Join our Newsletter — 33% off our NHI Course

What is the difference between access control and evidence integrity for privileged sessions?

Access control answers who may open the session or the recording. Evidence integrity answers whether the recording still reflects the original event after storage, replay, or download. In zero trust, both matter because a legitimate viewer can still be handed a tampered artefact.

How access control differs from evidence integrity in privileged sessions

Access control and evidence integrity answer different security questions, even though they often apply to the same privileged session workflow. Access control governs who may start, view, replay, export, or administer the session artefact. Evidence integrity governs whether that artefact still proves what actually happened, with no unauthorised edits, truncation, or silent replacement after capture.

That distinction matters because a recording can be perfectly protected at the access layer and still lose evidential value if its contents are altered, re-encoded, partially deleted, or detached from the session metadata that explains its context. Likewise, a recording can remain unmodified while being accessible to the wrong audience. Privileged session controls need both properties, not one in place of the other.

For practitioners, the cleanest way to think about it is that access control protects the doorway, while evidence integrity protects the object on the other side of the doorway. The first is about authorisation and distribution, the second is about trust in the record itself.

What each control protects in a privileged session workflow

In privileged access workflows, access control usually includes approval, role checks, viewer restrictions, segregation of duties, and limits on export or replay. A privileged session platform may also enforce just-in-time access, break-glass approval, or dual control for administration. The question is whether a given person or system is allowed to interact with the session at all, and in what way.

Evidence integrity is narrower but deeper. It concerns whether the session log, recording, transcript, or audit trail remains a faithful record after collection and storage. Typical integrity protections include tamper-evident hashes, signed artefacts, immutable storage, preserved timestamps, and chain-of-custody controls. Privileged Session Management Guide is useful here because privileged session tooling is where both access gating and evidential trust are usually implemented.

In practice, these controls answer different operational questions. Access control tells you whether the investigator, manager, or auditor should be able to open the file. Evidence integrity tells you whether the opened file still represents the original privileged event well enough to rely on it in incident review, compliance evidence, or dispute resolution.

Why the distinction matters for audit, investigations, and zero trust

These two concepts separate cleanly during incident response and audit review. If a privileged session is challenged, access control helps demonstrate that only authorised reviewers could see it. Evidence integrity helps demonstrate that the session record was not altered before review, export, or legal hold. Both are needed when the record may be used as proof rather than just as telemetry.

That is why session platforms often combine brokering, recording, and monitoring with retention and immutability features. NHIMG’s Privileged Access Management Guide explains the wider privileged access model, while Break-Glass and Emergency Access Account Guide shows how exceptional access makes both reviewability and tamper resistance more important, not less. In zero trust terms, the viewer still needs permission, but the artefact itself must also remain trustworthy across storage and transfer.

ISO/IEC 27001:2022 Information Security Management and the NIST SP 800-53 Rev 5 Security and Privacy Controls both reinforce this split between access restriction and record protection. One control family limits who can see or use privileged evidence, while the other supports auditability, integrity, and retention of the underlying record.

Risk and Threat Considerations

Privileged session artefacts are attractive because they can expose admin commands, credentials in motion, sensitive change activity, and investigative detail. If access controls are weak, the risk is unauthorised viewing or export. If integrity controls are weak, the risk is quieter: a modified recording can mislead reviewers, hide malicious steps, or create false confidence in an apparently clean audit trail.

Failure mechanism: An attacker, insider, or careless operator can gain access to the session record, then alter, truncate, repackage, or replace it after capture if integrity controls do not preserve a verifiable chain of custody.

Impact: The organisation may lose trust in the record, miss evidence of privilege abuse, make the wrong containment decision, or fail to defend the session as reliable evidence in an audit or investigation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-9 — Protection of Audit Information Protects privileged session records from alteration or deletion after capture.
AC-6 — Least Privilege Limits who can open, export, or administer privileged session artefacts.
Recommendation — Protect audit records with tamper-resistant storage and restricted modification paths. Restrict session access to the minimum roles needed for review and administration.
ISO/IEC 27001:2022 A.8.15 — Logging Supports trustworthy recording and review of privileged session activity.
A.8.16 — Monitoring activities Supports oversight of privileged sessions and suspicious access to records.
Recommendation — Log privileged session activity and protect logs from unauthorised alteration. Monitor privileged session access and investigate unusual review or export behaviour.
CIS Controls v8 CIS-8 — Audit Log Management Covers protection and retention of records used as evidence.
Recommendation — Centralise and protect privileged session logs and recordings for later verification.

Practitioner Guidance

What to verify: Confirm that viewer permissions, export permissions, and administrative permissions are separated from the controls that preserve file integrity. A reviewer who can open a session should not automatically be able to rewrite, re-sign, or replace it.

What good looks like: The session record is accessible only to the intended audience, and every stored copy can be checked against a stable integrity marker, retained metadata, or immutable archive. If the platform cannot prove both, treat the artefact as operationally useful but not fully evidential.

Decision rule: If the issue is “who is allowed to see this session,” treat it as access control. If the issue is “can we still trust this session after storage or download,” treat it as evidence integrity. When both are in scope, design and test them separately.

Practitioner takeaway: Privileged session security is not complete until you can restrict access to the recording and also prove the recording has not been altered since capture.