Skip to content
BOL Conferences
Thread Options
#2270765 - 05/23/22 03:25 PM User Access
Irishguy Offline
Platinum Poster
Irishguy
Joined: Aug 2008
Posts: 613
Kentucky
The FFIEC IT Examination Handbook note that User Access Programs should have "timely notification from HR to security administrators to adjust user access based on job changes, including terminations."

How should "timely" be defined? Is "timely" different for a part time teller versus a bank's CFO? If so, what about consistency?

Your thoughts are appreciated!

Return to Top
Audit
#2270769 - 05/23/22 03:44 PM Re: User Access Irishguy
rlcarey Online
10K Club
rlcarey
Joined: Jul 2001
Posts: 83,392
Galveston, TX
Timely, would be a total system lockout no more than 5 minutes after you told someone they were terminated. Not sure why it would be any different for different positions in the case of a termination. Job changes - well that is a different story as they might have to train replacements, etc. and may need to keep old accesses for a transitional period of time.
_________________________
The opinions expressed here should not be construed to be those of my employer: PPDocs.com

Return to Top

Moderator:  Andy_Z