An Audit Component is an architectural building block of the EIRA Technical view - application supporting the Technical interoperability layer of the European Interoperability Framework.
It is included in the Enabler grouping Application Security Enablers.


A is a specialisation of Application Component. It Implements the functionality of providing support for the principle of accountability, which is holding users of a system accountable for their actions within the system, and detection of policy violations. The audit policy defines the elements of an information system which need to be traced, for example to assure traceability of actions: what, how, when, where and with what.


The Audit Component ABB  is salient for technical interoperability because it allows the implementation of audit policies as stated in the Security and privacy chapter of the Conceptual model for integrated public services provision : "Public administrations should ensure that a 'data access and authorisation plan’ which determines who has access to what data and under what conditions, to ensure privacy. Unauthorised access and security breaches should be monitored and appropriate actions should be taken to prevent any recurrence of breaches"


Example

The following implementation is an example on how this specific Architecture Building Block (ABB) can be instantiated as a Solution Building Block (SBB):

Activiti audit feature
The audit feature of Activiti archives all process instances, activity instances, keeps variable values continuously in sync and all form properties that are submitted so that all user interaction through forms is traceable and can be audited.
Authenticated users who submitted the forms are accessible in the history as well as for start forms and task forms.
https://www.activiti.org/userguide/#historyFormAuditPurposes



The latest release of the EIRA© is available on Joinup.


Source: European Interoperability Reference Architecture (EIRA version 3) (url) (with information on the 3rd release at the website of the ISA² - Interoperability solutions for public administrations, businesses and citizens).