Benefits and Challenges of User Access Review
2022. December 19.

[vc_row][vc_column][vc_column_text]

Benefits

User access review (hereinafter: UAR) is the periodic review and verification of user access rights within one or more IT system of an organisation. This process is vitally important for the security of the organisation’s systems and data. UAR, as most of today’s data security measures, does not provide complete protection and assurance by itself, however it is a very important part of an organisation’s internal control system.

The benefits of a well-designed UAR programme are many:

Challenges

Everyone who has seen or participated in a UAR process have experienced how complex it is. There are many sensitive process steps to which we need to pay attention to have a complete, efficient and effective review.

We have audited and taken an active part in several UAR processes. Based on our experience, we would like to highlight the following key factors that can significantly contribute to the success of the process.

1. Scope

2. Process actors

3. Data sources

What are the sources of the data for the UAR? How can we make sure that they are complete and accurate? This is particularly important if there is external audit over process.

4. Tools

On which platform do we organise the UAR process? If there are a lot of manual steps in Excel, that is time-consuming and more error-prone. Purchasing an out-of-the-box software can be expensive and it may not be a complete solution to cover all your organisation’s needs.

5. Timelines

How do we resolve if an approver is unavailable for a period of time? How does delegation work? Who can perform it?

6. Consequence management

How do we manage responses not received by the deadline? Do we remove all roles, causing potential business disruption? How do we filter out self-review, thus ensuring independent approval?

To conclude, there are many questions and decision points that arise during a UAR process, where the assistance of an external consultant with knowledge of multiple methods and processes may be helpful at any time.

How can we help you?

Our experts have been involved in UAR-related projects for several companies throughout the years. Our services related to user access reviews are the following:

 

1. Figure A screen of ABT’s UAR tool

If you are interested in our UAR services, please contact us![/vc_column_text][/vc_column][/vc_row]

The above summary is provided for information purposes only. We recommend that you consult our experts before making any decision based on this information.