Skip to main content

Overview

Gap detection is the automated process of analyzing audit logs to identify compliance violations and security risks.

Detection Rules

ScaleHouse uses a comprehensive set of rules to detect gaps:
  • Terminated employees with active accounts
  • Users accessing data outside business hours
  • Unusual access patterns
  • Missing audit logs
  • Audit trail disabled
  • Incomplete event records
  • Failed login attempts
  • SQL command execution
  • Permission changes
  • Unauthorized data modifications
  • Bulk data exports
  • Image deletions

Severity Levels

Critical

Immediate action required (e.g., SQL command execution)

High

Should be addressed within 24 hours

Medium

Should be addressed within 7 days

Detection Frequency

Gap detection runs automatically:
  • Every 15 minutes for real-time monitoring
  • On-demand via dashboard refresh
  • After connector sync for immediate detection

Next Steps