Security Operations, IAM & Zero-Trust Control Centre
Governs production security readiness for BLACKSWAN Capital Markets OS — Microsoft Entra OIDC posture, MFA & conditional access, RBAC/ABAC entitlements, privileged-access management, session/token controls, secrets & keys, WAF/API protection, SIEM/logging, vulnerability management, secure SDLC, and security incident response. Every control carries an owner, an evidence reference, and an explicit conservative posture: internal readiness only, not security certification, not regulatory approval, not authorization for external launch.
Security Operations & IAM domains
Production target is Microsoft Entra OIDC. Staging uses simulated factors; Entra registration drafted, awaiting tenant admin sign-off.
MFA mandatory for all admin and evidence-pack-owner roles. Conditional access rules drafted by jurisdiction, device posture, and session age.
Roles for founder, admin, evidence owner, reviewer, observer, stakeholder-room recipient. ABAC attributes: jurisdiction, classification, MNPI scope.
Just-in-time elevation, recorded sessions, dual approver for break-glass, time-boxed token issuance, no shared admin credentials.
Short-lived access tokens, refresh-token binding, sliding-session expiry, hard-cap re-auth, anti-replay, secure cookie flags.
Cloud KMS for application keys, secret manager for service credentials, rotation cadence per class, zero plain-text secrets in repos.
Edge WAF for OWASP Top 10 + custom rule pack for stakeholder room endpoints, evidence-pack export, auth flow, file upload.
Centralised security log pipeline: auth events, admin actions, stakeholder-room access, evidence-pack read/write, anomaly triage.
Dependency scan, static analysis, secret scan, infra review on every release. P0/P1 block release; P2/P3 track to SLA.
Every release gated by Approval & Sign-Off + Release Control. Security review for changes touching auth, RBAC, secrets, evidence flow.
Severity triage, paging, war-room, regulator notification trigger, board paging trigger, evidence preservation, post-incident review.
Control inventory · access reviews · session/token logs · key rotation · WAF/SIEM samples · vuln status · incident timeline.
Identity, MFA, conditional access & admin controls
| Control | Owner | State | Evidence ref | Last test | Blocker | Next action |
|---|---|---|---|---|---|---|
| Microsoft Entra OIDC registration | CISO · Identity Lead | Drafted | SEC-EV-ENTRA-001 | 2026-05-12 | Tenant admin sign-off on app registration scope | Complete tenant registration & capture client/redirect URIs |
| MFA policy (admin + evidence-pack owner) | CISO | Policy drafted | SEC-EV-MFA-002 | 2026-05-13 | Entra readiness | Enforce via Entra Conditional Access once tenant live |
| Conditional access (jurisdiction · device · session age) | CISO · IT Ops | Drafted | SEC-EV-COND-003 | 2026-05-13 | Device-posture signal source pending | Pilot device-posture check in admin cohort |
| Founder / admin RBAC | CISO · Programme Manager | Enforced | SEC-EV-RBAC-004 | 2026-05-14 | None | Quarterly access review next 2026-08-01 |
| Evidence-pack owner roles | Head of Evidence | Enforced | SEC-EV-EVOWN-005 | 2026-05-14 | None | Quarterly access review |
| Stakeholder room recipient roles | Head of Stakeholder Rooms · CISO | Enforced | SEC-EV-ROOM-006 | 2026-05-15 | None | Per-room access review on every share |
| Break-glass account | CISO · COO (dual) | Conditional Approval | SEC-EV-BREAK-007 | 2026-04-02 | Quarterly break-glass test overdue (target 2026-05-02) | Schedule break-glass drill; produce evidence + revoke |
| Access reviews (quarterly) | CISO · Programme Manager | Q2 review in progress | SEC-EV-AXR-008 | 2026-05-15 | 1 stale assignment under triage | Close stale assignment by 2026-05-22 |
| Privileged session logging | CISO · SRE Lead | Enforced | SEC-EV-PSL-009 | 2026-05-15 | None | Continue weekly review of high-risk action sample |
| Token expiry & refresh binding | Identity Lead | Enforced | SEC-EV-TOK-010 | 2026-05-14 | None | Re-test on Entra cutover |
Production identity controls, staging-auth quarantine, cutover gate
Staging founder-only factors (email + passphrase + static MFA) are internal rehearsal only. They are held in process memory, with no real tenant, no real directory, no real Conditional Access, and no real SIEM forwarding. They are not production identity and are not external-use authorised. Production code paths must refuse the staging factor set before cutover.
| Control | Owner | State | Approval state | Approval authority | Evidence ref | Last reviewed | Unlock criterion |
|---|---|---|---|---|---|---|---|
| Microsoft Entra OIDC app registration ENTRA_TENANT_ID · ENTRA_CLIENT_ID · ENTRA_ISSUER · ENTRA_JWKS_URI · ENTRA_REDIRECT_URI |
CISO · Identity Lead | Config missing | Pending tenant supply | CISO · Founder Office | SEC-EV-ENTRA-001 | 2026-05-18 | Supply ENTRA_* env vars outside the platform; bind tenant. |
| Conditional Access + phishing-resistant MFA | CISO | In review | Policy drafted · acceptance pending | CISO + IT Ops | SEC-EV-MFA-002 | 2026-05-17 | Enable Conditional Access at tenant; capture sign-in log sample; retire staging static MFA from production path. |
| Role / permission mapping (RBAC + ABAC) ENTRA_REQUIRED_GROUP_ID |
Programme Manager · CISO | Ready · pending tenant | Mapping drafted · tenant binding pending | Programme Manager + CISO | SEC-EV-RBAC-004 | 2026-05-17 | Supply ENTRA_REQUIRED_GROUP_ID; reconcile with User & Role Permissions matrix. |
| Session issue · token handling · refresh / revocation | CISO · Platform | In review | Implementation drafted · evidence sample pending | CISO + Platform Lead | SEC-EV-SESSION-006 | 2026-05-16 | Capture session issue / refresh / revoke evidence against real Entra tenant. |
| Break-glass / privileged admin access ENTRA_BREAK_GLASS_OWNER |
CISO | Config missing | Owner not yet named in env | CISO + Founder Office | SEC-EV-BREAK-GLASS-007 | 2026-05-15 | Supply ENTRA_BREAK_GLASS_OWNER; confirm offline custody; drill dual-approver activation. |
| Staging-only auth quarantine | Platform Lead · CISO | Ready · pending tenant | Quarantine label live in staging | CISO + Platform Lead | SEC-EV-ENTRA-STAGING-QUARANTINE-001 | 2026-05-19 | Production build refuses the staging factor set; staging banner remains for internal rehearsal only. |
| Audit evidence · SIEM forwarding | CISO · SOC | In review | Pipeline configured · evidence sample pending | CISO + SOC Lead | SEC-EV-SIEM-008 | 2026-05-17 | Capture SIEM forwarding evidence against real tenant; verify failed / suspicious sign-in alerting. |
| Failed / suspicious sign-in evidence | CISO · SOC | In review | Counters drafted · sample needed | CISO + SOC Lead | SEC-EV-AUTH-ANOMALY-009 | 2026-05-16 | Capture end-to-end failed / suspicious sign-in evidence from Entra sign-in log; exercise in control test. |
| Security / compliance / go-live authority acceptance | CISO · Compliance · Founder Office | Blocked | Not yet captured | CISO + Compliance + Founder Office | SEC-EV-CUTOVER-ACCEPT-010 | 2026-05-15 | Counter-signed internal acceptance against real tenant config and staging quarantine evidence. |
Read-only fixture is exposed via /api/entra-oidc-readiness; presence-only environment posture via /api/auth/posture. No secrets are returned from any endpoint. Authoritative cutover gate is rendered in the
Final Production Launch Control Tower
and a summary card is mirrored in the
Completeness Command Centre.
