Sarbanes-Oxley Act
Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > How should termination procedures address a user's multiple roles?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How should termination procedures address a user's multiple roles?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 February 2007
Regarding access management policy, it is my belief that at the time of employee termination, locking the user ID and changing the "valid to" date to current date is sufficient. However, some think we should include the additional step of changing the "valid to" date of every role attached to the user ID, which for most of them is in the double digits, since they do not use composite roles. Please kindly address the question of whether or not this additional step is needed, and if this would be considered an industry standard or not.

>
EXPERT RESPONSE
By any and all means possible, remove every trace of a terminated user from the system. Though it may be a headache to remove access from a user in multiple groups, it has to be done. In fact, the more groups a user is in, the greater the danger that his or her "ghosts" can come back and haunt your system maliciously.

Terminated users who still have access are just as likely to penetrate enterprise systems as current employees. Former employees who retain access are considered by the information security industry to be insiders, making them part of any insider threat.

Besides blocking a terminated user for simple security reasons, removing these users is required for compliance with regulations, such as Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA). Both of these regulations require regular auditing of access controls and reporting of active accounts. It makes regulatory sense to monitor and remove terminated users from all groups.

You need an identity management system that not only provisions accounts, but also audits and removes stale accounts. When shopping around for such a system, make sure it can automate provisioning and provide auditing and reporting of active and inactive accounts. These systems should automatically flag an account that hasn't been active for a set time period, such as 30 days.

There are a number of tools on the market that can easily erase ex-employee IDs, provision new ones and change access levels. The Identity Management Suite from BMC Software Inc. has a tool called BMC User Administration and Provisioning, formerly called CONTROL-SA. The tool automates provisioning of accounts for as many (or as few) groups as a user needs access to. It also provides complete auditing and reporting capabilities for both compliance purposes and for use internally by your information security team. It also automatically removes expired users, preventing terminated employees from accessing your systems -- no matter how many groups they were in. Another product, PowerPassword from Symark Software International, offers similar access management controls but is strictly for Unix- and Linux-based systems. PowerPassword also provides logging and auditing features required for compliance.

For more information on termination procedures see Chapter 6 of my book, The Little Black of Computer Security. The chapter Managing Human Resources is excerpted on SearchSecurity.com.

For more information:

  • In this Identity and Access Management Security School lesson, see which IAM tools can satisfy compliance demands.
  • Learn how to prevent unauthorized access by securing your server.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    How to prevent hack attacks against smart card systems.
    For a small office, what are the best, least expensive office servers with secure access?
    What are the pros and cons of using stand-alone authentication that is not Active Directory-based?
    Should users set up password expiries in Active Directory?
    How to conduct an efficient and thorough employee access review.

    Password Management
    Societe Generale bolsters internal controls, discovers second insider
    Former LendingTree employees pilfer firm's customer database
    Hitachi acquires M-Tech Systems for identity management
    Worst Practices: Three big identity and access management mistakes
    Sun shifts strategy with GRC push
    Security360: Identity management market
    What are the pros and cons of using stand-alone authentication that is not Active Directory-based?
    Should users set up password expiries in Active Directory?
    IBM releases simplified Tivoli Identity Manager
    Top 10 access-related controls for PCI compliance

    Sarbanes-Oxley Act
    Information security book excerpts and reviews
    RSA attendees see data classification, rights management projects stumble
    Hannaford breach illustrates dangerous compliance mentality
    PCI compliance drives identity management spending, says IBM's GRC chief
    How to conduct an efficient and thorough employee access review.
    IBM to boost security spending, push PCI DSS program
    What types of software can help a company perform a security risk assessment?
    Industry group uses awareness month to lobby for data breach laws
    Code Green pitches data protection for SMBs
    Report: Companies still stumped by PCI DSS
    Sarbanes-Oxley Act Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    graphical password  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    logon  (SearchSecurity.com)
    OpenID  (WhatIs.com)
    passphrase  (SearchSecurity.com)
    password  (SearchSecurity.com)
    shadow password file  (SearchSecurity.com)
    single-factor authentication (SFA)  (SearchSecurity.com)
    TACACS  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts