ZenGRC

6 Steps to Create an Effective User Access Review Program

The article emphasizes the importance of regularly conducting user access reviews—focusing on identity and access management rather than just password safety—to protect company information by verifying employees' roles and access needs, especially given the frequent workforce changes and risks from both human error and cyber threats.

Taking regular inventories of your users and their needs helps keep information, and your company, safe and secure. In discussing user access, Deloitte’s David Mapgaonkar notes:

“Humans can still be bugged or tricked into revealing their passwords. There is malware, or malicious software installed on computers; there is phishing, in which cyber crooks grab login, credit card, and other data in the guise of legitimate-seeming websites or apps; and there are even “zero day” attacks, in which hackers exploit overlooked software vulnerabilities. And of course, old-fashioned human attacks persist, including shoulder-surfing to observe users typing in their passwords, dumpster-diving to find discarded password information, impersonating authority figures to extract passwords from subordinates, discerning information about the individual from social media sources to change their password, and employees selling corporate passwords.”

When the media discusses information security and cybersecurity concerns, passwords get the most attention. However, when it comes to user access reviews, password safety is the lowest risk of all. Reviewing user access is less about reviewing password safety and more about reviewing how much information an employee needs to do their job and verifying who the employee is – in other words, identity and access management.

With human error and electronic risks, internally monitoring your company’s user access is one way to protect information. Six to twelve months is a long time in the user access lifecycle. Particularly in larger corporations, employees enter and exit your workforce on a rotating basis and they change positions within your organization. At each stage, authentication is pivotal and must be managed regularly to ensure level of access for what needs to be done is accurate.

Often, former employees have access for far longer than they’re supposed to if a system administrator misses an employment termination email. An employee may have shifted departments, changing their user access needs and potentially posing a serious security threat. Internal assets can be compromised by employees who have outdated access. Therefore, reviewing a variety of different reports to ensure compliance and security matters. When trying to ensure that user access reviews are implemented successfully, you may want to consider some of the following tips.

What is a user access review?

A User Access Review (UAR), also commonly known as Access Certification or Entitlement Review, is a process that organizations implement to ensure that users have the appropriate access to systems, applications, and data. The primary purpose of a UAR is to prevent excessive or inappropriate access rights, which can pose security risks, especially the risk of insider threats.

The principle of least privilege is important to know when considering access control. Essentially, each user should have the absolute minimum access to systems and software possible. It is far better for them to have to request access to something they need than to discover they have access to many systems they don’t need. By allowing them too much access, the user has the opportunity to end up in places they shouldn’t be, seeing things they do not have reason or right to view, and potentially opening the door for the user to misuse the information or access. Least privilege-based access can be controlled by determining who has privileged access and to what, initiating role-based access control, and continuously monitoring access permissions, user accounts, and access policies through access audits.

Here’s a breakdown of what a User Access Review typically involves:

  1. 1.Identification of Access Points: Cataloging all the places where a user can access a system, including applications, databases, file servers, and other resources.
  2. 2.Listing Current Access Rights: For each user, generate a report or list of all the permissions and roles they currently have across the system (sometimes known as an “entitlement report”).
  3. 3.Review: The list is reviewed by the user’s manager, the data owner, or a designated authority to verify whether the access listed is necessary and appropriate for the user’s role and responsibilities.
  4. 4.Remediation: If discrepancies or excessive permissions are found, the reviewer can initiate a process to revoke or adjust the access rights.
  5. 5.Documentation: Maintain records of each UAR, including who reviewed it, what decisions were made, and any actions taken as a result. This documentation is crucial for audits and tracking patterns over time.
  6. 6.Automation: Many organizations use automated tools or solutions to manage the UAR process, schedule reviews, generate entitlement reports, facilitate the review process, track decisions, and automate remediation steps.

User Access Reviews are especially important in industries and environments where data security and privacy are paramount, such as healthcare, finance, and government. Regular UARs help organizations remain compliant with various regulatory standards and can significantly reduce the risk of data breaches and insider threats.

What is the difference between access review and access recertification?

“Access review” and “access recertification” are terms that are often used interchangeably, but they can have nuanced differences depending on the context. Both have their own compliance requirements.

Access Review: The process of regularly examining user permissions and roles across systems, applications, and data to ensure they align with job functions and organizational policies.

  • Frequency: As often as required based on organizational needs, risk assessment, or regulatory compliance. Some organizations may conduct access reviews more frequently for high-risk areas.
  • Scope: Can be broad (all systems and users) or targeted (specific to an application, system, or set of users).
  • Purpose: To identify any misalignments or discrepancies in user access rights. It serves as a routine checkup.

Access Recertification: A subset of access review, specifically focusing on revalidating and reconfirming that existing permissions and roles are still appropriate for users. It’s a formalized process where access rights are typically approved (or revoked) by managers or data owners.

  • Frequency: Usually done at regular intervals, such as quarterly, semi-annually, or annually, depending on regulatory requirements or internal policies.
  • Scope: Primarily targets existing permissions and roles to ensure they are still appropriate over time.
  • Purpose: To formally reconfirm and validate user access rights, often resulting in approvals or revocations based on changes in job roles, projects, or organizational structures.

While both access review and access recertification aim to ensure the right users have the right access, the key difference often lies in the specificity and formality of the process. Access recertification is more formal and is specifically about revalidating existing access, while access review is a broader examination of user permissions.