Required production configuration · presence · ownership · custody · rotation · evidence
Secret values are never read, logged, persisted, or emitted by this register. The API at /api/production-config-readiness reports each declared environment variable as a presence boolean only; the value itself stays in the secret manager / runtime environment and never crosses the API or UI boundary. Required production items that lack presence, approval, custody, or rotation evidence keep the launch gate at HOLD · NO-GO.
| Configuration item | Group | Owner | Presence | Approval | Custody / rotation | Evidence ref | Last reviewed | Launch impact |
|---|---|---|---|---|---|---|---|---|
| Microsoft Entra OIDC tenant binding ENTRA_TENANT_ID |
Microsoft Entra OIDC | CISO · Identity Lead | Missing | Pending | Tenant id non-secret · OIDC app + signing material in offline custody | SEC-EV-ENTRA-001 | 2026-05-18 | Holds production identity cutover at HOLD · NO-GO |
| Microsoft Entra OIDC client + redirect URI ENTRA_CLIENT_ID · ENTRA_REDIRECT_URI |
Microsoft Entra OIDC | CISO · Identity Lead | Missing | Pending | Public client · authorisation-code + PKCE · no client secret required | SEC-EV-ENTRA-001 | 2026-05-18 | Holds production identity cutover at HOLD · NO-GO |
| Microsoft Entra OIDC issuer + JWKS endpoint ENTRA_ISSUER · ENTRA_JWKS_URI |
Microsoft Entra OIDC | CISO · Identity Lead | Missing | Pending | JWKS rotation handled by Entra · cache TTL refresh | SEC-EV-ENTRA-001 | 2026-05-18 | Without trusted issuer + JWKS, OIDC id_tokens cannot be verified |
| Microsoft Entra group gate (RBAC/ABAC) ENTRA_REQUIRED_GROUP_ID |
Microsoft Entra OIDC | Programme Manager · CISO | Missing | In review | Quarterly access review with User & Role Permissions matrix | SEC-EV-RBAC-004 | 2026-05-17 | RBAC cannot be enforced for production sign-in without a required group claim |
| Break-glass / privileged admin custody ENTRA_BREAK_GLASS_OWNER |
Microsoft Entra OIDC | CISO | Missing | Blocked | Offline credential custody · dual-approver activation drill quarterly | SEC-EV-BREAK-GLASS-007 | 2026-05-15 | Break-glass owner must be named before cutover |
| Session signing secret SESSION_SECRET |
Session / token signing | Platform Lead · CISO | Missing | Pending | Rotated every 90 days via secret manager · previous version retained one cycle | SEC-EV-SESSION-006 | 2026-05-16 | Staging in-memory secret does not count as production |
| Internal token / signed-URL signing key reference TOKEN_SIGNING_KEY_REF |
Session / token signing | Platform Lead · CISO | Missing | Pending | HSM-backed key manager · ref-only at runtime · rotation every 180 days with overlap | SEC-EV-SIGNING-KEY-011 | 2026-05-16 | Holds any signed export / signed-URL flow at HOLD · NO-GO |
| Evidence pack / controlled bundle export bucket EVIDENCE_EXPORT_BUCKET |
Evidence export storage | Platform Lead · CISO | Missing | Pending | KMS-encrypted · WORM/object-lock retention · signed-URL TTL ≤ 15 min | EVID-EXPORT-BUCKET-001 | 2026-05-17 | Local-disk staging export does not count as production |
| Evidence pack signed-URL signing secret reference EVIDENCE_EXPORT_SIGNING_SECRET_REF |
Evidence export storage | Platform Lead · CISO | Missing | Pending | Secret reference only · rotated every 90 days · tied to share-link audit trail | EVID-EXPORT-SIGN-002 | 2026-05-17 | External-use bundle release at HOLD · NO-GO until signing custody captured |
| SIEM forwarder endpoint SIEM_FORWARDER_ENDPOINT |
SIEM / audit forwarding | CISO · SOC | Missing | In review | Endpoint host recorded · forwarder credential rotated every 180 days | SEC-EV-SIEM-008 | 2026-05-17 | Audit + sign-in evidence cannot be relied upon without forwarding |
| SIEM forwarder credential reference SIEM_FORWARDER_TOKEN_REF |
SIEM / audit forwarding | CISO · SOC | Missing | Pending | Reference only · rotated every 180 days · outage runbook captured | SEC-EV-SIEM-008 | 2026-05-17 | Forwarder cannot be enabled in production without token reference |
| Observability / monitoring endpoint MONITORING_ENDPOINT |
Monitoring / alerting | Platform Lead · SRE | Missing | In review | Endpoint host recorded · ingest credential in secret manager | OPS-MONITOR-001 | 2026-05-17 | Production runtime cannot evidence health / latency / error budgets |
| On-call alert route reference ALERT_ON_CALL_ROUTE_REF |
Monitoring / alerting | Platform Lead · SRE | Missing | Pending | Route reference only · webhook secret in secret manager · rotated annually | OPS-MONITOR-002 | 2026-05-17 | Paging route must be captured and drilled before launch |
| WAF · security edge policy reference WAF_POLICY_REF |
WAF / security edge | Platform Lead · CISO | Missing | In review | Policy ref recorded · rule set reviewed monthly · OWASP top-10 + custom | SEC-EV-WAF-001 | 2026-05-17 | WAF rule set must be bound to production hostnames |
| TLS certificate / mTLS custody reference TLS_CERTIFICATE_REF |
WAF / security edge | Platform Lead | Missing | Pending | Certificate body + private key not exposed · ACM/Key Vault · auto-renew monitored | SEC-EV-TLS-002 | 2026-05-17 | Certificate custody and renewal monitor required before cutover |
| Transactional email / notification provider NOTIFICATION_PROVIDER_REF |
Email / notification | Platform Lead · Comms | Missing | Pending | API key in secret manager · rotated every 180 days · sender domain SPF/DKIM/DMARC | COMMS-PROV-001 | 2026-05-16 | Stakeholder-room notifications cannot land in production |
| Sender domain authentication (SPF · DKIM · DMARC) NOTIFICATION_SENDER_DOMAIN |
Email / notification | Platform Lead · Comms | Missing | In review | DNS records reviewed quarterly · DMARC at quarantine pending acceptance to reject | COMMS-PROV-002 | 2026-05-16 | External-use bundle release at HOLD · NO-GO until domain auth captured |
| Production backup vault (immutable / WORM) BACKUP_VAULT_REF |
Backup / DR | Platform Lead · SRE | Missing | Pending | Credential in secret manager · WORM retention · cross-region replica | DR-VAULT-001 | 2026-05-17 | Backup vault and restore drill required before launch |
| Disaster recovery restore drill evidence DR_RESTORE_DRILL_REF |
Backup / DR | Platform Lead · SRE · COO | Missing | In review | Drill cadence quarterly · evidence pack per drill | DR-DRILL-002 | 2026-05-16 | At least one production-bound restore drill required before launch |
| Regulatory source manifest (rule text · evidence trail) REGULATORY_SOURCE_MANIFEST_REF |
Regulatory data / source | Regulatory Affairs · Legal | Missing | In review | Reviewed monthly with Regulatory Change horizon · source provenance tracked | REG-SOURCE-001 | 2026-05-15 | Source manifest must be bound and reviewed before launch |
| Partner data feed binding (custodian / paying agent / partner routes) PARTNER_DATA_FEED_REF |
Regulatory data / source | Operations · Partner Risk | Missing | Pending | Reference only · partner credentials in secret manager · rotated per partner SLA | PARTNER-FEED-001 | 2026-05-15 | Partner-routed evidence at HOLD · NO-GO without feed binding |
| Production launch authority acceptance custody LAUNCH_AUTHORITY_ACCEPTANCE_REF |
Production launch authority | Founder Office · CISO · Compliance · CFO | Missing | Blocked | Acceptance language version-controlled · renewed at every material readiness change | LAUNCH-AUTH-001 | 2026-05-15 | Final internal acceptance is the last gate before any cutover (not external authorisation) |
| Staging-only auth quarantine label STAGING_QUARANTINE_LABEL |
Production launch authority | Platform Lead · CISO | Not applicable (staging only) | Approved · internal | Static label held in staging only · refused by any production code path | SEC-EV-ENTRA-STAGING-QUARANTINE-001 | 2026-05-19 | Not applicable to production runtime — recorded so register stays complete |
Read-only fixture is exposed via /api/production-config-readiness; no secret values cross the API or UI boundary. Cross-references the
Microsoft Entra OIDC Production Cutover Readiness
layer (also at /api/entra-oidc-readiness) and the
/api/auth/posture endpoint. Authoritative cutover gate is rendered in the
Final Production Launch Control Tower
and a summary card is mirrored in the
Completeness Command Centre.
