Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Capabilityspecificatie

Time-bound access elevations

JIT Privileged Access

Time-bound access elevations defines a core capability outcome delivered by JIT Privileged Access, including implementation intent and execution coverage.

nDSGDORANIS2

Doel

Translate JIT Privileged Access intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.

Scopecontext

Privilege elevation only through ticketed, expiring, and auditable sessions.

Invoer

- Current-state architecture and operating model

- Approved bundle scope and target compliance obligations

- Delivery constraints, timeline, and responsible owners

Uitvoer

- Implemented capability increment with ownership mapping

- Execution notes and evidence pointers for review

- Operational handover requirements for production use

Acceptatiecriteria

- Capability can be demonstrated in a controlled walkthrough

- Owner, scope, and change boundaries are explicit

- Linked controls and evidence references are complete

Compliance-bewijsnotities

- [nDSG] Capability execution mapped in JIT Privileged Access control evidence

- [DORA] Capability execution mapped in JIT Privileged Access control evidence

- [NIS2] Capability execution mapped in JIT Privileged Access control evidence

Specificatieschema

Eigenaarsrol

Capability Stream Owner

Goedkeuringssign-off

Product owner and platform lead

Versioneringsbeleid

Revisioned per release with backward-compatibility notes

Reviewcadans

Sprint review and monthly capability maturity checkpoint

Bewijsretentie

Operational evidence retained for at least 12 months

Verplichte secties

- Capability objective and intended business outcome

- Technical scope and dependency matrix

- Implementation steps and ownership mapping

- Validation checklist and acceptance evidence

- Operational handover and support model