Changed-Fact Decision Key — Scenarios 10–18
S10 — Suspicious 2 a.m. access
Primary: abnormal behavior requires real-time response.
Best: Active monitoring.
Weaker: wait for weekly reporting.
Changed fact: only weekly comparison is needed → Passive monitoring.
Supporting: Governance, Storage & Operations; security operations, DBA, Owner, incident/control owner.
S11 — Trend review
Primary: periodic behavioral assessment.
Best: Passive monitoring.
Weaker: call every review Audit.
Changed fact: independent assurance examines evidence against policy/regulation → Audit.
Supporting: Governance; security operations, control owner, audit consumer.
S12 — Proof of training
Primary: intent exists but auditable evidence is required.
Best: recorded training completion tied to identity/authorization/audit trail.
Weaker: verbal assertion.
Changed fact: asks which rule requires training → Policy/Standard; asks how to prove it → Evidence/Audit Trail.
Supporting: Governance, Metadata; training/control owner, IAM/security, auditor, manager.
S13 — New role model
Primary: scalable access assignment.
Best: centrally managed RBAC + least-privilege membership/approval.
Weaker: bespoke permissions for every user.
Changed fact: start from classified data and ask which roles perform which operations → Role Assignment Grid / CRUD.
Supporting: Governance; Owner, IAM/security, managers, application owners.
S14 — Data-first role design
Primary: translate classification/regulation + function into access.
Best: Role Assignment Grid.
Weaker: start from org hierarchy.
Changed fact: starts from job families/workgroups and inheritance → Role Assignment Hierarchy.
Supporting: Governance, Metadata; Steward/Owner, IAM/security, role-design owner.
S15 — Contracted cloud analytics
Primary: vendor operates controls; organization retains accountability.
Best: shared responsibility, custody, SLA/contract, audit rights, monitoring/reporting.
Weaker: “vendor is responsible” = accountability transferred.
Changed fact: provider no longer processes/stores organization data and no custody/control is delegated → outsourcing custody is no longer primary.
Supporting: Governance, Metadata; Owner, vendor manager/procurement, legal, security, auditor.
S16 — Security added at end
Primary: requirements found after design.
Best: identify classification/regulatory/access/logging needs during analysis.
Weaker: retrofit everything after release.
Changed fact: only public non-sensitive presentation changes and no new exposure → analysis can be proportionate.
Supporting: Data Architecture, Governance; architect, security, Owner/Steward, development team.
S17 — Audit conflict
Primary: auditor lacks independence/separation of duties.
Best: separate assurance from control operation.
Weaker: DBA expertise substitutes for independence.
Changed fact: DBA performs routine monitoring and an independent function later audits evidence → separation problem resolved.
Supporting: Governance, Storage & Operations; independent auditor, DBA/control operator, governance/risk owner.
S18 — Metric overload
Primary: counts lack baseline, target, interpretation, action.
Best: smaller actionable/baselined metric set across the five Chapter 7 groups.
Weaker: add more indicators.
Changed fact: a count is tied to threshold/baseline, owner, and corrective action → it becomes an actionable metric.
Supporting: Governance; security leadership, metric owners, governance/risk stakeholders.