CISO · Compliance Manager
Kimlik tarafınız muhtemelen olgun. Boşluk yetkisiz erişimde değil, yetkili kişinin kuralsız işleminde. Your identity side is probably mature. The gap is not unauthorised access. It is an authorised person acting without a rule.
Kimlik yönetimi yerinde. Yetkiler tanımlı, erişim gözden geçiriliyor, ayrıcalıklı hesaplar izleniyor.
Identity management is in place. Privileges are defined, access is reviewed, privileged accounts are monitored.
Sonra bir yönetici bir veri istiyor. Yetkili bir kişi, izinli bir sorgu çalıştırıyor, sonucu bir dosyaya alıp gönderiyor. Hiçbir kural ihlal edilmiyor.
Then a manager asks for some data. An authorised person runs a permitted query, puts the result in a file and sends it. No rule is broken.
Bu işlemde kimin hangi gerekçeyle hangi veriyi aldığı, hangi alanların açık gittiği ve dosyanın nereye ulaştığı hiçbir yerde birlikte durmuyor.
Who took which data for what stated reason, which fields went out in the clear, and where the file ended up are nowhere recorded together.
Üretim verisi okuma işlemi, değişiklik kadar ciddi bir işlem olarak ele alınır: talep, gerekçe, onay ve teslim tek kayıtta durur.
Reading production data is treated as seriously as changing it: request, reason, approval and delivery live in a single record.
Hangi alanın maskeleneceği kişinin kararı olmaktan çıkar, kuralın kararı olur. Bir alan açık gidecekse bunun onayı ayrıca kayda geçer.
Which field is masked stops being a person's decision and becomes the rule's decision. If a field goes out in the clear, that approval is recorded separately.
Kanıt sonradan toplanmaz. Teslimin kendisi kaydı üretir ve bu kayıt, kaydı tutan sistemin dışından doğrulanabilir.
Evidence is not gathered afterwards. The delivery produces the record, and that record can be verified from outside the system that keeps it.