CEK-16 Key Suspension
Monitor, review and approve every transition of a key into or out of suspension, so no key changes state unnoticed.
4
artefacts
1
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Monitoring or alerting on key state changes · SIEM / log platform
periodic reviewEvidence produced at each review
- Records of suspension and reinstatement events with approver · Document repository
- Review evidence for suspended keys still in that state · Document repository
governing documentDocuments that govern the control
- The suspension procedure with approval requirements · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Suspension performed operationally with no approval trail
- Keys left suspended indefinitely with no review
- State changes not monitored, so an unauthorised reinstatement would pass unseen
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet