Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

An audit can be considered as a project with a start date and end date. We might want to audit or certify multiple items using an audit. For example, in a Q1 audit you might want to certify, an external partner, identify as well as a member of certain high-risk management roles. These items are specified in one or more recertification policies. As a project might have multiple deliverables an audit can have multiple recertification policies associated with it. We can create recertification policies of different types in the EmpowerID system, and these policies are reusable.

Recertification policies are policies that you add to audits to generate recertification review tasks for the access assignments given to people, roles, groups, and Query-Based collections. Person validity recertification policy is used to certify the person should exist or not. Possible decisions are: certify, disable and delete. We will create a person validity type recertification policy in this post and add a target to itThe person validity recertification is a method of determining whether or not the person is still required. Certain actions must be made if the persons are no longer required. In other words, a person validity recertification policy is to certify whether a person should exist or not.

For the recertification, a recertification policy is created, a recertification audit is created, the recertification policy is added to the audit, then the audit is compiled, which generates business requests that are sent for approval.

In the case of person validity recertification, the recertification engine bundles the recertification items into business requests as per the responsible partyassigned. For any item being recertified where its responsible party is null, it bundles them into one business request as per the fall-back assignee.

The possible decisions for the business requests are generally set as certify, disable or delete. However, these decisions are configurable.

Pre-requisite for recertification policies, audit compilation and fulfilment of business requests.

...