A full-stack IT Infrastructure Audit, Risk & Compliance Dashboard built to simulate the responsibilities of a Deloitte ITDA CEC Analyst. Demonstrates end-to-end skills in access monitoring, anomaly detection, SQL-based audit queries, risk scoring, and executive reporting.
This dashboard enables IT Audit and Risk professionals to:
- Monitor user access control logs across IT infrastructure systems in real time
- Detect suspicious authentication attempts, failed logins, and off-hours access
- Track privilege escalations and unauthorized access events
- Identify Segregation of Duties (SoD) conflicts
- Generate infrastructure compliance scores and AI-powered risk assessments
- Execute pre-built ITGC audit queries against live data
| Layer | Technology |
|---|---|
| Frontend | React 18, Vite, Tailwind CSS, Recharts, Lucide Icons |
| Backend | FastAPI (Python), async REST API |
| Database | MongoDB (via Motor async driver) |
| AI | OpenAI GPT-4o-mini (risk analysis) |
| Testing | Python requests-based API test suite |
IT-Audit-Dashboard/
│
├── API/ # FastAPI backend — routes, models, risk logic
│ ├── server.py
│ ├── requirements.txt
│ └── .env
│
├── Frontend/ # React 18 + Vite frontend
│ ├── src/
│ │ ├── App.jsx # Root router and layout shell
│ │ ├── index.jsx # React entry point
│ │ ├── index.css # Tailwind base styles
│ │ ├── services/
│ │ │ └── api.js # Axios API service layer
│ │ ├── components/
│ │ │ ├── Sidebar.jsx # Navigation sidebar
│ │ │ ├── StatCard.jsx # KPI metric card
│ │ │ ├── RiskBadge.jsx # Risk level badge
│ │ │ └── StatusComponents.jsx
│ │ └── pages/
│ │ ├── OverviewPage.jsx # IT Infrastructure Audit Overview
│ │ ├── AccessLogsPage.jsx # Access Control Audit Logs
│ │ ├── ViolationsPage.jsx # Security Violations & Compliance Breaches
│ │ ├── SqlQueriesPage.jsx # Audit Query Engine
│ │ └── AuditSummaryPage.jsx # IT Security Risk & Audit Findings Report
│ ├── index.html
│ ├── package.json
│ ├── vite.config.js
│ ├── tailwind.config.js
│ └── .env
│
├── Screenshots/ # Dashboard UI screenshots
│ ├── IT_Infrastructure_Audit_Overview.png
│ ├── Access_Control_Audit_Log.png
│ ├── Security_Violations_Report.png
│ └── SQL_Audit_Query_Interface.png
│
├── Dataset/ # Sample data definitions and schemas
├── Audit_Report/ # Generated audit findings and compliance reports
├── Documentation/ # Project documentation and architecture notes
│
├── backend_test.py # API test suite
├── test_result.md # Test tracking log
├── .gitignore
└── README.md
- 6 KPI cards: total audit log entries, active security violations, high-risk user accounts, failed auth attempts today, privilege escalations (7-day), infrastructure compliance score
- System Access Activity — 7-Day Trend area chart (access events vs violations)
- Audit Findings — Top Violation Categories horizontal bar chart
- Risk Level Distribution — All Infrastructure Events pie chart
- Full paginated audit trail of all access events (50 per page)
- Filter by risk level (critical / high / medium / low)
- Toggle violations-only view
- Live search by user account, system resource, IP address, or location
- Inline risk score progress bar per row
- Severity summary cards (critical / high / medium / low counts)
- Expandable violation cards with type, description, and detection timestamp
- One-click Resolve action per violation
- Toggle to include resolved violations
- 5 pre-built ITGC audit queries with SQL preview panel:
- Unauthorized Access Attempts
- Privilege Escalation Events
- Segregation of Duties Conflicts
- Failed Login Patterns
- Off-Hours Access Events
- Results table with execution time display
- Per-user infrastructure risk assessment lookup (USR001–USR010)
- Risk score bar, risk factors list, and remediation recommendations
- AI-generated security analysis (GPT-4o-mini)
- 5 key audit findings mapped to ITGC/ITAC control categories
Sample data is generated via the /api/generate-sample-data endpoint:
- 1,200 access log events spanning 30 days
- 10 simulated users across roles: Admin, Manager, Auditor, User, Guest
- 8 IP/location combinations including domestic and international
- 12 IT system resources: Financial DB, HR System, Payroll, CRM, Admin Panel, etc.
