Specification de capacite
Audit evidence trail of all elevation events
JIT Privileged Access
Audit evidence trail of all elevation events defines a core capability outcome delivered by JIT Privileged Access, including implementation intent and execution coverage.
Objectif
Translate JIT Privileged Access intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.
Contexte de perimetre
Privilege elevation only through ticketed, expiring, and auditable sessions.
Entrees
- Current-state architecture and operating model
- Approved bundle scope and target compliance obligations
- Delivery constraints, timeline, and responsible owners
Sorties
- Implemented capability increment with ownership mapping
- Execution notes and evidence pointers for review
- Operational handover requirements for production use
Criteres d acceptation
- Capability can be demonstrated in a controlled walkthrough
- Owner, scope, and change boundaries are explicit
- Linked controls and evidence references are complete
Notes de preuve de conformite
- [nDSG] Capability execution mapped in JIT Privileged Access control evidence
- [DORA] Capability execution mapped in JIT Privileged Access control evidence
- [NIS2] Capability execution mapped in JIT Privileged Access control evidence
Schema de specification
Role responsable
Capability Stream Owner
Validation finale
Product owner and platform lead
Politique de versioning
Revisioned per release with backward-compatibility notes
Cadence de revue
Sprint review and monthly capability maturity checkpoint
Retention des preuves
Operational evidence retained for at least 12 months
Sections obligatoires
- Capability objective and intended business outcome
- Technical scope and dependency matrix
- Implementation steps and ownership mapping
- Validation checklist and acceptance evidence
- Operational handover and support model