Boris.Lekumovich likes this.
  • After completing the collection, Access Reviews can begin to run to verify that the access is valid and appropriate.

    Access review should help you to review users’ access to resources and determine whether access should be maintained or revoked

  • ofg21 (ProLink Identity Management Ltd.)

    Other "functional elements" of IG&L designed to help achieve the "least privilege model" are Rules.

    Different types of Rules should be used to detect situations where access should be revoked.

    This can be as soon as a new data collection is completed.

     

    In fact, I would argue that Rules should be your primary tool to minimize excessive permissions.

    Periodic (eg Yearly) Access Reviews are then be used as a "compensating control", to detect excessive permissions that were not handled in time by Rules.

     

    Expand Post