skip to content

The subject of an insider case sits inside the SOC's own reporting line. Who approves telemetry access, and how?

level: principalimportance: nice to knowfreq 24%

answer

  1. Approval must leave the security line
  2. Name the alternate before any case exists
  3. The subject may administer the evidence
  4. Preservation and tipping off pull opposite ways
  5. No independent approver is a register entry

basics

~20 s

Approval must leave the security line entirely — a standing alternate such as internal audit, privacy or the general counsel's office. The subject also administers the tooling, so evidence, retention and the audit trail must move beyond their control before collection starts.

solid answer

~40 s

Two problems, and the second is the one people miss. Authority first: the approval chain cannot run through the subject or anyone whose career they influence, so you need a standing alternate outside security — internal audit, privacy or the general counsel's office, and for the CISO an audit-committee route. Then control of the evidence: a SOC member typically administers the SIEM, the EDR console, retention and the query audit, so they can watch the case, alter the record or notice the collection. Before collecting, move the relevant evidence and audit to a store they do not administer, sequence revocation against tipping off, and consider an external examiner. Decide all of this in policy beforehand. If no independent approver exists, that is a risk-register finding, not something to improvise.

go deeper

for a junior

Know that if a case names someone in your own team, you do not handle it yourself: it goes to a route defined in advance outside the security line.

for a middle

Explain why the ordinary approver is disqualified here, and why a subject who administers the SIEM or the query-audit index is a problem for the integrity of the record.

for a senior

Show the sequencing: confirm who administers the evidence, preserve outside their control, then weigh revocation against tipping off, and consider an external examiner.

for a principal

Own the policy decision made in peacetime — the named alternate approver, the escalation route for a case naming the CISO, the pre-provisioned break-glass and its own audit — and be willing to book the gap as a risk when no independent authority exists.

## Why this case breaks the normal design Every access control described elsewhere on this subject assumes the SOC is independent of the subject. When the subject *is* the SOC — an analyst, an engineer, the manager, or the CISO — three assumptions fail at once: 1. **The approval chain runs through the subject or their allies.** A request approved by the subject's own manager, or by someone the subject line-manages, is not a control. 2. **The subject administers the evidence.** SOC staff commonly hold administrative rights over the SIEM, the EDR platform, log retention, forwarding configuration and the query-audit index itself. Someone with those rights can read the case as it is built, shorten retention, disable an audit source, or delete entries. 3. **The subject knows the detections.** They know what is monitored, what is not, what is reviewed and what is merely collected. Detection-shaped assumptions about their behaviour are weaker than usual. ## Authority: naming the alternate in advance The useful answer names a **standing alternate approver defined in policy before any case exists**. Candidates: internal audit, the privacy or compliance function, the general counsel's office, or the risk function. For a case naming the CISO, the route usually goes to an executive outside the reporting line and, in a mature organisation, to the audit committee. The reason to fix it in advance is practical. During a live case, deciding who may authorise reading a colleague's mailbox becomes a negotiation among people who are themselves close to the subject, under time pressure, with the subject possibly aware. Written down in peacetime it is a paragraph: *"Where the subject of an investigation is a member of the security function, approval authority passes to X; where the subject is the head of the security function, to Y."* ## Control of the evidence, before anything else This is where the judgment shows. Before collection begins: - **Confirm where the relevant records live and who administers them.** If the subject administers that store, the record has an integrity problem from the outset. - **Ensure the audit trail is outside their reach.** Append-only or third-party-held audit indexes exist largely for this scenario; if the query audit sits in a system the subject administers, it cannot be relied on. - **Plan revocation.** Removing administrative rights is both necessary and a tipping-off event. Sequence it: collect and preserve first, then revoke, unless the risk of destruction outweighs the risk of alerting them. - **Consider an external examiner.** Retaining an outside forensic party means no one in the subject's line handles the data. It also removes the awkwardness of colleagues examining a colleague, and it strengthens the defensibility of the result if it is ever challenged. - **Watch the second-order signal.** The subject may notice the collection itself — a new forwarding rule, an unusual export, an agent policy change, a colleague behaving oddly. Assume they might, and decide whether you can live with it. ## The trade-offs a lead has to own - **Pre-provisioned independence versus least privilege.** A break-glass path that the SOC cannot see is, by construction, an access path outside the SOC's normal governance. It has to exist, and it has to be audited by whoever holds it. You are choosing which risk to carry. - **Speed versus independence.** The independent approver is, by design, someone who does not do this often. Expect slower decisions and brief them in advance so the first time is not during the case. - **Preservation versus tipping off.** Every step that secures the evidence is a step that might be noticed. - **Proportionality.** The subject is an employee with the same protections as any other, and being on the security team is not a reason for a lower bar. If anything the bar should be visibly equal, because the team's own credibility depends on it. ## When the answer is "there is nobody" Small organisations reach this quickly: the SOC is three people, the CISO approves everything, and there is no internal audit function. The correct move is not to improvise a chain that will not survive scrutiny. It is to name the gap — as a risk on the register, with an owner — and to arrange the cheap mitigations available: an external examiner on retainer, an audit trail held by a third party or in a store the security team cannot administer, and a written escalation route to a board member or an external adviser. That is a decision a lead is expected to make and to have made *before* the day it is needed. ## The tell interviewers listen for Weak answers stay on authority: "HR approves it". Strong answers add the evidence-control half — that the subject's administrative rights over the logging platform, the retention settings and the query audit are the more urgent problem, because authority can be arranged in an hour and a deleted audit trail cannot be recovered at all.

  • Why is the subject's administrative access the more urgent problem than the approval chain?
    Authority can be arranged in an hour; a deleted or altered audit trail cannot be recovered. A SOC member typically administers the SIEM, the EDR console, retention and forwarding configuration, so they can watch the case being built, shorten retention on the very sources you need, or remove their own query records. Confirming where the evidence lives and moving it beyond their control comes first.
  • You are a three-person security team with no internal audit function. What do you do?
    Do not invent a chain that will not survive scrutiny. Name the gap as a risk with an owner, then take the cheap mitigations: an external forensic examiner on retainer, an audit trail held outside the team's administrative control, and a written escalation route to a named executive, board member or external adviser. Agree it in advance; deciding during the case is how small organisations end up with unusable evidence.
  • Should the subject's administrative rights be revoked immediately?
    Not reflexively. Revocation is a tipping-off event, so sequence it against the risk of destruction: if they can plausibly delete or alter the evidence, preserve copies to a store they do not administer first, then revoke. If the risk of destruction is high and immediate, revoke first and accept that they will know. Either way, decide deliberately and record why.

saying these in an interview costs you the question

  • Routes approval through the subject's own management chain
  • Ignores the subject's admin rights over logs and retention
  • Improvises the approval authority during the live case
  • Revokes access first without weighing tipping off
  • Applies a lower bar because the subject is a colleague

context