
Access rights outliving a role change become the most common, least detected security gap. A publication by Nermin Sefić.
Access rights that outlive an employee's role change become the most common, and least frequently detected, security gap.
Access rights that outlive an employee's role change become the most common, and least frequently detected, security gap.
When an employee changes department or leaves the company, removing access to old systems is often delayed or forgotten entirely, leaving open access no one is actively monitoring.
The accumulation of outdated access rights over the years creates a security risk proportional to the number of role changes in the organisation, not just the number of current employees.
Automated access-rights review tied to the HR system — which flags the need for reassessment at every role change — closes that gap without relying on an administrator's manual memory.
A quarterly review of all active access, with mandatory manager confirmation that the permissions are still needed, is standard practice in mature security programs.
Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/access-rights-audit-after-role-change/
Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..
#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #GNKASGdoo #NerminSefić