{"id":10167,"date":"2026-08-31T05:40:55","date_gmt":"2026-08-31T03:40:55","guid":{"rendered":"https:\/\/qdata.pl\/blog\/identity-security-what-auditors-check-first\/"},"modified":"2026-08-31T07:15:18","modified_gmt":"2026-08-31T05:15:18","slug":"identity-security-what-auditors-check-first","status":"publish","type":"post","link":"https:\/\/qdata.pl\/de\/blog\/identity-security-what-auditors-check-first\/","title":{"rendered":"Identity Security in der Praxis: Was Pr\u00fcfer zuerst kontrollieren"},"content":{"rendered":"<div class=\"qdata-blog-tldr\">\n<h3>TL;DR<\/h3>\n<ul>\n<li>Identity is the fastest path from &#8220;we have ISO tools&#8221; to &#8220;we can prove control&#8221; \u2014 or the fastest path to a major finding.<\/li>\n<li>Auditors sample privileged accounts, MFA exceptions and JML tickets \u2014 not your policy PDF alone.<\/li>\n<li>Break-glass accounts must be rare, monitored and tested; standing admin is a finding waiting to happen.<\/li>\n<li>Evidence beats narrative: access reviews, logs and ticket IDs tied to approvals.<\/li>\n<\/ul>\n<\/div>\n<p>Security programmes often lead with network diagrams and endpoint agents. External auditors \u2014 whether for ISO 27001, NIS2 readiness, DORA or customer due diligence \u2014 usually start elsewhere: <strong>who can access what, through which path, with what approval, and can you prove it for last quarter<\/strong>. Identity is not a subsection of IT. It is the control plane. When identity is weak, every other control becomes harder to trust: your SIEM cannot tell a legitimate admin from a stale vendor account that should have been disabled.<\/p>\n<p>We have sat in audit opening meetings where the CISO presents a polished ISMS folder and the lead auditor replies, &#8220;Thank you \u2014 now show me three terminated contractors and when their access was removed.&#8221; That question sets the tone for the week. The organisations that pass smoothly are rarely the ones with the most tools. They are the ones where HR status, IAM provisioning and ticket numbers line up without improvisation.<\/p>\n<h2>The first three samples auditors request<\/h2>\n<p><strong>Privileged access inventory<\/strong> comes first. Auditors do not accept &#8220;we have few admins&#8221; as evidence. They want a list of accounts with elevated rights across Active Directory, Entra ID or Azure, cloud IAM roles, database sysadmin equivalents and SaaS admin consoles \u2014 with last-use timestamps and named human owners. Standing global administrator without Privileged Identity Management or just-in-time elevation is routinely flagged. One manufacturing client discovered fourteen dormant Global Admin accounts from a 2019 migration; three had logged in within the last month with no documented reason.<\/p>\n<p><strong>MFA coverage and exceptions<\/strong> is the second sample. Tenant-level &#8220;MFA enabled&#8221; is not the same as enforced on every sign-in path. Auditors ask for the percentage of users with phishing-resistant MFA where the platform supports it, plus every documented exception: legacy protocols, service accounts, break-glass, integration users. Each exception needs a compensating control, an expiry date and a named approver. A spreadsheet of &#8220;temporary&#8221; exceptions that renewed quarterly for two years is a major nonconformity waiting to be written.<\/p>\n<p><strong>Joiner\u2013mover\u2013leaver evidence<\/strong> closes the opening trio. Auditors pick three random hires, role changes and terminations from the last ninety days. For each they trace HR ticket to provisioning request to access granted to access removed. Gaps between HR offboarding date and account disable \u2014 even forty-eight hours \u2014 are among the most common major findings in B2B IT. In one case a departed sales engineer retained VPN access for eleven days because &#8220;IT was waiting for laptop return.&#8221; The laptop was irrelevant to the VPN credential.<\/p>\n<h2>What &#8220;good&#8221; looks like without buying another portal<\/h2>\n<p>Mature identity security is deliberately boring. Role-based groups map to job functions, not to individuals&#8217; convenience. Access recertification runs on a calendar with named data owners who actually click approve or revoke \u2014 not auto-approve after reminder emails. Privileged sessions are logged; break-glass accounts live offline, are counted on one hand and are exercised in a tabletop quarterly. The tooling varies: Entra ID, Okta, Keycloak, on-prem AD. The <em>evidence model<\/em> does not.