Ingress · edge · mTLS · partner-route controls · presence · approval · route exposure · evidence
/api/production-ingress-route-readiness, in the fixture, or in any commit. Only ownership, declared (non-secret) env-key NAMES, presence flags, approval state, route exposure state, evidence references, and unlock criteria are recorded. The staging hostname does not count as a production endpoint. Internal ingress / partner-route readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
Production hostnames, DNS zones, WAF rule bodies, mTLS certificate bodies / private keys, partner API endpoints, partner credentials, tokens, and client secrets are never exposed in this register, the API, the fixture, or any commit. The API at /api/production-ingress-route-readiness reports only ownership, declared (non-secret) env-key NAMES, per-key presence booleans, approval state, route exposure state, evidence references, and unlock criteria. Until DNS ownership, TLS / WAF, API gateway, mTLS / partner controls, rate-limit / abuse controls, route-level monitoring + audit forwarding, rollback / failover, and the internal external-route go-live authority are present and approved, every external-facing route stays externally blocked at WAF / API gateway / DNS and launch remains HOLD · NO-GO.
| Control | Group | Owner | State | Approval | Route exposure | Evidence | Last reviewed | Launch impact |
|---|---|---|---|---|---|---|---|---|
| Production hostname registration & ownership proof PRODUCTION_HOSTNAME_OWNERSHIP_REF | Hostname & DNS | Platform Lead · CISO | Missing | Pending | External-blocked | ING-DNS-001 | 2026-05-19 | Holds production launch at HOLD · NO-GO until ownership proven |
| Production DNS zone custody & DNSSEC / CAA posture PRODUCTION_DNS_ZONE_REF | Hostname & DNS | Platform Lead · SRE | Missing | In review | External-blocked | ING-DNS-002 | 2026-05-18 | DNS zone custody must be captured before TLS / WAF binding |
| Production TLS certificate issuance custody PRODUCTION_TLS_CERT_CUSTODY_REF | TLS lifecycle | Platform Lead · CISO | Missing | Pending | External-blocked | ING-TLS-001 | 2026-05-18 | TLS custody required before any hostname can be served |
| TLS certificate renewal & expiry monitor TLS_RENEWAL_MONITOR_REF | TLS lifecycle | Platform Lead · SRE | Missing | Pending | External-blocked | ING-TLS-002 | 2026-05-18 | Without monitor, cert expiry would silently break ingress |
| WAF policy bound to production hostnames PRODUCTION_WAF_BINDING_REF | WAF · security edge | Platform Lead · CISO | Missing | In review | External-blocked | ING-WAF-001 | 2026-05-19 | WAF must be bound to production hostnames before external traffic |
| Bot / credential-stuffing / abuse mitigation BOT_ABUSE_RULESET_REF | WAF · security edge | Platform Lead · CISO | In review | In review | External-blocked | ING-WAF-002 | 2026-05-17 | Sign-in and partner callback routes must resist credential stuffing |
| CDN / edge routing binding PRODUCTION_CDN_BINDING_REF | CDN · edge routing | Platform Lead · SRE | Missing | Pending | External-blocked | ING-CDN-001 | 2026-05-18 | Origins must be shielded behind CDN with cache + signed-URL hygiene |
| API gateway / ingress controller binding PRODUCTION_API_GATEWAY_REF | API gateway / ingress | Platform Lead | Missing | Pending | External-blocked | ING-GW-001 | 2026-05-18 | All production routes must traverse the API gateway / ingress |
| Route-level authentication via Entra OIDC PRODUCTION_API_AUTH_BINDING_REF | API gateway / ingress | CISO · Identity Lead | Blocked | Blocked | External-blocked | ING-GW-002 | 2026-05-18 | Routes cannot be authenticated until Entra OIDC tenant supplied |
| mTLS / partner certificate issuance & custody PARTNER_MTLS_CUSTODY_REF | mTLS · partner custody | Platform Lead · CISO · Partner Risk | Missing | Pending | Restricted-review | ING-MTLS-001 | 2026-05-17 | No partner route may go live without mTLS custody + drill |
| mTLS / partner certificate rotation & revocation drill PARTNER_MTLS_ROTATION_REF | mTLS · partner custody | Platform Lead · Partner Risk | Missing | Pending | Restricted-review | ING-MTLS-002 | 2026-05-17 | Rotation + revocation must be drilled per partner |
| Partner-route allowlist & contract scope PARTNER_ROUTE_ALLOWLIST_REF | Partner allowlist | Operations · Partner Risk · Legal | Restricted review | In review | Restricted-review | ING-PART-001 | 2026-05-15 | Partner routes need contract scope + counsel countersign |
| Partner callback / webhook signature & replay protection PARTNER_CALLBACK_SIGNATURE_POLICY_REF | Partner callback | Platform Lead · Partner Risk | Missing | Pending | External-blocked | ING-PART-002 | 2026-05-16 | Inbound callbacks must enforce signature + replay protection |
| Rate-limit policy & burst caps PRODUCTION_RATELIMIT_POLICY_REF | Rate limit · abuse | Platform Lead · SRE | In review | In review | External-blocked | ING-RATE-001 | 2026-05-17 | Required to resist credential-stuffing & abuse |
| Abuse-event runbook & containment ABUSE_EVENT_RUNBOOK_REF | Rate limit · abuse | Platform Lead · CISO · SOC | Missing | Pending | External-blocked | ING-RATE-002 | 2026-05-15 | Abuse events need containment + escalation path |
| Route-level monitoring & telemetry forwarding ROUTE_MONITORING_BINDING_REF | Route monitoring | Platform Lead · SRE | In review | In review | External-blocked | ING-MON-001 | 2026-05-18 | Per-route telemetry must reach monitoring + SIEM stack |
| Route-level audit log forwarding ROUTE_AUDIT_FORWARDING_REF | Route monitoring | CISO · SOC | Missing | Pending | External-blocked | ING-MON-002 | 2026-05-17 | Sign-in, partner-route, admin events must be SIEM-forwarded |
| Production rollback / failover route drill ROLLBACK_FAILOVER_DRILL_REF | Rollback · failover | Platform Lead · SRE · COO | Missing | In review | External-blocked | ING-ROLL-001 | 2026-05-16 | External go-live needs a drilled rollback + failover path |
| External-route go-live authority custody EXTERNAL_ROUTE_AUTHORITY_REF | External-route authority | Founder Office · CISO · Compliance · CFO | Blocked | Blocked | External-blocked | ING-AUTH-001 | 2026-05-15 | Final internal acceptance — not external endpoint authorisation |
| Staging URL quarantine label (no env key — staging-only) | External-route authority | Platform Lead · CISO | Not applicable (staging only) | Approved · internal | Internal-only | ING-STAGING-QUARANTINE-001 | 2026-05-19 | Staging URL is never promoted to production endpoint |
Read-only fixture exposed via /api/production-ingress-route-readiness; presence flags + non-secret env-key NAMES only. Cross-references the
Production Environment Variable & Secret Readiness Register,
the Microsoft Entra OIDC Production Cutover Readiness layer,
/api/production-config-readiness, /api/entra-oidc-readiness, and /api/auth/posture.
Mirrored summary in the
Integration · API · Data Exchange Centre,
the Final Production Launch Control Tower,
the Production Monitoring Centre,
and the Completeness Command Centre.
Internal ingress / partner-route readiness posture only — not external endpoint authorisation, not regulator approval, not external-use authorisation. The staging hostname does not count as a production endpoint.
