Designing Audit and Compliance Architecture
1. Designing Audit Logging Architecture
| Field | Detail |
|---|---|
| who | actor_id, role, IP, device |
| what | action, resource, before/after |
| when | UTC timestamp |
| where | service, region |
| why | request_id / trace_id |
2. Designing Audit Trail Storage
| Property | Detail |
|---|---|
| Append-only | No updates; immutable |
| WORM storage | S3 Object Lock, Glacier Vault Lock |
| Hash chain | Tamper-evident (each row hashes prev) |
| Retention | 7 years typical; per regulation |
| Separate account | Restrict admin access |
3. Designing GDPR Compliance
| Right | Implementation |
|---|---|
| Access | Self-service data export |
| Erasure | Crypto-shred or hard delete; cascade |
| Portability | Machine-readable export |
| Rectification | User edit own data |
| Consent | Granular, revocable, logged |
| DPA / DPIA | Vendor assessments, risk analysis |
4. Designing HIPAA Compliance
| Control | Detail |
|---|---|
| PHI encryption | At rest + in transit |
| Access controls | Role-based, least privilege |
| Audit logs | All PHI access |
| BAA | With every vendor handling PHI |
| Backup / DR | Required |
5. Designing SOC2 Compliance
| TSC | Detail |
|---|---|
| Security | Required; access, change mgmt, vuln |
| Availability | SLA monitoring, DR testing |
| Confidentiality | Encryption, NDAs |
| Processing integrity | QA, monitoring |
| Privacy | Notice, consent, retention |
| Tools | Vanta, Drata, Secureframe automate evidence |
6. Designing Access Control Auditing
| Process | Detail |
|---|---|
| Quarterly access review | Owners certify |
| Joiner/mover/leaver | Auto-provision/revoke |
| Privileged access | JIT, time-bound (e.g., Teleport, Boundary) |
| SoD checks | Conflicting roles flagged |
7. Designing Data Encryption Compliance
| Standard | Detail |
|---|---|
| FIPS 140-2/3 | Validated crypto modules |
| KMS / HSM | Cloud KMS, AWS CloudHSM |
| Key rotation | Automatic |
| BYOK / HYOK | Customer-managed keys |
8. Designing Privacy-by-Design Architecture
| Principle | Detail |
|---|---|
| Data minimization | Collect only what's needed |
| Purpose limitation | Use only for declared purpose |
| Default privacy | Most privacy-preserving default |
| Pseudonymization | Tokenize identifiers |
| DPIA | For high-risk processing |
9. Designing Compliance Reporting
| Report | Detail |
|---|---|
| Access reports | Who accessed what data |
| Change logs | Config changes |
| Incident reports | Breach notifications (72h GDPR) |
| Automated evidence | From compliance platforms |
10. Designing Data Anonymization
| Technique | Detail |
|---|---|
| Suppression | Drop direct identifiers |
| Generalization | Age 27 → 25–30 |
| k-anonymity | Each record indistinguishable from k-1 |
| Differential privacy | Noise injection |
| Tokenization | Reversible with vault |
11. Designing Data Retention Policies
| Practice | Detail |
|---|---|
| Per-data-type policy | Logs vs PII vs financial differ |
| Automated purge | Job enforces retention |
| Legal hold | Override delete during litigation |
| Documentation | Retention schedule register |
12. Designing PCI DSS Compliance
| Control | Detail |
|---|---|
| Tokenize PAN | Reduce CDE scope |
| Hosted fields / iframe | Stripe Elements; never touch raw card |
| Network segmentation | Isolate CDE |
| Quarterly ASV scans | External vuln scans |
| Annual pen test | + on major change |
| Encryption | AES-256 at rest; TLS 1.2+ transit |