User Access Reviews for Financial Services

User Access Reviews for Financial Services

 Financial Institutions are heavily regulated by many agencies and standards to ensure proper security and IT controls. Nearly every financial IT audit requires that companies establish a user access management program. SCC has many leading banks, credit unions, and insurance companies that successfully automate their user access rights review. Access Auditor can give you that same success and automate your user access review in under one week.

For banks and credit unions, the governmental regulators follow the FFIEC IT Handbook which mandates the following items in your user access program.
  • Principle of least privilege, which recommends minimum user profile privileges for both physical and logical access based on job necessity.
  • Alignment of employee job descriptions to the user access program.
  • Requirements for business and application owners to define user profiles.
  • Ongoing reviews by business line and application owners to verify appropriate access based on job roles with changes reported on a timely basis to security administration personnel.
  • Timely notification from human resources to security administrators to adjust user access based on job changes, including terminations.
  • Periodic independent reviews that ensure effective administration of user access, both physical and logical.
Many requirements refer back to a user access review process. Access to all critical systems must be reviews on a regular basis by business lines and/or application owners. This creates a tremendous labor-intensive burden on financial companies of all sizes.
Access Auditor is the fastest and easiest solution available for automating the entire user entitlement review process. One bank with 2,000 employees was able to deploy Access Auditor and launch a web-based access review for 70 banking applications in under 2 weeks from start to finish.
To further improve the user access program, SCC’s Access Manager automates the provisioning and termination of users and their access to critical systems. Using advanced workflow automation, on-boarding and off-boarding steps can be orchestrated to occur with no manual intervention, all based upon triggered changes from HR or helpdesk teams.

RELATED INFORMATION


SUCCESSFUL FINANCIAL CUSTOMERS


WHAT OUR CUSTOMERS ARE SAYING

The deployment for AA went very smoothly... Access Auditor has changed what used to be a very onerous task into one that is easy to use, efficient and effective.

— Tony Meholic, Chief Security Officer, The Bancorp

NEXT STEPS

Schedule a demo to learn how you can automate your user access reviews in under one week.