<\/p>\n<p>We recommend a single <strong>identity control matrix<\/strong>: control objective, system of record, log source, review cadence, owner. When an auditor asks &#8220;show me how you revoke vendor access within twenty-four hours of contract end,&#8221; you open one row \u2014 not five Slack threads and a manager&#8217;s memory. The matrix is not bureaucracy; it is the map that lets a new CISO or MSP take over without losing audit readiness.<\/p>\n<p>Good identity also means <strong>time-to-revoke<\/strong> as a measured SLA, not a policy aspiration. If HR marks someone terminated at 17:00 Friday, when does IAM show disabled? Chart it monthly. Spikes correlate with reorganisations and acquisitions \u2014 exactly when auditors expect gaps.<\/p>\n<h2>Common failures we see in B2B IT<\/h2>\n<p>Shared mailbox accounts used as pseudo-users for RDP or VPN appear in almost every mid-market review. They cannot hold MFA cleanly, blur accountability and survive reorganisations because &#8220;everyone knows the password.&#8221; Vendor accounts without contract end dates in IAM are another staple: the integrator who built the warehouse API in 2021 still has production database read access because nobody owned offboarding when the project closed.<\/p>\n<p>Local administrator on laptops &#8220;because helpdesk is faster&#8221; undermines entire device trust models. Cloud IAM sprawl \u2014 project-level Owner for convenience, service account keys in repos \u2014 turns up in equal measure. Each failure is fixable, but not by policy PDF alone. Automate disable on HR status change, enforce PIM for cloud admin, block legacy auth where modern protocols exist, and measure exceptions shrinking quarter over quarter.<\/p>\n<h2>Scenario: ISO surveillance vs customer security questionnaire<\/h2>\n<p>Consider two assurance events in the same month. ISO surveillance samples JML and privileged access \u2014 evidence-heavy, process-focused. A enterprise customer&#8217;s questionnaire asks about SSO, MFA enforcement on admin roles and how you manage third-party access to production. If your answers differ between the two because identity data lives in three systems, you will contradict yourself under time pressure.<\/p>\n<p>The fix is one source of truth for identity evidence: exports from IdP, ticketing IDs, access review sign-offs. A fintech client unified these into a quarterly &#8220;identity pack&#8221; consumed by internal audit, customer DD and regulatory prep. Preparation time for each event dropped from weeks to days \u2014 not because they bought a GRC unicorn, but because they stopped rebuilding the same story from scratch.<\/p>\n<h2>How this connects to wider assurance<\/h2>\n<p>Identity findings cascade. Poor JML invalidates penetration test scope when the tester uses a stale vendor account that should have been removed. Weak MFA on admin paths means red-team success is attributed to &#8220;sophisticated attack&#8221; when the root cause was standing privilege. Strong identity shrinks attack surface and makes technical testing meaningful: findings reflect real control gaps, not hygiene debt.<\/p>\n<p>If you are preparing for NIS2, DORA or a board risk committee, start identity evidence before you order another vulnerability scanner. Scanners find holes; identity proves you know who can walk through them. Our <a href=\"\/de\/service\/audit-and-information-security-consulting-msisa-cism-cissp-ceh-chfi-iso-27001\/\">Audit- und Informationssicherheitsberatung<\/a> practice maps controls to your actual IdP and ticketing \u2014 then helps close gaps with operable runbooks, not slide decks.<\/p>","protected":false},"excerpt":{"rendered":"<p><span data-no-translation>Vor Pentest-Funden pr\u00fcfen Auditoren Identity: MFA-Abdeckung, privilegierten Zugriff, Joiner-Mover-Leaver und Belege, dass Zugriff zur Rolle passt \u2014 nicht Hoffnung auf Tabellenkalkulation. Was sie stichproben und wie Sie sich vorbereiten.<\/span><\/p>","protected":false},"author":1,"featured_media":10131,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[64],"tags":[],"class_list":["post-10167","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-compliance"],"_links":{"self":[{"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/posts\/10167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/comments?post=10167"}],"version-history":[{"count":1,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/posts\/10167\/revisions"}],"predecessor-version":[{"id":10172,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/posts\/10167\/revisions\/10172"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/media\/10131"}],"wp:attachment":[{"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/media?parent=10167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/categories?post=10167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qdata.pl\/de\/wp-json\/wp\/v2\/tags?post=10167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}