What are user access reviews (UARs)?
A user access review (UAR) is a recurring security and compliance review process for verifying that users possess the appropriate access authorities to applications, systems, and data. UARs are a key focus for Identity Governance and Administration (IGA) implementations. They are also mandated for compliance with many regulatory standards including GDPR, HIPAA, PCI DSS, and SOX.
This blog discusses the different user access reviews that can be performed, the differences between manual and automated UARs, and best practices for performing user access reviews.
User access review types
Different types of user access reviews are performed for different purposes. As shown in Figure 1, common user access review types include:
- Periodic Reviews: A formal process specified in Identity Governance and Administration (IGA) and Access Governance and Compliance (AGC) frameworks where designated reviewers validate and confirm current user access rights to applications, data, and systems. Periodic reviews are scheduled and are often triggered by regulatory compliance audits.
- Event-Driven Reviews: Another IGA/AGC process to review, modify, and revalidate user access rights after a user reprovisioning or security event occurs. Event-driven reviews can be triggered by role changes, terminations, mergers & acquisitions, cyberattacks, and unauthorized access. Event-driven reviews should be immediately performed after the event occurs.
- Continuous Reviews: Review processes that are triggered whenever an access change is implemented. Continuous reviews provide an automated real-time review, validation, and confirmation process to catch user access provisioning errors as they occur. Continuous reviews are predictive rather than reactive. They are intended to detect and flag identity access drift, excessive access, and to automate anomaly detection.
- Manager access reviews are performed by managers and supervisors who review, approve, and recommend access changes for their direct reports.
- Resource owner reviews are performed, approved, and maintained by system, application, and data owners for all users having access to their designated resources.
User access reviews are generally performed by two different groups:
UARs and associated user provisioning changes can be performed manually, or they can be automated inside an Identity and Access Management (IAM) solution such as Tello. UARs use documentation from Identity Management systems (logs, alerts, notifications, etc.) to detect and correct user access anomalies and excessive authorities that can lead to security and auditing risks.
User access reviews can also create compliance documentation including audit logs, user & permission reports, access matrices, and customized reports.
Figure 1: Common User Access Review Types
Manual user access reviews are prone to errors and omissions. Manual reviews can be a tedious and time-consuming process, requiring days of work to correlate, correct, verify, and document user access over multiple systems.
Identity and Access Management (IAM) solutions such as Tello automate the user access review process. IAM solutions are integrated with enterprise and SaaS applications, allowing them to query, update, validate, and document user access capabilities.
The first critical user access review best practice is to perform automated user access reviews using an IAM solution adhering to Identity Governance and Administrative standards.
Best practices for user access reviews
To enhance security and achieve compliance, use IAM solutions that incorporate these best practices and capabilities for user access reviews. These practices pre-validate and confirm correct user access provisioning and drive the processes for periodic, event-driven, and continuous reviews.
- Role-based access control (RBAC) and role templates: Add or delete user access through roles and policies rather than by granting access to individual users.
- Rapid provisioning: Quickly add new users with appropriate access permissions across connected apps. Automate user access changes after a user access review completes.
- Instant deprovisioning: Automatically disable user access across all enterprise apps, when a user leaves the organization.
- Comprehensive audit logging for all access provisioning activities: Full audit trails for evidence collection and export.
- Access review by individual user: View which systems, application, and data access permissions users possess across all enterprise, SaaS, and cloud solutions.
- Access review by application: View all users and their access rights by enterprise and SaaS applications.
- Continuous monitoring and alerting: Monitoring and notifications for drift detection, anomaly alerts, orphaned accounts, and access policy violations.
- Compliance & reporting: User and permission reporting; access matrixes for all applications; and customizable reports filtered according to organizational audit and compliance needs.
- Scheduled audit/compliance reporting and delivery: Automated report generation and delivery to audit and compliance personnel.
Learn more about user access reviews
Contact Tello for more information on using innovative tools like Tello to modernize your user access reviews. Tello’s Identity Access Management experts can perform an organization-specific assessment to help modernize your IAM user access provisioning and identity governance compliance and reporting needs.