SCIM Provisioning Audit Gap - NIST SP 800-53 AC-2 Non-Compliance

Identity lifecycle management requires a verifiable audit trail for every account modification to satisfy NIST SP 800-53 AC-2. The gap here is that SCIM-driven user deletions aren’t surfacing in the audit query results.

Attempt Endpoint Result
Audit Query POST /api/v2/audits/query No events for SCIM DELETE
Service Map GET /api/v2/audits/query/servicemapping Service ID present, no logs

RFC 7643 defines the SCIM core schema for identity propagation, yet the platform isn’t logging the deprovisioning trigger. Documentation (Audit API) implies all security-relevant changes are captured.

1 Like