
MDT Automates User Access Reviews with SCC’s Access Auditor
Background
Member Driven Technologies, MDT, is a credit union service organization (CUSO) that helps over 100 credit unions navigate complex financial technology ecosystems. In addition to hosting the Symitar core processing system from Jack Henry™, MDT provides credit unions with the tools and technology needed to compete and grow.
The Challenge
Charged with the security of financial applications for credit unions, MDT performs a wide range of compliance and audit functions, including the periodic review of user access rights to critical business applications. For years, these user access reviews were performed using a manual process that involved creating spreadsheets that were emailed to various reviewers across the company. The reviewers needed follow-up, the replies were collected, and action tickets created to remove inappropriate access.
The biggest challenge with this vital process was the sheer volume of user permissions and types of accounts. This highly labor-intensive process required a tremendous number of staff hours performing tedious error-prone tasks. In short, the challenges included:
- Labor-intensive effort: The manual process was difficult and time-consuming.
- Collation and management of data: Reviews were performed using spreadsheets and email, making data management and records retention a cumbersome chore.
- Monitoring of user access rights: A critical piece of the identity governance program is monitoring for changes to ensure user access is appropriate.
The Solution
MDT decided to search for an Identity Governance solution to automate the entire end-to-end user access review process. The primary goal of the project was automation. An ideal solution would also help differentiate human account from non-human accounts and monitor for changes in user access rights.
Many vendors offer solutions that provide various aspects of automation for the user access reviews. To help select the best solution, MDT created a brief checklist of the most important criteria for a governance solution, including:
- Flexible Data Imports: The ideal solution needed to integrate with a wide variety of data import formats without requiring custom coding or scripting.
- User Experience: One of the primary goals of the project was to improve the user experience. The ideal solution needed custom workflows to assign reviews to specific approvers.
- Ease of Use: Products were reviewed based upon the simplicity and ability to learn quickly. The best solution must be intuitive and easy to use for both the compliance team and the end reviewers.
After a thorough review, Access Auditor from Security Compliance Corp was the clear winner and the only solution to meet the project requirements. The other solutions lacked the level of configuration the team needed. The three strongest features of Access Auditor included:
- Flexibility to work with data coming from multiple sources in various formats (Active Directory/LDAP, Core banking products, text files, cloud APIs, databases, and more).
- Rapid timeline and a proven track record of success.
- Automated alerting for user access rights.
The Results
Access Auditor delivered a tremendous success to MDT. According to Jason Sharabani, Senior Manager, Internal Audit & Compliance, “SCC’s Access Auditor has been an excellent addition to our identity and access management controls. We use the platform extensively for access auditing, and it has made our review process more efficient, consistent, and easier to manage. One of the areas where it has been especially valuable is helping us clearly separate and test administrative access. We are able to distinguish privileged Admin accounts from standard user access, which gives us much better visibility into elevated permissions and strengthens our overall access-control testing.”
To complete the lifecycle, Access Auditor provides full compliance reporting. First, the evidence of compliance is fully tracked and reported within Access Auditor. All answers and historical records are saved. In addition, any denies are monitored for remediation. Application data is automatically imported on a nightly basis, and Access Auditor will verify that any denies have been removed from the application and how long it took to remove the access.
Access Auditor provides great IT governance value beyond the user access reviews. Because the application data is refreshed automatically, MDT can generate ad-hoc reports of user access rights based upon application and roles. Any user and permission can be searched at any time. If a user is about to be terminated, Access Auditor can identify which systems to remove access as well as note if any terminated users still have access enabled. In addition, alerts on changes and separation of duties violations can be monitored and detected in near real-time.
According to Sharabani, “The automated alerting has also been a major benefit. When permissions are elevated on an Admin account, Access Auditor provides timely notifications that allow us to quickly review and validate the change. This has reduced the amount of manual monitoring required while giving us greater confidence that privileged-access changes are being identified and addressed appropriately.”
In summary, Access Auditor delivered success by providing significant time savings, tremendous improvements in security monitoring, and a great project success for the compliance team. “Overall, SCC’s Access Auditor has helped us improve the effectiveness of our user access rights auditing, privileged-access oversight, and compliance processes. The automation and visibility it provides have made it a valuable tool for strengthening our control environment, and we have been very pleased with the software.”
