Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

TRUST

Audit & Evidence

Create reviewable evidence for sensitive actions, policy decisions, configuration changes and integration outcomes.

Owner
Security & Compliance Operations
Scope
Accountable service actions
Status
Published control statement
01 / CONTROL

Control model

01

Actor & context

Who/what acted, organization/workspace, subject/context and session assurance where relevant.

02

Decision

Action requested, authorization/policy result and reason category.

03

Configuration

Policy/configuration/model/interface version associated with the action where material.

04

Outcome

Timestamp, correlation, success/failure and resulting state or approval evidence.

02 / BOUNDARY

Responsibility boundary

Audit evidence is access-controlled and is not the same as a public evidence register; patient data and secrets are not published.

03 / ESCALATION

Evidence and escalation

Evidence requests are handled according to authorization, purpose and retention; the public website is not a direct audit-log export channel.

EVENT MODEL

Audit evidence answers who did what, to which object, when and why

The evidence model should distinguish authentication, access, business decisions and state changes while sharing correlation identifiers that reconstruct the end-to-end action.

01

Actor & session

Record the authenticated actor/workload, organization/workspace and session/device context appropriate to the event.

02

Object & action

Identify the affected patient/order/document/resource or configuration object and the action/decision performed.

03

Time & correlation

Use reliable timestamps plus request/workflow correlation so distributed events can be assembled without copying sensitive payloads into logs.

04

Outcome & reason

Record success/failure and, for approvals/overrides/corrections, the decision reason or reference required by policy.

EVIDENCE CHAIN

From event generation to reviewable evidence

Audit is useful only if collection, access and retention are controlled.

GenerateApplication/service emits the relevant event at the decision or state-change boundary.
NormalizeApply a consistent actor/object/action/time/correlation schema without flattening domain meaning.
ProtectRestrict write/admin access and separate audit/evidence operations from ordinary business editing where the deployment supports it.
Store & retainApply retention/archival controls appropriate to the event class and repository policy.
QueryAuthorized reviewers search by actor, object, time and correlation without gaining unrelated content access.
Export / investigateProduce a scoped evidence package for incident, dispute or compliance review with chain/context preserved.
Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access