Specifikacia kontroly
No persistent admin role assignments
JIT Privileged Access
No persistent admin role assignments defines an enforceable control requirement inside JIT Privileged Access, with measurable checkpoints and operational constraints.
Ucel
Enforce policy and runtime constraints tied to JIT Privileged Access so drift and non-compliant operations are blocked early.
Kontext rozsahu
Privilege elevation only through ticketed, expiring, and auditable sessions.
Vstupy
- Policy requirements and risk appetite definition
- System boundaries and affected components
- Exception handling workflow and escalation owner
Vystupy
- Control implementation with enforceable policy condition
- Monitoring signal and alerting threshold
- Exception register entry with expiry and audit trace
Akceptacne kriterie
- Control blocks or flags non-compliant state changes
- Evidence is exportable for internal or external audit
- Exception path is time-bounded and explicitly approved
Poznamky ku compliance dokazom
- [nDSG] Control objective and test outcome recorded for assurance
- [DORA] Control objective and test outcome recorded for assurance
- [NIS2] Control objective and test outcome recorded for assurance
Schema specifikacie
Rola vlastnika
Security and Platform Governance Owner
Schvalovaci sign-off
Governance lead plus founder-level exception approval for bypasses
Politika verzovania
Policy revision tags linked to deployment release ID
Rytmus revizie
Bi-weekly control health review and quarterly deep audit
Retencia dokazov
Control test evidence retained for at least 18 months
Povinne sekcie
- Control objective and policy statement
- Trigger conditions and enforcement mechanism
- Monitoring signals and alert thresholds
- Exception process with expiry policy
- Control test method and result capture format