Secret & key custody · custodian · rotation cadence · last rotation · next rotation due · recovery drill · evidence
/api/secret-rotation-key-custody, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, evidence references, and unlock criteria are recorded. Staging or demo credentials do not count as production secret custody evidence. Internal key-custody readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
Secret values, certificate private keys, encryption keys, passwords, client secrets, tokens, connection strings, backup keys, signing material, mTLS private keys, break-glass credentials, and recovery codes are never exposed in this register, the API, the fixture, or any commit. The API at /api/secret-rotation-key-custody reports only ownership, custodian, custody model, declared (non-secret) reference NAMES, per-key presence booleans, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, evidence references, and unlock criteria. Until session signing, JWT/OIDC signing, Entra OIDC app credential, evidence export storage credential, SIEM forwarding token, monitoring webhook secret, TLS private-key custody, mTLS partner-key custody, backup encryption key, data-store encryption key, break-glass credential, CI/CD deploy token, and regulatory data API credential custody are captured with rotation cadence + last-rotation evidence + next rotation due + recovery drill evidence, launch remains HOLD · NO-GO and external-use bundle release is blocked.
| Item | Group | Owner / custodian | Custody model | State | Approval | Rotation cadence | Last rotation | Next rotation due | Recovery drill | Evidence | Launch impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Session signing secret SESSION_SIGNING_SECRET | Session · token signing | CISO · Identity Lead / CISO · Platform Lead | Secret-manager-backed | Missing | Pending | 90 days | — | — | Required · not drilled | SEC-EV-ROT-001 | Holds HOLD · NO-GO until rotation + recovery drill captured |
| JWT / OIDC signing key JWT_SIGNING_KEY_REF | Session · token signing | CISO · Identity Lead / Platform Lead | KMS-backed | Missing | Pending | 180 days | — | — | Required · not drilled | SEC-EV-ROT-002 | Holds external-facing OIDC trust at HOLD · NO-GO |
| Entra OIDC app secret / cert credential ENTRA_APP_CREDENTIAL_CUSTODY_REF | Entra OIDC credential | CISO · Identity Lead / Identity Lead · Platform Lead | Secret-manager-backed | Missing | Pending | 90 days | — | — | Required · not drilled | SEC-EV-ROT-101 | Holds production identity cutover at HOLD · NO-GO |
| Entra OIDC federated cert credential ENTRA_FEDERATED_CERT_CUSTODY_REF | Entra OIDC credential | CISO · Identity Lead / Identity Lead · Platform Lead | KMS-backed | Not applicable | Pending | 365 days | — | — | Optional | SEC-EV-ROT-102 | Optional path; only applies if federated cert credential selected |
| Evidence export storage credential EVIDENCE_EXPORT_STORAGE_KEY_REF | Evidence export storage | Head of Evidence · CISO / Platform Lead | Secret-manager-backed | Missing | Pending | 90 days | — | — | Required · quarterly restore drill | SEC-EV-ROT-201 | Holds external-use bundle release at HOLD · NO-GO |
| SIEM / audit forwarding token SIEM_AUDIT_FORWARDING_TOKEN_REF | SIEM forwarding | CISO · SOC Lead / Platform Lead · SOC | Secret-manager-backed | Missing | Pending | 90 days | — | — | Required · annual restore drill | SEC-EV-ROT-301 | Audit forwarding must be live before any external-use |
| Monitoring / alerting webhook secret MONITORING_ALERTING_WEBHOOK_SECRET_REF | Monitoring · alerting | SRE Lead · CISO / Platform Lead | Secret-manager-backed | Missing | Pending | 180 days | — | — | Required · paging drill | SEC-EV-ROT-401 | Alerting must be live before external-use bundle release |
| Production TLS private-key custody PRODUCTION_TLS_PRIVATE_KEY_CUSTODY_REF | TLS custody | Platform Lead · CISO / Platform Lead | HSM-backed | Missing | Pending | 90 days | — | — | Required · annual revocation drill | SEC-EV-ROT-501 | No production hostname may be served without TLS private-key custody |
| mTLS partner private-key custody PARTNER_MTLS_PRIVATE_KEY_CUSTODY_REF | mTLS partner custody | Platform Lead · CISO · Partner Risk / Platform Lead | HSM-backed | Missing | Pending | 180 days | — | — | Required · per-partner revocation drill | SEC-EV-ROT-601 | No partner route may go live without mTLS partner key custody |
| Backup vault encryption key BACKUP_ENCRYPTION_KEY_CUSTODY_REF | Backup · DR | Platform Lead · CISO · COO / Platform Lead · COO | HSM-backed | Missing | Pending | 365 days | — | — | Required · quarterly restore drill | SEC-EV-ROT-701 | External-use requires evidenced backup / restore drill |
| Data-store encryption key DATASTORE_ENCRYPTION_KEY_CUSTODY_REF | Data-store custody | Platform Lead · CISO / Platform Lead | KMS-backed | Missing | Pending | 365 days | — | — | Required · annual rotation drill | SEC-EV-ROT-801 | External-use requires evidenced data-store encryption custody |
| Break-glass credential custody BREAK_GLASS_CREDENTIAL_CUSTODY_REF | Break-glass | Founder Office · CISO · Board Secretariat / Board Secretariat · CISO (dual control) | Offline custody | Missing | Pending | 365 days (envelope refresh) | — | — | Required · quarterly retrieval drill | SEC-EV-ROT-901 | External-use requires evidenced break-glass posture |
| CI/CD deploy token custody CI_CD_DEPLOY_TOKEN_CUSTODY_REF | CI/CD pipeline | Platform Lead · CISO / Platform Lead | Secret-manager-backed | Missing | Pending | 90 days | — | — | Required · per rotation | SEC-EV-ROT-A01 | External-use requires evidenced deploy token custody |
| Regulatory data feed / partner API key REGULATORY_DATA_API_KEY_CUSTODY_REF | Regulatory data feed | Regulatory Affairs · Platform Lead / Platform Lead · Partner Risk | Secret-manager-backed | Missing | Pending | 180 days | — | — | Required · per rotation | SEC-EV-ROT-B01 | External-use requires evidenced partner API key custody |
| Staging founder MFA factor quarantine (no production reference — staging-only) | Session · token signing | Platform Lead · CISO / Platform Lead · CISO | Not applicable | Not applicable (staging only) | Approved · internal | Quarantined | — | — | Not applicable | SEC-EV-ROT-STAGING-001 | Staging factor is never promoted to production secret custody |
Read-only fixture exposed via /api/secret-rotation-key-custody; reference NAMES, presence flags, custody owner, custodian, custody model, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, and evidence references only. Cross-references the
Production Environment Variable & Secret Readiness Register,
the Production Hostname, DNS, WAF & Partner-Route Readiness Register,
the Microsoft Entra OIDC Production Cutover Readiness layer,
/api/production-config-readiness, /api/production-ingress-route-readiness, /api/entra-oidc-readiness, and /api/auth/posture.
Mirrored summary in the
Final Production Launch Control Tower,
the Operational Runbooks & Day-2 Support Centre,
the Data Governance & Retention Centre,
and the Completeness Command Centre.
Internal key-custody readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, and not external-use authorisation. Staging or demo credentials do not count as production secret custody evidence.
