Browse Definitions :
Definition

access recertification

Access recertification is an IT control that involves auditing user access privileges to determine if they are correct and adhere to the organization’s internal policies and compliance regulations. Access recertification is typically the responsibility of the organization’s Chief Information Security Officer (CISO) or Chief Compliance Officer (CCO) and may also be known as access attestation or entitlements review.

Access recertification can be carried out manually or programmatically. The first step in a manual recertification process is to extract and collate account information from the organization’s IT and business systems and distribute it in a format that will allow each manager to easily see what privileges each of his or her employees has been granted. Managers are then given a deadline for reviewing the information to flag inappropriate access and verify appropriate access. Challenges with this approach include the possibility that recertification may only be carried out sporadically and that some managers may not understand the importance of access recertification and rubberstamp their verifications.

In large organizations, access governance software can be used to automate the recertification process and ensure that audits occur on a regular basis. Once the information has been extracted and normalized, the software uses a message template to issue recertification requests. If the recipient of the recertification request fails to respond within a specified time period, the software suspends the recipient’s access rights and notifies the recipient’s manager. Challenges with this approach include the cost of the software as well as the time, effort and technical knowledge it requires to ensure the software’s interoperability with legacy systems.

This was last updated in October 2016

Continue Reading About access recertification

Networking
  • Network as a Service (NaaS)

    Network as a service, or NaaS, is a business model for delivering enterprise WAN services virtually on a subscription basis.

  • network configuration management (NCM)

    Network configuration management is the process of organizing and maintaining information about all of the components in a ...

  • presentation layer

    The presentation layer resides at Layer 6 of the Open Systems Interconnection (OSI) communications model and ensures that ...

Security
  • backdoor (computing)

    A backdoor attack is a means to access a computer system or encrypted data that bypasses the system's customary security ...

  • Heartbleed

    Heartbleed was a vulnerability in some implementations of OpenSSL, an open source cryptographic library.

  • What is risk management and why is it important?

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

CIO
HRSoftware
  • team collaboration

    Team collaboration is a communication and project management approach that emphasizes teamwork, innovative thinking and equal ...

  • employee self-service (ESS)

    Employee self-service (ESS) is a widely used human resources technology that enables employees to perform many job-related ...

  • learning experience platform (LXP)

    A learning experience platform (LXP) is an AI-driven peer learning experience platform delivered using software as a service (...

Customer Experience
  • chief customer officer (CCO)

    A chief customer officer, or customer experience officer, is responsible for customer research, communicating with company ...

  • relationship marketing

    Relationship marketing is a facet of customer relationship management (CRM) that focuses on customer loyalty and long-term ...

  • voice recognition (speaker recognition)

    Voice or speaker recognition is the ability of a machine or program to receive and interpret dictation or to understand and ...

Close