Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

An audit can be considered as a project with a start date and end date. We might want to audit or certify multiple items using an audit. For example, in a Q1 audit you might want to certify, an external partner, identify as well as a member of certain high-risk management roles. These items are specified in one or more recertification policies. As a project might have multiple deliverables an audit can have multiple recertification policies associated with it. We can create recertification policies of different types in the EmpowerID system, and these policies are reusable.

The management role access assignment recertification process validates whether the access granted to a management role is still required for a valid business purpose. Certain actions must be made if access is no longer required. In other words, the management role of access recertification policy is to certify whether access granted should exist or not.

...