← CISA: audit IT, controls, and resilience
07 / 8 · 30 MIN

Identity, data, and protection boundaries

Assess the actual reach of access and cryptographic controls.

Concept and mechanism

Identity spans creation, assignment, use, review, and revocation. A disabled directory state does not prove that personal tokens, sessions, and local accounts lost access. Use authorized tests and records to assess relevant paths, avoiding an assumption of abuse merely because access still works. Segregation of duties also depends on who controls identities, not only different names. When policy requires independent approval, logs of one person creating and approving do not automatically satisfy that requirement. Records remain useful for detection and investigation but must be assessed against the control’s precise objective.

Guided application

Encryption has a protection boundary. Data encrypted at rest may be read by the application and authorized users; that does not prove algorithm failure. Control access and exports after decryption. During key rotation, retain authorized capability to recover retained data or plan re-encryption; recreating a name does not recreate deleted material. For a TLS certificate, a valid date does not replace the appropriate name and trust chain. In cloud, provider physical-security evidence does not demonstrate patching of a customer-managed guest. For physical access, a shared badge identifies an object and needs corroboration to attribute entry to a person.

IN PRACTICE

An encrypted backup depending on a deleted key may exist without being a usable recovery option.

Common pitfalls

Disabling one account as revoking every path; encryption as protection of every use; hash or name as identity.

Related topics: Detection, testing, and incident evidence · Audit mandate, independence, and planning

Take this idea with you

Ask what the control protects, at which point, and against which condition.

Create account

Reference: Authentication and Authenticator Management · CISA outline effective August 1, 2024