Advanced / Compliance lessons

Advanced / Compliance · Lesson 3

Audit Readiness

Evidence packs for SOX, ISO, and regulators — continuous proof instead of quarterly panic.

Auditors ask three questions: Who has access? Who approved it? Can you show it was removed when no longer needed?

An audit-ready IGA program keeps living evidence:

  • Authoritative joiner/mover/leaver events with timestamps.
  • Request and approval history linked to entitlements.
  • SoD policy definitions, violations, and exception register.
  • Certification campaign results with reviewer identity and decisions.
  • Privileged session or checkout logs from PAM where applicable.

Avoid “screenshot archaeology.” Exportable reports, immutable logs, and clear control owners beat ad-hoc spreadsheets. Map controls to frameworks (SOX ITGC, ISO 27001 A.5/A.8, NIS2, DORA) so the same evidence serves multiple assessments.

Continuing theme: reduce standing privilege so there is less high-risk access to explain.

Interactive check

No game on this lesson — try Access Request Flow or Spot the SoD Conflict.

Mark complete

Save progress on this device. Track completion unlocks badges in a later release.