AxiPassAxiPass
Back to blog
ISMS-P & Compliance·About 8 min

Preparing ISMS-P Account Management Evidence with Audit Logs

What account and access evidence an ISMS-P audit expects, and how audit logs keep you audit-ready at all times.

ISMS-P is South Korea's information security and personal data protection certification. If you have ever started digging through a year's worth of account provisioning and removal records only after the audit was scheduled, this article is for you. In an ISMS-P audit, account and access management is reviewed every year, and if you are unprepared, it is one of those areas where a single staff member burns several days right before the audit.

What the audit actually checks

For the authentication and access management area of ISMS-P, understanding what the auditor is trying to see is more useful in practice than memorizing clause numbers. There are three main threads.

First, were accounts created through a legitimate process? The auditor looks at who was granted an account, when, and through which approval, and whether the request and approval records remain. Second, were privileges granted only to the extent the work requires? They check whether the principle of least privilege is actually observed and whether excessive administrator rights are left unattended. Third, were unnecessary accounts revoked in time? They look at whether the accounts of leavers or people who changed roles were disabled without delay.

All three are judged not by "is the policy in a document" but by "is there a record that it was actually operated that way." That is why evidence—that is, logs—is the core.

Records you should keep as evidence

Instead of hastily taking screenshots in the audit room, these are the records that should already be there day to day.

  • The history of account creation, modification, and deletion, and who performed each action
  • The history and timing of privilege grants and revocations
  • Login success and failure records, especially access records for administrator accounts
  • Records of periodic access reviews (re-certification of privileges)

A commonly missed point here is consistency of timestamps. When logs are scattered across multiple systems, the same event is often recorded in different time zones. When you explain the sequence of events during an audit, this inconsistency trips you up. Storing logs against a single reference such as UTC, and showing them in the staff member's time zone only on screen, avoids this problem.

An approach that keeps you always ready

The goal of preparing evidence is not "produce the material at audit time" but "be able to present it instantly whenever asked." For this, three things are worth recommending.

Make records appear automatically at the moment account and privilege changes happen. Any approach that relies on people tidying up later will inevitably have omissions. And logs are more trustworthy when kept separately in a form that is hard to alter or delete. Finally, the per-period and per-user lookups and exports that auditors commonly request should be possible in advance. If you can extract account activity for a given period straight to CSV or PDF, audit response time drops sharply.

How AxiPass helps here

AxiPass automatically records major events such as account provisioning, privilege changes, and logins as audit logs, and keeps these logs in a separate dedicated database. Storage is in UTC, and the screen displays them in the user's time zone. You can also export audit records queried by period and user as an ISMS-P submission PDF report or CSV, so you do not have to gather audit material by hand every time.

If you want to see it right away, you can explore the audit log screen yourself when you start for free, and if you are curious about an approach suited to your organization's size, talk to us.

Get to know AxiPass

Start AxiPass for free

Try SSO, SCIM, MFA, and audit logs yourself on the Free plan. No credit card required.

Start free

Need help planning your rollout?

Tell us about your environment and the features you need, and our team will help you plan the adoption.

Talk to us
Back to blog