H.9.5 Security Audit

recommended
Reading progress2 helpful
Article in preparation — showing conspect notes

Security audit proves required access, authority, and compliance events; operational source-to-runtime tracing belongs to H.11.8 Delivery Traceability.

  • Record sensitive access, policy changes, approval decisions, rejected changes, credential use, breakglass, signing, and promotion as required by the threat model.
  • Define who may read the evidence, how long it survives, and which events can be delayed, sampled, missing, or rewritten.
  • Test joins among source, review, invocation, provenance, artifact, registry, promotion, and runtime state.
  • Distinguish security proof from operational traceability and ordinary debugging telemetry.
  • Exercise the audit with an incident or artifact rather than assuming stored records can be joined.