Backup scope · restore drills · RPO/RTO · retention · DR · recovery authority
/api/backup-restore-recovery-evidence, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, backup cadence, last-backup evidence date, last restore drill date, RPO/RTO targets, measured RPO/RTO, retention / legal-hold posture, evidence references, and unlock criteria are recorded. Staging or demo backups do not count as production recovery evidence. Internal backup/recovery readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
| Control | Group | Owner / custodian | Custody model | State | Approval | Backup cadence | Last backup | Last restore drill | RPO target | RTO target | Retention / legal hold | Evidence | Launch impact |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Database backup schedule & automation BACKUP_CADENCE_DATABASE_REF | Backup schedule | Platform Lead / Platform Lead · CISO | Vault-backed | Missing | Pending | Continuous PITR + daily full | — | — | 15 min | 4 hr | Per jurisdictional retention matrix | BKP-EV-SCH-001 | Holds HOLD · NO-GO until cadence + last backup + restore drill + RPO/RTO captured |
| Production backup scope inventory BACKUP_SCOPE_INVENTORY_REF | Scope inventory | Platform Lead / Platform Lead · Head of Evidence | n/a — inventory | Missing | Pending | Reviewed quarterly | — | — | n/a | n/a | Lifetime of production system | BKP-EV-SCP-001 | Holds HOLD · NO-GO until backup scope approved + cross-linked |
| Backup encryption key custody link BACKUP_ENCRYPTION_KEY_REF | Encryption / custody | CISO / CISO · Platform Lead | KMS-backed | Missing | Pending | Per Secret Rotation Loop | — | — | n/a | n/a | Per backup retention policy | BKP-EV-ENC-001 | Holds HOLD · NO-GO until KMS/HSM-backed backup key custody + rotation + drill captured |
| Database restore drill evidence RESTORE_DRILL_DATABASE_REF | Restore drill | Platform Lead / Platform Lead · CISO | Vault-backed | Recovery untested | Pending | Quarterly restore drill | — | — | 15 min | 4 hr | Per database backup retention | BKP-EV-RST-001 | Holds HOLD · NO-GO until production-grade restore drill captured with measured RPO/RTO |
| Database RPO · RTO targets & measurement RPO_RTO_DATABASE_REF | RPO/RTO targets | Platform Lead / Platform Lead · CISO | n/a — target | RPO/RTO unverified | Pending | Measured every drill | — | — | 15 min | 4 hr | n/a | BKP-EV-RPO-001 | Holds HOLD · NO-GO until measured RPO/RTO inside target captured |
| Immutable backup · retention lock · WORM IMMUTABLE_RETENTION_LOCK_REF | Retention lock | CISO / CISO · Platform Lead | Immutable object storage | Retention unverified | Pending | Lock state verified quarterly | — | — | n/a | n/a | Per jurisdictional retention + legal-hold matrix | BKP-EV-IMM-001 | Holds HOLD · NO-GO until WORM / object-lock retention evidenced end-to-end |
| Evidence pack & controlled-bundle recovery EVIDENCE_EXPORT_RECOVERY_REF | Evidence export | Head of Evidence · CISO / Platform Lead | Immutable object storage | Missing | Pending | Per-pack on create + daily snapshot | — | — | 1 hr | 8 hr | Min 7 years (legal hold) | BKP-EV-EXP-001 | Holds external-use bundle release at HOLD · NO-GO until evidence pack backup + restore + retention captured |
| Audit log · SIEM backup & recovery AUDIT_LOG_RECOVERY_REF | Audit log recovery | CISO / CISO · SRE Lead | Vault-backed | Missing | Pending | Continuous forwarder + daily snapshot | — | — | 5 min | 2 hr | Per regulator-required audit retention | BKP-EV-AUD-001 | Holds HOLD · NO-GO until audit log backup + retention + restore drill captured |
| Database · data-store point-in-time recovery DATASTORE_PITR_REF | Data-store recovery | Platform Lead / Platform Lead | Vault-backed | Missing | Pending | Continuous PITR window | — | — | 15 min | 4 hr | Per data class retention | BKP-EV-PITR-001 | Holds HOLD · NO-GO until PITR + restore drill + measured RPO/RTO |
| Configuration · runtime · IaC recovery CONFIGURATION_IAC_RECOVERY_REF | Config / IaC recovery | Platform Lead / Platform Lead | Vault-backed | Missing | Pending | Per IaC commit + daily snapshot | — | — | 1 hr | 4 hr | Source control retention | BKP-EV-CFG-001 | Holds HOLD · NO-GO until IaC / runtime image rebuild evidenced |
| Incident recovery runbook · per data class INCIDENT_RECOVERY_RUNBOOK_REF | Incident runbook | SRE Lead · CISO / SRE Lead | n/a — runbook | Missing | Pending | Reviewed quarterly | — | — | n/a | n/a | Lifetime of production system | BKP-EV-RUN-001 | Holds HOLD · NO-GO until incident recovery runbook approved + drilled |
| DR · region-failover exercise DR_FAILOVER_EXERCISE_REF | DR / failover | CISO / Platform Lead · SRE Lead | Vault-backed | Recovery untested | Pending | Annual DR + semi-annual tabletop | — | — | 1 hr | 8 hr | Lifetime of production system | BKP-EV-DR-001 | Holds HOLD · NO-GO until full DR / region-failover exercise executed |
| Backup monitoring · alerting · escalation BACKUP_MONITORING_REF | Monitoring / alerting | SRE Lead / SRE Lead · Platform Lead | n/a — monitoring | Missing | Pending | Continuous monitoring + on-failure paging | — | — | n/a | n/a | Per audit retention | BKP-EV-MON-001 | Holds HOLD · NO-GO until backup monitoring + paging drill captured |
| Retention period · legal hold alignment RETENTION_LEGAL_HOLD_REF | Retention / legal hold | Head of Evidence · CISO / Head of Evidence | n/a — alignment | Retention unverified | Pending | Reviewed quarterly + on jurisdiction change | — | — | n/a | n/a | Per jurisdictional retention + legal-hold matrix | BKP-EV-RET-001 | Holds HOLD · NO-GO until retention aligns end-to-end with regulator-required retention |
| Recovery approval · go-live authority RECOVERY_AUTHORITY_REF | Recovery authority | Founder Office · CISO / Founder Office | n/a — authority | Missing | Pending | Reviewed on each cutover decision | — | — | n/a | n/a | Lifetime of production system | BKP-EV-AUT-001 | Holds HOLD · NO-GO until Founder Office + CISO + Platform Lead counter-sign captured |
Read-only fixture exposed via /api/backup-restore-recovery-evidence; reference NAMES, presence flags, owner, custodian, custody model, approval state, backup cadence, last-backup date, last restore drill date, RPO/RTO targets, measured RPO/RTO, retention / legal-hold posture, and evidence references only. Cross-references
/api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, and /api/jurisdictional-permissions-matrix.
Mirrored summary in the
Final Production Launch Control Tower,
the Operational Runbooks & Day-2 Support Centre,
the Data Governance & Retention Centre,
the Production Monitoring Centre,
and the Completeness Command Centre.
Internal backup/recovery readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, and not external-use authorisation. Staging or demo backups do not count as production recovery evidence.
Health checks · SLOs · alert routing · SIEM · incident command · PIR · escalation · notification triggers
/api/observability-slo-incident-evidence, in the fixture, or in any commit. Only ownership, declared (non-secret) reference NAMES, presence flags, approval state, SLO targets, measured values where captured, alert route names, last alert-test dates, last incident-drill dates, log retention evidence references, linked runbook / escalation paths, notification trigger statuses, evidence references, and unlock criteria are recorded. Staging or demo monitoring does not count as production observability evidence. Internal observability / incident readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, not incident notification submission, and not external-use authorisation.
| Control | Group | Owner | State | Approval | SLO target | Measured value | Alert route | Last route test | Last incident drill | Runbook | Escalation path | Notify trigger | Evidence | Launch impact |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Production liveness health check OBS_HEALTH_LIVENESS_REF | Health · synthetic | Platform Lead | Missing | Pending | Probe response < 2s · 99%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-LIVENESS | ESC-INC-TIER1 | Pending | OBS-EV-HC-001 | Holds HOLD · NO-GO until probe bound + SLO measured + route tested |
| Production readiness health check OBS_HEALTH_READINESS_REF | Health · synthetic | Platform Lead | Missing | Pending | Probe response < 5s · 99%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-READINESS | ESC-INC-TIER1 | Pending | OBS-EV-HC-002 | Holds HOLD · NO-GO until readiness probe + SLO measured + route tested |
