SP-R-1 — Operator denies configuration changes
Component: Policy Engine. Mitigations: No audit log for configuration file changes. Action: Log configuration hash at startup; integrate configuration changes with SDLC change management
| Property | Value |
|---|---|
| Section | Repudiation |
| Owner | platform |
Mapped Controls
| Control | Title |
|---|---|
| SID-AUDIT-01 | Structured Security Event Logging |
| SID-OPS-05 | Secure Configuration Management |
Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md