Controls and Evidence Pipeline
Last updated on
Purpose
Section titled “Purpose”This module defines how controls are enforced and how evidence is generated automatically for compliance and audit use cases.
Control categories
Section titled “Control categories”- Preventive controls: Guardrails that block non-compliant changes before deployment.
- Detective controls: Monitoring controls that identify deviations and suspicious behavior.
- Corrective controls: Response controls that contain and resolve incidents.
Evidence pipeline model
Section titled “Evidence pipeline model”- Source layer: Collect audit events, platform telemetry, and workload observability data.
- Normalization layer: Standardize and enrich records for policy and reporting.
- Retention layer: Apply retention and access policies aligned with compliance obligations.
- Reporting layer: Provide control status and evidence extracts for governance and audit.
STACKIT references
Section titled “STACKIT references”- Audit Logging: Documentation
- Telemetry Router and Logs: Basics and Introduction To Logs
- Observability: Documentation
Anti-patterns to avoid
Section titled “Anti-patterns to avoid”- Evidence by spreadsheet: Manual and inconsistent evidence handling across teams.
- Disconnected telemetry: Audit, platform, and application signals cannot be correlated.
- No recurring verification: Controls are declared effective without periodic validation.