Platform Audit Approach
The periodic audit of Synapse activity is intended to surface potential threat scenarios concerning the privacy and security of data held in Synapse. The approach to this audit is informed by an assessment of risks to priority data, such as the data sets associated with Synapse projects marked with restricted access control lists. The risk assessment process considers access control at the point when access is granted, when access is used, and when access may become uncontrolled.
Auditing may be done by analyzing a comprehensive report of activity over the audit period. A comprehensive report is generated by running queries that precisely target privacy threat scenarios.
Overview
The Synapse audit should occur twice a year, once in July and once in January. Each audit should contain data from the two quarters prior to the data pull. The purpose of the audit is to ensure that there have not been any data breaches or security risks during the respective audit period.
An audit report is generated during each audit to analyze the data and explain whether there have been any security breaches or privacy concerns. The Governance Regulatory Support Team should submit the audit report to WIRB annually in October during the Synapse continuing review, which occurs in October.
For more details, please reference the following pages:
Audit Timeline
When | Who | What |
First two weeks of January and July | Synapse Security Engineer | Run Automation
Reference “Engineering Audit Resources” page for details |
Second two weeks of January and July | Synapse ACT | Sort Data & Triage Threats
Reference the “Audit Details for ACT” page for details |
Mid September | Synapse Security Engineer and Synapse ACT | Generate Audit report following this template
Reference the “Audit Report” page for details |
Late September | Director of Governance (Christine) | Review and Approve/Reject Audit Report
|
October | Synapse Security Engineer and Governance Regulatory Support Team | Security Engineer: Submit Audit Report to HITRUST Governance Regulatory Support Team: Submit Audit Report to WIRB during Synapse Continuing Review Reference the “Audit Report” page for details |