| End-to-end synthetic transaction probe OBS_SYNTHETIC_E2E_REF | Health · synthetic | Platform Lead | Missing | Pending | Critical path ≥ 99.5%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-E2E | ESC-INC-TIER1 | Pending | OBS-EV-HC-003 | Holds HOLD · NO-GO until E2E probe bound + measured |
| Uptime SLO target & measurement OBS_SLO_UPTIME_REF | SLO · targets | Platform Lead | SLO unverified | Pending | Uptime ≥ 99.9%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-SLO-UPTIME | ESC-INC-TIER1 | Pending | OBS-EV-SLO-001 | Holds HOLD · NO-GO until measured uptime within target + burn-rate alert bound |
| Latency SLO target & measurement OBS_SLO_LATENCY_REF | SLO · targets | Platform Lead | SLO unverified | Pending | p95 < 1.5s · p99 < 3s | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-SLO-LATENCY | ESC-INC-TIER1 | Pending | OBS-EV-SLO-002 | Holds HOLD · NO-GO until measured p95/p99 within target |
| Error-rate SLO target & measurement OBS_SLO_ERROR_REF | SLO · targets | Platform Lead | SLO unverified | Pending | 5xx ≤ 0.1%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-SLO-ERROR | ESC-INC-TIER1 | Pending | OBS-EV-SLO-003 | Holds HOLD · NO-GO until measured 5xx within target |
| Entra OIDC dependency monitor OBS_DEP_ENTRA_REF | Dependency monitor | CISO | Missing | Pending | Sign-in ≥ 99.9% / p95 < 2s | — | OBS-ROUTE-SECURITY | — | — | RB-INC-ENTRA | ESC-INC-TIER1 | Pending | OBS-EV-DEP-001 | Holds HOLD · NO-GO until Entra availability + sign-in failure detection captured |
| Production database dependency monitor OBS_DEP_DB_REF | Dependency monitor | Platform Lead | Missing | Pending | DB ≥ 99.95% · query p95 < 500ms | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-DB | ESC-INC-TIER1 | Pending | OBS-EV-DEP-002 | Holds HOLD · NO-GO until DB availability + replication alert captured |
| Partner route dependency monitor OBS_DEP_PARTNER_REF | Dependency monitor | Platform Lead | Missing | Pending | Partner-route ≥ 99.5%/30d | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-PARTNER | ESC-INC-TIER1 | Pending | OBS-EV-DEP-003 | Holds HOLD · NO-GO until partner heartbeat + reachability captured |
| Primary alert routing & on-call rota OBS_ALERT_PRIMARY_REF | Alert routing | CISO | Alert route untested | Pending | Ack ≤ 15m · 24/7 | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-ON-CALL | ESC-INC-TIER1 | Pending | OBS-EV-ALERT-001 | Holds HOLD · NO-GO until paging route + rota tested end-to-end |
| Security alert routing OBS_ALERT_SECURITY_REF | Alert routing | CISO | Alert route untested | Pending | Sec event ack ≤ 15m · 24/7 | — | OBS-ROUTE-SECURITY | — | — | RB-INC-SEC | ESC-INC-SEC | Pending | OBS-EV-ALERT-002 | Holds HOLD · NO-GO until security paging route tested + counter-signed |
| Incident command room & role allocation OBS_IC_ROOM_REF | Incident command | CISO | Missing | Pending | IC + scribe + comms ≤ 15m | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-COMMAND | ESC-INC-TIER1 | Pending | OBS-EV-IC-001 | Holds HOLD · NO-GO until IC room + roles + severity matrix counter-signed |
| Per-severity incident runbook OBS_IC_RUNBOOK_REF | Incident command | CISO | In review | In review | SEV-1/2/3/4 coverage | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-SEV | ESC-INC-TIER1 | Pending | OBS-EV-IC-002 | Holds HOLD · NO-GO until per-severity runbook approved + drilled |
| Audit log · SIEM forwarder OBS_SIEM_FORWARDER_REF | Audit log · SIEM | CISO | Logging unverified | Pending | Forwarder success ≥ 99.95%/30d | — | OBS-ROUTE-SECURITY | — | — | RB-INC-SIEM | ESC-INC-SEC | Pending | OBS-EV-LOG-001 | Holds HOLD · NO-GO until SIEM forwarder + retention + failure alert tested |
| Audit log retention & immutability OBS_LOG_RETENTION_REF | Audit log · SIEM | CISO | Logging unverified | Pending | Per jurisdictional matrix · lock | — | OBS-ROUTE-SECURITY | — | — | RB-INC-LOG-RETENTION | ESC-INC-SEC | Pending | OBS-EV-LOG-002 | Holds HOLD · NO-GO until retention + immutability lock + legal-hold evidenced |
| Sign-in anomaly detection OBS_SEC_DETECT_SIGNIN_REF | Security detection | CISO | Missing | Pending | Detect ≤ 5m · page ≤ 15m | — | OBS-ROUTE-SECURITY | — | — | RB-INC-SIGNIN | ESC-INC-SEC | Pending | OBS-EV-SEC-001 | Holds HOLD · NO-GO until sign-in anomaly rule + route + runbook captured |
| Break-glass usage detection OBS_SEC_DETECT_BREAK_GLASS_REF | Security detection | CISO | Missing | Pending | Detect ≤ 1m · page CISO + Founder | — | OBS-ROUTE-SECURITY | — | — | RB-INC-BREAK-GLASS | ESC-INC-SEC | Pending | OBS-EV-SEC-002 | Holds HOLD · NO-GO until break-glass detection + paging + runbook captured |
| Evidence export · bundle anomaly monitor OBS_EVIDENCE_EXPORT_MON_REF | Evidence export monitor | Head of Evidence | Missing | Pending | Anomaly ≤ 5m | — | OBS-ROUTE-SECURITY | — | — | RB-INC-EXPORT | ESC-INC-SEC | Pending | OBS-EV-EXP-001 | Holds HOLD · NO-GO until export / share-link anomaly monitor captured |
| Regulator · board · stakeholder notification triggers OBS_NOTIFY_MATRIX_REF | Notification triggers | Founder Office | In review | In review | SEV-1/2/3/4 → recipients | — | OBS-ROUTE-EXEC | — | — | RB-INC-NOTIFY | ESC-INC-EXEC | Pending | OBS-EV-NOTIFY-001 | Holds HOLD · NO-GO until trigger matrix approved + drill-tested; nothing here auto-files a notification |
| Post-incident review · PIR evidence OBS_PIR_REF | Post-incident review | CISO | PIR untested | Pending | PIR ≤ 10 business days | — | OBS-ROUTE-EXEC | — | — | RB-INC-PIR | ESC-INC-EXEC | Pending | OBS-EV-PIR-001 | Holds HOLD · NO-GO until PIR rehearsal evidence + corrective action captured |
| Escalation SLA · cross-tier hand-off OBS_ESCALATION_SLA_REF | Escalation SLA | CISO | In review | In review | Detect 5m / ack 15m / engage 30m / escalate 60m | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-ESCALATION | ESC-INC-TIER1 | Pending | OBS-EV-ESC-001 | Holds HOLD · NO-GO until escalation SLA approved + drilled + counter-signed |
| Customer · stakeholder comms template OBS_COMMS_TEMPLATE_REF | Comms template | Founder Office | Missing | Pending | Per SEV + channel · pre-approved | — | OBS-ROUTE-EXEC | — | — | RB-INC-COMMS | ESC-INC-EXEC | Pending | OBS-EV-COMMS-001 | Holds HOLD · NO-GO until comms templates approved + rehearsed; nothing here auto-sends |
| Chaos · failure injection drill OBS_CHAOS_DRILL_REF | Chaos drill | Platform Lead | PIR untested | Pending | Quarterly chaos exercise | — | OBS-ROUTE-PRIMARY | — | — | RB-INC-CHAOS | ESC-INC-TIER1 | n/a | OBS-EV-CHAOS-001 | Holds HOLD · NO-GO until chaos drill performed + counter-signed |
| Maintenance window · change freeze OBS_MAINT_FREEZE_REF | Maintenance window | Platform Lead | In review | In review | Maintenance window + freeze declared | — | OBS-ROUTE-EXEC | — | — | RB-INC-MAINTENANCE | ESC-INC-TIER1 | Pending | OBS-EV-MAINT-001 | Holds HOLD · NO-GO until maintenance window + change freeze approved + counter-signed |
| Incident authority · go-live acceptance OBS_INC_AUTHORITY_REF | Incident authority | Founder Office | Missing | Pending | Authority + counter-sign + go/no-go | — | OBS-ROUTE-EXEC | — | — | RB-INC-AUTHORITY | ESC-INC-EXEC | Pending | OBS-EV-AUTH-001 | Holds HOLD · NO-GO until incident authority counter-sign captured |
Read-only fixture exposed via /api/observability-slo-incident-evidence; reference NAMES, presence flags, owner, approval state, SLO targets, measured values, alert route names, last alert-test dates, last incident-drill dates, log retention evidence references, linked runbook / escalation paths, notification trigger statuses, and evidence references only. Cross-references
/api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/entra-oidc-readiness, and /api/jurisdictional-permissions-matrix.
Mirrored summary in the
Final Production Launch Control Tower,
the Operational Runbooks & Day-2 Support Centre,
the Production Monitoring & Incident Command Centre,
the Regulatory Notification & Board Escalation Centre,
and the Completeness Command Centre.
Internal observability / incident readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, not incident notification submission, and not external-use authorisation. Staging or demo monitoring does not count as production observability evidence.
