Student and Campus Life Policy & Procedure Manual

Title:  SCL Application Access Control Policy & Procedure                           

Section: 1.0                                                                  

Effective Date: September 1, 2021                                    

Revision Date: July 9, 2024

PURPOSE

To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations.


SCOPE

All Student and Campus Life Applications Access


ROLES & RESPONSIBILITIES

 Manager

  • Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned.
  • Submit access requests through the TDX ticketing system for new employees.


System Administrator

  • Manage access to applications for all users that have joined Cornell, departed, been reassigned, or promoted from unit systems


SSIT

  • Regularly review and maintain comprehensive list of attributes for all SCL owned and supported applications.
  • Manage API for Human Resources data feed.
  • Maintain TDX ticket routing rules, template updates, and messaging content.


SCL Compliance

  • Request user lists from System Administrators.
  • Manage ticket exceptions.
  • Troubleshoot overdue pending tickets.
  • Provide audit report to SCL leadership, upon request.



REVIEW PROCESS

  • SCL Compliance Team initiates request to System Administrators for updated user list and attestation.
  • System Administrator uploads user list and submits attestation.
  • API feed provided by Human Resources integrates with nightly updates.
  • Employee profiles are flagged when there is a change in employment. This is an ongoing process, with regular data feed updates.
  • Automated TDX tickets are sent to managers to approve or request removal of user account when an employee profile shows a change of title, supervisor, or employment status.
  • Managers confirm (approve) continuation of user account or request removal of access by marking the appropriate action on the TDX ticket.
  • Tickets marked with continuation of user account are automatically closed and moved to archive in TDX.
  • System Administrator receives removal request for TDX tickets where the manager has indicated that a user account is no longer needed. System Administrator removes access and marks TDX ticket as closed.
  • Managers may view employee profiles and request access changes at any time.
  • SCL Compliance Team manages ticket exceptions and facilitates timely resolution of all tickets.
  • SCL Compliance Team provides audit report to SCL leadership, upon request.


AUDIT CYCLE

Random audits to validate data integrity to SCL compliance team may be conducted.


  • No labels