You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 7 Next »

Student and Campus Life

Policy & Procedure Manual

 

Title:  SCL Application Access Control Policy & Procedure                           

Section:                    1.0                                                                  

Effective Date:        September 1, 2021                                    

Revision Date:        July 9, 2024

 

Purpose


To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations.


 

Scope


All Student and Campus Life Applications Access


 

Roles & Responsibilities

Supervisor:

·         Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned.

·         Submit access requests through the TDX ticketing system for new employees.

 

System Admin (SSIT or Unit):

·         Manage access to applications for all users that have joined Cornell, departed, been reassigned, or promoted from unit systems.

 

SSIT

·         Regularly review and maintain comprehensive list of attributes for all SCL owned and supported applications.

·         Manage API for Human Resources data feed.

·         Maintain TDX ticket routing rules, template updates, and messaging content.

 

SCL Compliance Team

·         Request user lists from System Administrators.

·         Manage ticket exceptions.

·         Toubleshoot overdue pending tickets.

·         Provide audit report to SCL leadership, upon request.

 

 

Review Process

·         SCL Compliance Team initiates request to System Administrators for updated user list and attestation.


·         System Administrator uploads user list and submits attestation.


·         API feed provided by Human Resources integrates with nightly updates.


·         Employee profiles are flagged when there is a change in employment. This is an ongoing process, with regular data feed updates.


·         Automated TDX tickets are sent to managers to approve or request removal of user account when an employee profile shows a change of title, supervisor, or employment status.


·         Managers confirm (approve) continuation of user account or request removal of access by marking the appropriate action on the TDX ticket.


·         Tickets marked with continuation of user account are automatically closed and moved to archive in TDX.


·         System Administrator receives removal request for TDX tickets where the manager has indicated that a user account is no longer needed. System Administrator removes access and marks TDX ticket as closed.


·         Managers may view employee profiles and request access changes at any time.


·         SCL Compliance Team manages ticket exceptions and facilitates timely resolution of all tickets.


·         SCL Compliance Team provides audit report to SCL leadership, upon request.



Audit Cycle


·         Random audits to validate data integrity to SCL compliance team may be conducted.











  • No labels