Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The review of user access rights to see if they are proper and correspond to the organization's internal rules and compliance standards is known as access recertification audit. An audit can be considered as a project with a start date and end date. We might want to audit or certify multiple items using an audit. For example, in a Q1 audit we might want to certify, an external partner, identify as well as a member of certain high-risk management roles. These items are specified in one or more recertification policies. EmpowerID maintains an audit trail of these access snapshots and the decisions made concerning the access. EmpowerID recertification audits can be scheduled to run periodically, such as on a quarterly or monthly basis, weekly, daily, or at will.

In EmpowerID, an audit is a logically named user-defined object for identifying or grouping recertification tasks and running the Recertification policies that generate them. After you create creating an audit, you can add one or more Recertification policies to it. Then when the audit runs, it creates a recertification task for each item in the policy.

...

Create an audit

  1. On the navbar, expand Compliance Management and click Audit Configurationand select Recertification.

  2. From On the Audit Configuration Recertification page, click select the Actions Audits tab and then click + icon to Create Audit.

    Image Removed


    Image Added

  3. In the Audit Details form that appears, enter a name, display name and description of the Audit in the Name, Display Name and Description fields, respectively.Under Creation Location, click Select a Location the following information:

    • Name – Name of the audit

    • Display Name – Display name of the audit

    • Creation Location – Click the Select a Location link and then search for and select the desired location

    .
    • Description – Description of the audit

    • Started

    • Select the date you want the audit to start

    .
    • Due Date

    • Select the date the audit

    is due.
    • completes

    • Audit Owner

    • Search for and select the person who is to be the

    owner of the audit.
  4. Select Enabled to enable the audit.

    • audit owner

    • Do No Allow Delete – Select this option if you do not want to allow the audit to be deleted from the EmpowerID UI

    • Enabled – Select to enable the audit to run

    • IsTemplate - Select this option to use this audit as a template for quickly creating other audits.

    Image Added

4. Optionally, enable or disable any of these settings:

  • Is

...

  • Template – Select this option to use this audit as a template for quickly creating other audits.

...

Skip Quality Check For Group Membership — Select this option to allow a managers decision's regarding their direct reports membership in specific groups go directly to fulfillment instead of being sent for approval.

...

Skip Quality Check For Business Role — Select this option to allow a manager's decisions regarding the Business Role assignments of their direct reports to go directly to fulfillment instead of being sent for approval.

...

Skip Quality Check For Management Role — Select this option to allow a manager's decisions regarding the Management Role assignments of their direct reports to go directly to fulfillment instead of being sent for approval.

...

Notify Participant On Audit Creation — Select this option to have EmpowerID send participants a notification as soon as you create the audit.

  • All Participant Notification Email Template — Click in this field and press Enter to see a list of available templates to use for the email notification.

...

Enable Notification — Select this option to have EmpowerID send participants reminder email notifications.

  • Open Task Notification Email Template — Click in this field and press Enter to see a list of available templates to use for the email notification.

  • Notify Open Task Participant After Audit Start In Days — Enter the number of days after the audit start date to send a reminder to any participants with open tasks.

  • Notification Frequency In Days — Enter the number of days to wait to send further reminders to any participants who still have open tasks.

...

Enable Escalation — Select this option to have EmpowerID send an email notification to the managers of participants who still have open tasks.

  • Open Task Escalation Email Template — Click in this field and press Enter to see a list of available templates to use for the email notification.

  • Escalate Open Task Participant Before Audit End In Days — Enter the number of days prior to the audit end date to send the escalation email.

  • Escalation Frequency In Days — Enter the number of days to wait before sending further escalation reminders.

...

Enable Automatic Revocation After Due Date — This setting is only valid for the Person Direct Entitlement policy type.

  • Selecting this checkbox will show another checkbox on the UI named “Enable Audit Creation on Schedule.”

  • Enable Audit Creation On Schedule - You need to select the dates and intervals on the Audit creation schedule and audit duration in days.

    Image Added

5. Click Save.

Insert excerpt
IL:External Stylesheet
IL:External Stylesheet
nopaneltrue

Info

After creating an audit, you need to add at least one Recertification policy to the system to generate recertification tasks.

...

Next Steps

Add Recertification Policy to Audit