Eight zero-trust pillars × readiness & evidence
| Pillar | What it requires | Readiness | Evidence output | Owner |
|---|---|---|---|---|
| Identity | Every principal authenticated via Entra OIDC · no anonymous server-to-server calls | Entra cutover pending | Auth event log · Entra sign-in log (production target) | Identity Lead |
| Device / Session | Device posture signal · session age cap · re-auth on high-risk actions | Pilot in admin cohort | Conditional access decisions · session re-auth log | IT Ops · CISO |
| Network / API | Edge WAF · per-route auth · per-route rate-limit · mTLS service-to-service | WAF rule pack drafted | WAF event sample · rate-limit rejections · mTLS handshake log | SRE Lead · CISO |
| Data Classification | Every dataset tagged (Restricted/MNPI · Personal · Internal · Public) · ABAC enforced on access | Linked to Data Governance Centre | Data inventory tags · access-decision audit log | Data Governance Lead |
| Least Privilege | Default deny · JIT elevation · zero standing admin | JIT live in pilot | Standing-privilege snapshot · JIT elevation log | CISO |
| Continuous Verification | Re-evaluate auth/authz on every sensitive action · revoke on signal change | Token-level revocation live | Continuous-verification event sample | Identity Lead |
| Logging & Telemetry | Auth · admin · evidence access · room access · API · WAF all sent to SIEM | Pipeline live | SIEM index · retention attestation | CISO · SRE Lead |
| Response & Recovery | Runbook · paging · containment · revocation · regulator notification trigger | Runbook live | Incident timeline · revocation evidence · regulator-notify decision | CISO |
Privileged roles · approvers · expiry · cadence · last review
| Privileged role | Holder count | Approver | Expiry / token TTL | Review cadence | Last review | Stale access? | Revocation evidence |
|---|---|---|---|---|---|---|---|
| Founder root | 1 | Board (dual) | Permanent · MFA + re-auth on every privileged action | Monthly attestation | 2026-05-15 | No | SEC-EV-AXR-008 § FR |
| System admin (JIT) | 2 | CISO + COO | 2h JIT · recorded session · auto-revoke | Quarterly | 2026-05-15 | No | SEC-EV-AXR-008 § SA |
| Evidence publisher (21 packs) | 4 | Head of Evidence | 30 d rotation · MFA | Quarterly | 2026-05-14 | No | SEC-EV-AXR-008 § EP |
| Stakeholder room owner | 3 | Head of Stakeholder Rooms | Per-room TTL · MFA | Per-share | 2026-05-15 | No | SEC-EV-AXR-008 § RO |
| Data custodian (Restricted/MNPI) | 2 | CISO + Data Governance Lead | JIT · 4 h · recorded | Monthly | 2026-05-15 | No | SEC-EV-AXR-008 § DC |
| Incident commander (on-call) | 3 | CISO | On-page elevation · time-boxed | Quarterly | 2026-05-09 | Yes — 1 holder rotation overdue | SEC-EV-AXR-008 § IC (in progress) |
| Break-glass | 1 | CISO + COO (dual) | Sealed · open-on-break only · auto-rotate after use | Quarterly drill | 2026-04-02 | Yes — drill overdue (target 2026-05-02) | SEC-EV-BREAK-007 (drill pending) |
Secret class · storage · rotation · last rotation · exposure
| Secret class | Storage | Rotation cadence | Last rotation | Owner | Exposure risk | Evidence ref |
|---|---|---|---|---|---|---|
| App signing keys | Cloud KMS · HSM-backed | 90 d | 2026-04-22 | Identity Lead | Low · key material non-exportable | SEC-EV-KEY-001 |
| Service credentials (S2S) | Secret manager | 60 d | 2026-04-30 | SRE Lead | Low · injected at runtime · no repo exposure | SEC-EV-KEY-002 |
| Database credentials | Secret manager · IAM-scoped | 30 d | 2026-05-10 | SRE Lead · Data Governance Lead | Low | SEC-EV-KEY-003 |
| Third-party API keys (vendor inventory) | Secret manager · per-vendor scope | 90 d | 2026-04-15 | Head of Procurement · SRE Lead | Medium · scope review pending for 1 vendor | SEC-EV-KEY-004 |
| Webhook signing secrets | Secret manager | 180 d | 2026-03-12 | SRE Lead | Low | SEC-EV-KEY-005 |
| Evidence-pack encryption keys | Cloud KMS · per-pack DEK · KEK rotated | 90 d | 2026-04-22 | Head of Evidence · CISO | Low | SEC-EV-KEY-006 |
| Stakeholder room link signing | Cloud KMS | 30 d | 2026-05-10 | Head of Stakeholder Rooms · CISO | Low | SEC-EV-KEY-007 |
| JWT signing keys | Cloud KMS · key-ID rotated | 30 d | 2026-05-08 | Identity Lead | Low | SEC-EV-KEY-008 |
| Backup encryption keys | Cloud KMS · BYOK candidate | 180 d | 2026-02-18 | SRE Lead · CISO | Watch · rotation due 2026-08-17 | SEC-EV-KEY-009 |
Control · signal · threshold · alert owner · escalation
| Control | Signal monitored | Threshold | Current sample | State | Alert owner | Escalation path | Evidence event |
|---|---|---|---|---|---|---|---|
| WAF · OWASP Top 10 rule pack | Block / challenge rate per route | Block rate < 0.5 % on healthy routes | 0.21 % (baseline) | Configured | SRE Lead | SRE Lead → CISO on sustained > 1 % | WAF-EV-001 |
| WAF · custom rule pack (auth · evidence export · upload) | Hits on custom rule IDs | 0 hits on critical IDs | 0 (baseline) | Drafted · pending test | CISO · SRE Lead | Auto-page CISO on any critical-ID hit | WAF-EV-002 |
| API rate-limit (per route · per tenant) | Rejections / 1 m | < 50 rejections / m on healthy routes | 12 (baseline) | Enforced | SRE Lead | SRE Lead | API-EV-003 |
| API auth-failure spike | 401/403 burst per IP / per principal | < 20 / m / principal | 2 (baseline) | Enforced | CISO | Auto-page on > 20 / m | API-EV-004 |
| SIEM · admin action stream | High-risk admin actions per hour | All actions captured · 0 dropped | 14 / h captured · 0 dropped | Configured | CISO | CISO → COO on anomalous burst | SIEM-EV-005 |
| SIEM · evidence-pack access | Read/write/export events | 100 % capture | 2,841 captured / 7 d | Configured | Head of Evidence · CISO | Anomaly triage via Model Governance | SIEM-EV-006 |
| SIEM · stakeholder-room access | Off-hours · off-device · scope changes | 100 % capture | 1,193 captured / 7 d | Configured | Head of Stakeholder Rooms · CISO | Auto-page CISO on off-device + restricted scope | SIEM-EV-007 |
| SIEM · DLP / data egress | Restricted-class data leaving boundary | 0 unauthorised egress | 0 | Pending test | Data Governance Lead · CISO | Auto-block · auto-page CISO | SIEM-EV-008 |
Dependency · static · secret scan · infra review · release · remediation
| Check | Tool / signal | Owner | Cadence | Last run | Open issues | Remediation SLA | Exception handling | State |
|---|---|---|---|---|---|---|---|---|
| Dependency scan | SCA · SBOM diff per release | SRE Lead | Per release + nightly | 2026-05-15 | 2 P3 (transitive) | P0 ≤ 24h · P1 ≤ 7d · P2 ≤ 30d · P3 ≤ 90d | CISO sign-off required | Watch |
| Static analysis | SAST · ruleset pinned per release | SRE Lead | Per release | 2026-05-15 | 0 | Same SLA tiers | CISO sign-off | Enforced |
| Secret scan | Pre-commit · CI · history scan | SRE Lead | Every push | 2026-05-15 | 0 | P0 immediate rotation | Block-on-detect | Enforced |
| Infrastructure review | IaC scan · CIS-aligned rules | SRE Lead · CISO | Per IaC PR | 2026-05-14 | 1 P3 (logging-retention drift) | Same SLA tiers | CISO sign-off | Watch |
| Release approval | Approval & Sign-Off + Release Control gate | Programme Manager · CISO | Per release | 2026-05-15 | 0 | n/a | No release without dual sign-off | Enforced |
| Remediation SLA tracker | Vuln backlog burn-down | SRE Lead · CISO | Weekly | 2026-05-15 | 3 open · 0 SLA breached | Aged-out alerts page CISO | Exceptions logged in register | Enforced |
| Exception handling | Time-boxed exception with compensating control | CISO | Per-exception | 2026-05-14 | 1 open exception (WAF rule pending) | ≤ 30 d | Risk-committee review | Exception Granted |
Links to Production Monitoring · Release Control · Regulatory Escalation · Data Governance · Stakeholder Rooms · Vendor Risk
Production Monitoring & Incident Command
Security incidents page the Incident Commander via the production monitoring runbook. Severity, RTO/RPO impact, and customer-impact recorded with the same audit-event family.
Release Control & Rollback
If a release introduces a security regression, Release Control rolls back; security review re-runs and the release re-enters Approval & Sign-Off.
Regulatory Escalation
Incidents that meet jurisdiction notification triggers (ADGM · FCA · MAS · MiFID-aligned) escalate to the Regulatory Notification & Board Escalation Centre with timeline.
Data Governance & Privacy
Incidents involving personal or restricted data trigger DSR & transfer review in the Data Governance Centre; access ledger updated and retention hold applied.
