Review product activity and access
Private CA product audit logs record CA lifecycle changes, certificate issuance and revocation, profile and policy changes, HSM configuration changes, and administrative actions.
Platform audit logs in Account Manager record sign-in activity, user and role changes, and credential changes. Review both platform and product logs when an investigation involves account access and CA activity.
Based on the cadence required by your agency and whenever responsibilities change:
Confirm that each user and service user with Private CA access has a current business need.
Review Account Manager and Private CA role assignments separately.
Review permissions combined through multiple roles.
Confirm that PKI validation and PKI compliance roles remain assigned to different users where your ceremony process requires separation of duties.
Remove roles that are no longer required.
Review integration credentials for ownership, use, and expiration.
Investigate unexpected CA configuration changes, issuance activity, revocation activity, or key-recovery events.