Student and Campus Life
Policy & Procedure Manual
Title: SCL Application Access Control Policy & Procedure
Section: 1.0
Effective Date: September 1, 2021
Revision Date: July 9, 2024
Purpose | To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations. |
Scope | All Student and Campus Life Applications Access |
Roles & Responsibilities | Supervisor: · Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned. · Submit access requests through the TDX ticketing system for new employees. |
| System Admin (SSIT or Unit): · Manage access to applications for all users that have joined Cornell, departed, been reassigned, or promoted from unit systems. |
| SSIT · Regularly review and maintain comprehensive list of attributes for all SCL owned and supported applications. · Manage API for Human Resources data feed. · Maintain TDX ticket routing rules, template updates, and messaging content. |
| SCL Compliance Team · Request user lists from System Administrators. · Manage ticket exceptions. · Toubleshoot overdue pending tickets. · Provide audit report to SCL leadership, upon request.
|
Review Process | · SCL Compliance Team initiates request to System Administrators for updated user list and attestation. · System Administrator uploads user list and submits attestation. · API feed provided by Human Resources integrates with nightly updates. · Employee profiles are flagged when there is a change in employment. This is an ongoing process, with regular data feed updates. · Automated TDX tickets are sent to managers to approve or request removal of user account when an employee profile shows a change of title, supervisor, or employment status. · Managers confirm (approve) continuation of user account or request removal of access by marking the appropriate action on the TDX ticket. · Tickets marked with continuation of user account are automatically closed and moved to archive in TDX. · System Administrator receives removal request for TDX tickets where the manager has indicated that a user account is no longer needed. System Administrator removes access and marks TDX ticket as closed. · Managers may view employee profiles and request access changes at any time. · SCL Compliance Team manages ticket exceptions and facilitates timely resolution of all tickets. · SCL Compliance Team provides audit report to SCL leadership, upon request. | |
Audit Cycle | · Random audits to validate data integrity to SCL compliance team may be conducted. | |
Related University Policies & Guidelines |
5.10: Information Security 5.8: Authentication to Information Technology Resources 5.4.1: Security of Information Technology Resources |