- Access result distribution: 85% success / 12% failed / 3% suspicious
- Risk scoring factors: failed attempts, privilege changes, off-hours access, weekend access
Each access event receives a risk score (0.0–1.0) based on:
| Factor | Score Added |
|---|---|
| Each failed login attempt | +0.20 |
| Each privilege change | +0.30 |
| Failed access result | +0.50 |
| Suspicious access result | +0.80 |
| Off-hours access (before 7AM or after 7PM) | +0.30 |
| Weekend access | +0.20 |
Risk levels: Low (< 0.3) · Medium (0.3–0.6) · High (0.6–0.8) · Critical (≥ 0.8)
This project simulates a standard IT General Controls (ITGC) audit cycle:
- Scoping — Define systems in scope (Financial DB, HR, Payroll, CRM)
- Data Collection — Pull access logs, user provisioning records, change logs
- Control Testing — Test access controls, authentication policies, SoD matrix
- Anomaly Detection — Flag off-hours access, brute-force attempts, privilege changes
- Risk Assessment — Score each user and event; classify by severity
- Reporting — Generate compliance score, violation summary, executive findings
| Category | Finding | Risk |
|---|---|---|
| Access Control | Off-hours system access detected across multiple users | High |
| Authentication | Repeated failed logins from multiple IPs | Critical |
| Privilege Management | Privilege escalations without change request | High |
| Segregation of Duties | Users with conflicting roles accessing Finance + Payroll | Critical |
| Compliance | Active violations keeping compliance score below 95% | Medium |
- ~15% of access events are flagged as violations (industry benchmark: < 5%)
- Off-hours access accounts for ~30% of all events — warrants time-based restrictions
- Privilege escalation events lack formal approval workflow
- SoD conflicts indicate role design gaps in the IAM system
- Recommend: MFA enforcement, account lockout policy, quarterly access reviews
cd API
pip install -r requirements.txt
# Configure .env with your MongoDB URL and DB name
uvicorn server:app --reload --port 8000cd Frontend
npm install
npm start # runs on http://localhost:3000Then open the dashboard and click "Seed Sample Data" on the Audit Overview page to populate the database.
python backend_test.py| Method | Endpoint | Description |
|---|---|---|
| GET | /api/dashboard/stats |
KPI summary statistics |
| GET | /api/access-logs |
Access control logs with filters |
| GET | /api/violations |
Security violations list |
| POST | /api/violations/{id}/resolve |
Mark violation as resolved |
| GET | /api/analytics/trends |
7-day trends + risk level distribution |
| POST | /api/sql-query |
Execute pre-built ITGC audit query |
| GET | /api/users/{id}/risk-assessment |
AI-powered user risk assessment |
| POST | /api/generate-sample-data |
Seed 1,200 sample audit log events |
- Add export to PDF/CSV for audit reports
- Implement real-time WebSocket updates for live log streaming
- Add user provisioning review module (joiners/movers/leavers)
- Integrate SIEM alert correlation (e.g., Splunk or AWS Security Hub)
- Add role-based access to the dashboard itself (auditor vs. admin view)
- Expand risk model with geolocation anomaly detection (impossible travel)
Built as a portfolio project to demonstrate expertise in:
- IT Audit & Risk frameworks (ITGC, ITAC, SoD)
- Full-stack development (React + FastAPI + MongoDB)
- Data analysis and compliance reporting
- AI-assisted security analysis
This project demonstrates an IT infrastructure audit system with a dashboard for analyzing system risks, access logs, and compliance violations.
- FastAPI (Backend)
- React + Vite (Frontend)
- MySQL (Database)
- Security Risk Monitoring
- Access Log Analysis
- Compliance Violation Tracking
- SQL Query Interface
- Interactive Dashboard
John Raj
B.E CSE Cyber Security
Sri Krishna College of Technology