0
04

User Access Reviews

In this topic, you’ll learn about your responsibilities in supporting reviews of the access our people have to our information.

Scroll down
to learn more

Let’s revisit the story of Sage for a moment. Remember the employee who had unauthorised access to client information?

That employee was arrested, but the case highlights the importance of protecting our information from unauthorised access by both external and internal parties.

In this case, all the employee needed was an internal login and she caused significant damage.

Her login was valid, but should she have had access to that data in the first place?

By ensuring that her access was regularly reviewed and fit for purpose, this breach could have been prevented or better contained.

The Sage Story part II

It’s important that we control the access that people have to our information. Reviewing and validating who has access to our services on a regular basis is fundamental in protecting our information and preventing fraud and misdemeanor.

Click play to watch the video. When you have finished, continue scrolling down the page.

User access reviews

When it comes to User Access Reviews, Business Owners, Service Owners and Line Managers all have specific responsibilities and accountabilities during the various phases of the process.

Consider the following and for each select what specific responsibilities and accountabilities each of the following people have.

As a Service Owner, Doug is for Data Gathering and Business Validation.

As a Service Owner, Doug is for Data Analysis.

As a Service Owner, Doug is for Remediation and Stakeholder Sign-off.

As a Line Manager, Doug is also for Business Validation.

As a Business Owner, Simon is for Data Gathering, Business Validation and Stakeholder Sign-off.

Call to action

Take a moment to reflect on the following UAR behaviours and select any that you’d like to adopt.

Back at work

Remember: Jamie and her team can provide assistance in understanding how to best support User Access Reviews.

UAR

Congratulations, you've finished Topic 4

Select the buttons below to continue.