Who should conduct a user access review?

A User Access Review (UAR) is an essential process that ensures the appropriate allocation of access rights within an organization. Deciding who should conduct these reviews is crucial to their effectiveness and integrity. Typically, the responsibility for conducting a UAR rests on a combination of several roles within an organization:

  • Data or Resource Owners: Individuals or teams with primary responsibility for specific data sets or system resources. They evaluate if certain users should have access based on the data’s sensitivity and relevance.
  • Direct Managers: Familiar with the day-to-day responsibilities and tasks of their subordinates, ensuring access rights align with job functions.
  • IT or System Administrators: Generate accurate reports detailing user permissions and access histories, and implement necessary changes to user access after the review.
  • Information Security Teams: Provide oversight, ensure reviews align with security guidelines, and offer tools, training, and support.
  • Compliance and Audit Teams: Ensure UAR processes and decisions meet all regulatory standards and requirements.
  • External Auditors or Consultants: Offer an unbiased perspective, especially for regulatory audits or when internal expertise is lacking.

Why are user access reviews important?

UARs are essential for several reasons, primarily centering around security, compliance, and operational efficiency:

  1. 1.Enhanced Security
    • Prevention of unauthorized access
    • Mitigation of insider threats
  2. 2.Regulatory Compliance
    • Meeting regulatory standards
    • Audit preparedness
  3. 3.Operational Efficiency
    • Streamlining access
    • Accurate resource allocation
  4. 4.Risk Management
    • Identifying and addressing gaps
    • Maintaining trust
  5. 5.Maintaining Data Integrity
    • Ensuring only authorized individuals can modify or delete critical data
  6. 6.Change Management
    • Managing transitions during organizational changes

What Standards, Laws, and Regulations Encourage User Access Reviews?

UARs are advocated by various standards, laws, and regulations to ensure the security and privacy of data:

  1. 1.HIPAA: Requires regular review and verification of user access to electronic protected health information (ePHI).
  2. 2.Sarbanes-Oxley Act (SOX): Emphasizes internal controls over financial reporting, including regular UARs.
  3. 3.PCI DSS: Mandates regular review of user access to cardholder data and the card transaction environment.
  4. 4.ISO 27001: Calls for regular access reviews as part of access control objectives.
  5. 5.GDPR: Encourages robust access controls, including UARs, to safeguard personal data.
  6. 6.FISMA: Mandates comprehensive information security programs, including regular reviews of user access.

What are the benefits of a user access review program?

A UAR program offers a structured approach to managing and verifying user permissions, ensuring alignment with an organization’s security policies, business requirements, and regulatory mandates. Benefits include:

  1. 1.Enhanced Security Posture: Identifies and rectifies excessive or inappropriate access, reducing risk of unauthorized access or malicious activities.
  2. 2.Regulatory Compliance and Audit Readiness: Helps organizations meet requirements and streamlines the audit process.
  3. 3.Operational Efficiency: Optimizes system and application performance by removing redundant or obsolete access rights.
  4. 4.Data Integrity and Quality Assurance: Maintains data integrity by ensuring only authorized personnel can access and modify data.
  5. 5.Fostered Organizational Trust: Demonstrates commitment to data protection and privacy.
  6. 6.Proactive Risk Management: Allows organizations to identify and address potential issues before they escalate.

Common challenges associated with user access reviews

Implementing and maintaining a UAR program can pose several challenges:

  1. 1.Volume and Complexity of Access Points: Employees often have access to numerous systems, making the UAR process cumbersome.
  2. 2.Dynamic Business Environment: Organizational changes can lead to outdated access rights.
  3. 3.Lack of Automation and Tools: Manual processes are labor-intensive and prone to error.
  4. 4.Inconsistent or Ambiguous Review Criteria: Lack of clear guidelines can lead to inconsistent decisions.
  5. 5.Decentralized Systems and Siloed Information: Consolidating information for review can be difficult.
  6. 6.Reviewer Fatigue: Overwhelmed reviewers may overlook critical access issues.
  7. 7.Resistance to Change: Some may view UARs as bureaucratic hurdles.
  8. 8.Documentation and Audit Trails: Maintaining detailed records is crucial but challenging.
  9. 9.Training and Awareness: Ongoing training is required for effectiveness.
  10. 10.Ensuring Timely Remediation: Swift action is needed once issues are identified.

6 Ways to Create an Effective User Access Review Program

Assess User Access Risks

  • Identify the greatest risks in terms of who has the most open access to the most systems (e.g., developers, IT professionals, third-party vendors, employees).
  • Review risks annually and ensure security roles match organizational changes.
  • Revoke privileges or change roles as needed to improve fraud prevention.

Create Risk Appropriate Policies and Procedures

  • Develop risk-based policies and procedures.
  • Choose between "Deny All" (no access unless needed) and "Allow All" (access granted until proven untrustworthy) approaches.
  • Consider compliance concerns such as segregation of duties.
  • Implement action and row security to limit access appropriately.

Train Staff

  • Ensure everyone from managers to IT to HR understands their role in the process.
  • Provide training and foster a culture of security.
  • Schedule regular reviews and keep reports updated.

Set Alerts from Monitoring Software

  • Use monitoring software to review daily alerts and identify compromised access.
  • Address lags in rescinding access to prevent security gaps.

(Additional steps may be present in the full article, but are not included in the provided content.)