Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Student and Campus Life Policy & Procedure Manual

 

Title:  SCL Application Access Control Policy & Procedure                           

Section:                     1.0                                                                  

Effective Date:         September 1, 2021                                    

Revision Date:         July 9, 2024

 

Roles & Responsibilities

:

·       

 

System Admin (SSIT or Unit):

·        

PURPOSE

To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations.


SCOPE

All Student and Campus Life Applications Access


ROLES & RESPONSIBILITIES

 Manager

  • Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned.
  • Submit access requests through the TDX ticketing system for new employees.


System Administrator

  • Manage access to applications for all users that have joined Cornell, departed, been reassigned, or promoted from unit systems
.

 


SSIT

·        
  • Regularly review and maintain comprehensive list of attributes for all SCL owned and supported applications.
·        
  • Manage API for Human Resources data feed.
·        
  • Maintain TDX ticket routing rules, template updates, and messaging content.
 


SCL Compliance

Team

·        
  • Request user lists from System Administrators.
·        
  • Manage ticket exceptions.
·         Toubleshoot
  • Troubleshoot overdue pending tickets.
·        
  • Provide audit report to SCL leadership, upon request.

 

 

Review Process



·        

REVIEW PROCESS

  • SCL Compliance Team initiates request to System Administrators for updated user list and attestation.
·        
  • System Administrator uploads user list and submits attestation.
·        
  • API feed provided by Human Resources integrates with nightly updates.
·        
  • Employee profiles are flagged when there is a change in employment. This is an ongoing process, with regular data feed updates.
·        
  • Automated TDX tickets are sent to managers to approve or request removal of user account when an employee profile shows a change of title, supervisor, or employment status.
·        
  • Managers confirm (approve) continuation of user account or request removal of access by marking the appropriate action on the TDX ticket.
·        
  • Tickets marked with continuation of user account are automatically closed and moved to archive in TDX.
·        
  • System Administrator receives removal request for TDX tickets where the manager has indicated that a user account is no longer needed. System Administrator removes access and marks TDX ticket as closed.
·        
  • Managers may view employee profiles and request access changes at any time.
·        
  • SCL Compliance Team manages ticket exceptions and facilitates timely resolution of all tickets.
·        
  • SCL Compliance Team provides audit report to SCL leadership, upon request.
Audit Cycle


AUDIT CYCLE

·        

Random audits to validate data integrity to SCL compliance team may be conducted.

 

Related

University

Policies &

Guidelines


 

5.10:  Information Security

5.8:    :

PURPOSE

To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations.

SCOPE

All Student and Campus Life Applications Access

ROLES & RESPONSIBILITIES

Supervisor

  • Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned.
  • Submit access requests through the TDX ticketing system for new employees.