Product owner and platform lead

Politique de versioning

Revisioned per release with backward-compatibility notes

Cadence de revue

Sprint review and monthly capability maturity checkpoint

Retention des preuves

Operational evidence retained for at least 12 months

Sections obligatoires

- Capability objective and intended business outcome

- Technical scope and dependency matrix

- Implementation steps and ownership mapping

- Validation checklist and acceptance evidence

- Operational handover and support model