Producing Compliance Evidence From Asset Data
Auditors ask the same questions every year. A maintained register answers most of them in minutes rather than launching a three-week exercise.
Procedure · 684 words
The register earns its keep at audit. Most of what an auditor asks about asset and access management is a query against data you should already hold.
What auditors typically ask
What systems process regulated data?
Who has access to them, and how was that access approved?
How is access removed when someone leaves? With evidence for a sample of leavers.
Who are the administrators?
When was access last reviewed, and what was removed?
What devices exist, and are they encrypted?
How are devices disposed of, and what evidence exists?
Which third parties process your data, and what diligence was done?
All eight are register queries if the register holds the right fields and is current.
The fields that carry the evidence
Data classification per application, which answers the first question.
Access lists with grant dates and approvers.
Review dates and outcomes per application.
Administrator lists with dates.
Encryption status per device, from endpoint management.
Disposal records with certificate references.
Vendor assessment dates and tiers.
Offboarding completion records per leaver.
Making the evidence credible
Dates on everything. An assertion with no date is not evidence.
A named person for each decision.
Retained artefacts, not summaries. The actual review output, the actual certificate, the actual approval.
Consistency between systems. An auditor comparing your register against your identity provider and finding disagreement will expand the sample.
Completeness you can demonstrate. How do you know the register is complete? Answering that with your discovery methodology is stronger than asserting it.
The sampling reality
Auditors sample. They take five leavers and check that access was removed.
One failure in five expands the sample and turns a clean finding into an exception.
So the process has to work, not just exist. Documentation of a process that is inconsistently followed is worse than a simpler process that runs every time.
Run your own sample before the audit. Take five recent leavers and check every application. Whatever you find, the auditor would have found.
Continuous rather than annual
The register maintained monthly produces audit evidence as a by-product.
The register assembled for the audit produces a three-week exercise, gaps that cannot be retrospectively filled, and findings.
Retrospective evidence is frequently impossible. You cannot demonstrate that access was reviewed last March if it was not.
What to keep and for how long
Access review outcomes: for the period the relevant framework requires, commonly several years.
Offboarding records: similarly.
Disposal certificates: frequently longer, and they are the hardest to reconstruct.
Vendor assessments: current plus previous.
Register snapshots: a periodic export, so you can show what the estate looked like at a past date. This is cheap and it answers questions that a current-state register cannot.
The reciprocal benefit
Everything in this note is worth doing without an audit.
The register that satisfies an auditor is the same register that answers an incident, supports a renewal negotiation and makes offboarding reliable. The audit is a deadline rather than a reason.
The self-sample before the audit
Auditors sample. Running the same sample yourself first converts a finding into a fix.
Take five recent leavers.
For each, check every application in the register, not just the federated ones.
Check the device was returned or written off, with a record.
Check OAuth grants were revoked.
Check owned applications were reassigned.
Whatever you find, the auditor would have found. Fixing it beforehand and documenting the fix is a materially better position than being shown it.
Repeat with five devices against the disposal records, which is the other sample commonly taken.
Register snapshots
A current-state register answers what exists now. Several questions need what existed then.
Export the full register monthly, dated, to immutable storage.
Include user lists where the volume permits.
Include the ownership and classification fields.
Retain for the period your obligations require.
This answers: who had access on a given date, what the estate looked like at the start of an incident, whether an application was registered at the time of a finding, and how counts changed over a period.
It costs a scheduled job and it answers questions that are otherwise unanswerable at any price.