Stakeholder Rooms & Evidence Distribution
Room-access anomalies escalate to room owner + CISO; impacted rooms can be frozen and rotated link-signed.
Vendor / Third-Party Risk
Third-party security incidents trigger vendor risk review and (where applicable) exit-substitution planning & counsel review.
ADGM · UK FCA · MAS · MiFID — internal readiness only
| Jurisdiction | Security focus areas | Internal readiness state | Evidence output | Limitation (draft) | Owner |
|---|---|---|---|---|---|
| ADGM / FSRA | Cyber risk · outsourcing · data-handling · incident notification | Drafted | Control inventory · access reviews · incident timeline | Internal posture only; not FSRA certification. | CISO · Head of Regulatory |
| UK FCA | Operational resilience · important business services · incident notification | Drafted | Resilience runbooks · evidence-pack samples · vendor exit plans | Drafted against FCA OpRes; not a substitute for SMF accountability sign-off. | CISO · SMF Lead |
| Singapore / MAS | Technology risk · cyber hygiene · third-party risk | Drafted | IAM controls · SIEM samples · vendor concentration · key rotation | Drafted against MAS TRM expectations; not MAS-issued approval. | CISO · Data Governance Lead |
| EU MiFID II / MiFIR | Record-keeping · access control · incident traceability (no order routing) | Drafted | Auth event log · evidence access log · retention attestation | Platform does not place orders. Records aligned for evidence retention only. | CISO · CFO |
Open exceptions · compensating controls · target close
| Exception | Affected control | Severity | Owner | Compensating control | Resolution path | Target close | State |
|---|---|---|---|---|---|---|---|
| Missing MFA test on Entra pilot | MFA policy | Medium | CISO | Staging factors enforced; Entra cohort gated | Complete Entra cutover + MFA enforcement test | 2026-06-05 | Pending Test |
| Stale access review (Incident Commander rotation) | Access reviews | Low | CISO | Holder bound to MFA + privileged-session log | Close Q2 review by 2026-05-22 | 2026-05-22 | Watch |
| Privileged account without explicit expiry | Founder root (permanent) | Accepted | Board (dual) | Re-auth + dual approver on every privileged action | Board-recorded accepted risk; monthly attestation | Standing accepted risk | Exception Granted |
| Secret rotation overdue (Backup KEK) | Backup encryption keys | Low | SRE Lead | Backups encrypted; access constrained | Rotate before 2026-08-17 | 2026-08-17 | Watch |
| SIEM gap — DLP egress pending test | SIEM · DLP | Medium | Data Governance Lead · CISO | Restricted-class data tagging + ABAC denies enforced | Complete DLP egress test on staging | 2026-05-30 | Pending Test |
| Vulnerability SLA — one P3 nearing aged-out alert | Dependency scan | Low | SRE Lead | Transitive · no runtime exposure | Remediate or accept with risk-committee sign-off | 2026-06-02 | Watch |
| WAF custom rule pending sign-off | WAF custom rule pack | Medium | CISO · SRE Lead | OWASP pack live; manual review on critical paths | CISO sign-off on rule pack; enable in shadow then enforce | 2026-05-28 | Exception Granted |
| Unsupported stakeholder-room role request | Room recipient roles | Low | Head of Stakeholder Rooms | Request refused · observer role offered as substitute | Decline + document; surface in onboarding policy | 2026-05-24 | Blocked |
| Break-glass test overdue | Break-glass account | Medium | CISO · COO | Sealed account; dual approver on open; auto-rotate | Schedule drill + capture evidence + revoke | 2026-05-26 | Conditional Approval |
Audit log of security control & IAM events
| Timestamp (UTC) | Actor | Security control | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 09:12 | CISO · Identity Lead | IAM control inventory | SEC-IAM-BASELINE published | sha256:aa11…cc01 | "Internal readiness only." | Entra cutover plan dated |
| 2026-05-13 14:22 | CISO | MFA policy | SEC-MFA-POLICY-002 drafted | sha256:bb22…cc02 | "Not MFA certification." | Enforce at Entra cutover |
| 2026-05-15 11:05 | CISO · Programme Manager | Access reviews | SEC-AXR-008 Q2 review in progress | sha256:cc33…cc03 | "Internal." | Close stale assignment by 2026-05-22 |
| 2026-05-10 03:18 | SRE Lead | Database credentials | SEC-KEY-003 rotated | sha256:dd44…cc04 | "Internal." | Next rotation 2026-06-09 |
| 2026-05-14 22:48 | SRE Lead | WAF OWASP pack | WAF-EV-001 baseline captured | sha256:ee55…cc05 | "Internal." | Enable custom rule pack in shadow |
| 2026-05-15 06:30 | CISO | SIEM evidence-pack access | SIEM-EV-006 7d sample preserved | sha256:ff66…cc06 | "Internal." | Weekly anomaly review |
| 2026-05-15 12:00 | SRE Lead | Vulnerability backlog | SEC-VULN-BURN weekly review · 3 open | sha256:aa77…cc07 | "Internal." | Close 1 P3 before 2026-06-02 |
| 2026-05-09 17:42 | CISO · SRE Lead | Security incident runbook | SEC-IR-DRILL tabletop completed | sha256:bb88…cc08 | "Tabletop only; not a live incident." | Quarterly cadence |
| 2026-05-15 13:22 | Risk Committee | Exception register | SEC-EXC-REGISTER 9 open exceptions logged | sha256:cc99…cc09 | "Internal readiness only." | Weekly review |
| 2026-05-16 07:40 | CISO · COO · CEO | Security control owners | SEC-ATTESTATION monthly attestation | sha256:dd00…cc10 | "Internal; not regulatory approval." | Re-attest monthly |
Classification level · MNPI posture · clean-team · access boundary · retention · residency · watermark · release authority
Classification & MNPI rule: No real MNPI, client / customer / investor identity, regulator contact, clean-team identity, deal codename in flight, access log line, IP address, device fingerprint, room URL, signed URL, room token, OTP code, watermark salt body, board pack body, board minute body, regulator submission body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, transaction / order data, confidential attachment contents, personal data subject identity, or live notification channel appears in this register, in the API at /api/data-classification-mnpi-boundary-register, in the fixture, or in any commit. Only reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors, linked evidence / control / stakeholder / regulatory dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria are recorded. Staging or demo classifications do not count as production data classification or MNPI boundary evidence. Internal data-classification / MNPI boundary readiness posture only — not data classification authorisation, not MNPI boundary acceptance, not privacy-compliance certification, not data residency authorisation, not clean-team activation, not data-room authorisation, not regulator submission, not launch authorisation, and not external-use authorisation.
Read-only fixture exposed via /api/data-classification-mnpi-boundary-register; reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors only. Authoritative row table is rendered in the
Data Governance, Retention & Privacy Centre.
Mirrored summaries in the
Final Production Launch Control Tower,
the Regulatory Notification & Board Escalation Centre,
the Strategic Risk Register & Scenario Planning Centre,
the Stakeholder Rooms · External Evidence Centre,
and the Completeness Command Centre.
Cross-references /api/approval-authority-register, /api/risk-acceptance-exception-register, /api/stakeholder-evidence-distribution-gate, /api/regulatory-submission-correspondence-gate, /api/evidence-pack-gate-validation, /api/jurisdictional-permissions-matrix, and /api/observability-slo-incident-evidence. Staging or demo classifications do not count as production data classification or MNPI boundary evidence.
What this Centre is — and is not
- Staging / simulated security data. All control identifiers, evidence hashes, audit events, last-test dates, and rotation timestamps shown here are seed values for an internal security readiness workflow. They are not production telemetry, not a live SIEM index, and not a live audit log.
- Internal security readiness workflow only. This Centre captures BLACKSWAN's internal security posture. It is not security certification, not a SOC 2 / ISO 27001 attestation, not a regulator-issued approval, and not a substitute for an external assessor engagement.
- Not legal advice. Jurisdiction posture (ADGM / FCA / MAS / MiFID) is drafted by internal owners as readiness only and is pending counsel review. Submissions to any regulator are always reviewed and signed by external counsel and the accountable SMF / senior person.
- Not an audit opinion. Control owner attestations are internal management attestations. They do not constitute an internal-audit opinion or an external-audit conclusion.
- Not authorization for external launch. Enforced state means "control is configured and tested internally." External-facing deployment, regulator engagement, and tenant-specific Entra cutover are pre-conditions that are tracked elsewhere and are not implied by any state shown here.