Key Risks | Key Controls |
Administrative delays and errors in restricting access. | The SCL Compliance Tracking Database tightens notification of changes and improves communication around access needs. |
Compiling of user lists is prone to errors and time consuming for application administrators who manage applications that do not allow user account data to be exported. | AAC is increasing awareness and providing education around timeline for requesting updated user lists on quarterly cycle. |
No crosscheck for real-time access comparison. | AAC requires user lists to be uploaded on a quarterly basis and encourages more frequent updates in the SCL Compliance database. |
Communication between compliance with educational training required for access to applications is decentralized. | AAC project team will soon begin phase three to pivot the SCL Compliance database from an application centric focus to an employee focus that adds the tracking of educational training requirements. |
Individuals who hold multiple campus positions may need access to an application to fulfill responsibilities related to their secondary position. | AAC created a response option for ‘I am not the supervisor for the role in question’ that routes to a pending cue managed by SCL Compliance. SCL Compliance checks employment status in Workday, consults with managers and application administrators, determines access needs, and manages the ticket flow. |
Administrators may assign users with broader access than what is needed for their responsibilities. | Employees should be given the minimum access privileges to fulfill responsibilities. If broader access is requested, require written justification. |
Applications with too many application administrators are prone to inefficiency and gaps. | Limit # of application admins to 2-3 per application, with clear primary and backup designations. |