Menu
Skip to main content
Table of Contents
<All topics
Print

Efficient auditing in Appterix Security Key Management

The challenge

For compliance audits (e.g., NIS-2, TISAX, ISO 27001) or in the context of responding to security incidents (Incident Response It is essential to precisely track when and where a hardware key was used. With a heterogeneous fleet of NitroKey- and Swissbit iShieldWithout central consolidation, this quickly leads to unwieldy log silos and high manual testing effort for devices.

Best practice: Use a central audit log

Take advantage of that Security Key Management > Journal Appterix serves as a manufacturer-independent, audit-proof log. The Appterix client on the end devices automatically and securely reports interactions with inserted NitroKeys or Swissbit hardware tokens to the central administration.

  • Targeted filtering: When investigating, search for predefined event tags such as "Lost security key used" or "Unauthenticated user".
  • SIEM Integration & Export: Use the export function (CSV/Excel) in the top right of the journal to prepare structured log data for external auditors or to seamlessly import it into your higher-level SIEM system.
  • Anomaly detection: Check the dashboard weekly to quickly identify unusual spikes in connection statistics (e.g., spikes on non-working days).

Advantages of the journal for NitroKey & Swissbit iShield

The consolidation of different hardware manufacturers in the Appterix Journal offers specific administrative and regulatory advantages:

  • Manufacturer-independent single source of truth: NitroKey (often used in open-source or high-security environments) and Swissbit iShield (frequently used in industrial or extremely rugged environments) are correlated alongside YubiKey LifeCycle Management in a single console. Administrators do not need to evaluate vendor-specific tools separately.
  • Audit compliance according to EU regulations: Every status change – whether PIN reset, lockout, or a failed authentication attempt – is recorded in the log in a tamper-proof manner. This ensures the required traceability according to [relevant regulations/standards]. NIS-2 and TISAX.
  • Automatic background inventory: Since the Appterix agent is hardened on the end devices and cannot be stopped by the user, the journal records the status and usage of the keys (FIDO2, PIV certificates) seamlessly as soon as the hardware is plugged in.

Typical use cases

Audit-proof lifecycle tracking

The journal documents the entire lifecycle of each NitroKey and Swissbit iShield. The error-prone need for manual Excel spreadsheets for hardware inventory is completely eliminated.

Automated Lost & Found Management

If an employee loses their token, it can be reported as "lost". Should the lost security key subsequently be inserted into an endpoint, the journal will immediately register the event with the corresponding tag. "Lost security key used" and optionally informs about the access before any damage occurs.

Practical scenarios and behavioral guidelines

Scenario A: Suspected token theft in a home office

An employee reports the loss of his Swissbit iShield Keys was delayed. There is a suspicion that unauthorized third parties may have gained access to company resources in the meantime.

  1. Journal entry: The administrator filters the journal for the unique serial number of the affected Swissbit key.
  2. Analysis of the events: It is checked whether log entries with the status exist after the presumed time of loss. "Unauthenticated user detected" or "Lost security key used" were registered.
  3. Reaction: The exported journal data subsequently serves as official proof for IT security management.

Scenario B: Compliance verification in crypto agility and post-quantum migration

The company is introducing new, crypto-agile NitroKeys one, to establish post-quantum encryption, while older legacy tokens are phased out in parallel.

  1. Dashboard control: About the Authentication Insights and the journal filters the IT according to the token models used and their firmware versions.
  2. Export for auditors: For an upcoming compliance audit, the security officer exports the report from the log. This report provides comprehensive proof that the legacy systems have been successfully decoupled and the new guidelines have been implemented across the board.