← Back to GRC Projects

PROJECT 05 / IDENTITY & ACCESS MANAGEMENT

Identity & Access Control Review

A simulated IAM control assessment evaluating user access, privileged accounts, role-based access control, least privilege, terminated-user access, segregation of duties, access certification, and remediation tracking.

REVIEW TYPE User Access Review
POPULATION 125 Accounts
EXCEPTIONS 8
CONTROL RESULT Needs Improvement

01 / EXECUTIVE SUMMARY

Access governance overview.

This simulated assessment reviews identity and access management controls for a fictional enterprise financial application containing sensitive business information.

The objective is to determine whether user access remains appropriate based on job responsibilities, whether privileged permissions are adequately controlled, and whether access changes are completed when users transfer or leave the organization.

A population of 125 fictional accounts was reviewed using simulated HR records, application access exports, role assignments, manager certifications, privileged account listings, and termination records.

Eight exceptions were identified. The most significant issues involved terminated-user access, excessive privileged permissions, conflicting financial roles, and incomplete manager certification evidence.

The overall control conclusion is Needs Improvement because access governance processes exist, but several exceptions indicate that important controls are not operating consistently.

All identities, systems, records, findings, and assessment results in this portfolio project are simulated.

02 / CONTROL OBJECTIVES

What the review tests.

The review focuses on whether access is authorized, appropriate, limited, periodically reviewed, and removed when no longer required.

01

Authorized Access

Verify that accounts and permissions were approved by appropriate personnel.

02

Least Privilege

Determine whether users have only the access required to perform assigned responsibilities.

03

Privileged Access

Verify that elevated permissions are limited, justified, monitored, and periodically reviewed.

04

Segregation of Duties

Identify combinations of permissions that could allow incompatible business activities.

05

Access Removal

Confirm that access is promptly removed when employment or business need ends.

06

Access Certification

Confirm that managers and system owners periodically recertify user permissions.

03 / METHODOLOGY

Review workflow.

01

Define Scope

Identify the application, review period, user population, privileged roles, and control objectives.

02

Obtain Population

Obtain user, role, privilege, employment, and access certification records.

03

Reconcile Records

Compare application accounts against HR and identity records to identify discrepancies.

04

Test Access

Evaluate role appropriateness, privilege, authorization, segregation of duties, and termination status.

05

Validate Exceptions

Confirm identified exceptions with control owners and gather supporting evidence.

06

Report & Remediate

Document findings, assign owners, establish remediation, and track closure.

04 / REVIEW POPULATION

Account population.

Total Accounts 125
Standard Users 108
Privileged 12
Service Accounts 5
Exceptions 8
Exception Rate 6.4%

05 / CONTROL TESTING

Access review results.

Each access governance control was evaluated using simulated evidence from the user population.

Control Population Exceptions Result Risk
Active employees have authorized system access 108 1 Mostly Effective Medium
Terminated-user access is promptly removed 7 2 Needs Improvement High
Privileged access is appropriately assigned 12 2 Needs Improvement High
Conflicting financial duties are restricted 125 1 Needs Improvement High
Quarterly access certification is completed 125 2 Partially Effective Medium

06 / EXCEPTION REGISTER

Identified access exceptions.

ID User Exception Risk Required Action Status
IAM-001 User-017 Terminated account remained enabled after employment ended. High Disable account and investigate offboarding process failure. Open
IAM-002 User-041 Terminated user retained application access beyond required removal timeframe. High Remove access and validate termination workflow. Open
IAM-003 User-063 Administrative role is not supported by current job responsibilities. High Remove unnecessary privileged role and review approval history. Open
IAM-004 User-088 Privileged access lacks documented business justification. Medium Obtain approval or remove privileged permissions. Open
IAM-005 User-094 User can both create and approve financial transactions. High Remove conflicting permission and establish preventive segregation-of-duties control. Open
IAM-006 User-102 Access exceeds requirements of the user's current role. Medium Reduce permissions to approved role baseline. Open
IAM-007 User-111 Manager certification evidence was not retained. Medium Complete certification and retain review evidence. Open
IAM-008 User-119 Quarterly access review was not completed by the required reviewer. Medium Complete overdue review and establish escalation for missed certifications. Open

07 / PRIORITY FINDING

Terminated-user access.

IAM-001

Account Remained Active After Termination

HIGH
CONDITION

Review of simulated HR termination records identified an application account that remained enabled after the user's employment ended.

RISK

Active accounts belonging to former employees increase the possibility of unauthorized access, misuse of credentials, data exposure, and fraudulent activity.

CONTROL AREA

Account Management

SEVERITY

High

CONTROL OWNER

Identity & Access Management

TREATMENT

Mitigate

RECOMMENDED REMEDIATION
  • Immediately disable the terminated user's account.
  • Review authentication and application logs for activity following termination.
  • Validate whether other terminated users retain active access.
  • Integrate HR termination events with identity deprovisioning workflows.
  • Establish escalation for accounts not disabled within the required timeframe.
  • Periodically reconcile active accounts against authoritative employment records.
EXPECTED RESULT TIMELY ACCESS REVOCATION

Automated or tightly coordinated offboarding controls reduce the opportunity for former employees to retain access after the business relationship ends.

08 / SEGREGATION OF DUTIES

Preventing conflicting access.

IAM-005

Conflicting Financial Permissions

HIGH
ACCESS ROLE 1

Transaction Creator

ACCESS ROLE 2

Transaction Approver

CONFLICT

One user can initiate and approve the same type of financial activity.

RISK

Unauthorized or fraudulent transactions could occur without independent approval.

REMEDIATION
  • Remove one of the conflicting roles from the affected user.
  • Establish an approved segregation-of-duties matrix.
  • Prevent incompatible roles from being assigned together where technically possible.
  • Require documented compensating controls when exceptions are necessary.
  • Include SoD conflicts in recurring access certification.

09 / PRIVILEGED ACCESS

Elevated access requires stronger oversight.

01

Business Need

Privileged access should have documented business justification tied to job responsibilities.

02

Approval

Elevated permissions should be approved by appropriate system or business owners.

03

Least Privilege

Administrative permissions should be limited to only what the individual requires.

04

MFA

Strong authentication should protect privileged access wherever supported.

05

Logging

Privileged activity should be logged and monitored for suspicious administrative actions.

06

Recertification

Elevated access should be reviewed regularly and removed when no longer required.

10 / CONTROL MAPPING

Access governance framework mapping.

NIST CSF 2.0 PR.AA

Identity Management, Authentication, and Access Control.

NIST 800-53 AC-2

Account Management.

NIST 800-53 AC-5

Separation of Duties.

NIST 800-53 AC-6

Least Privilege.

NIST 800-53 IA-2

Identification and Authentication.

CIS CONTROLS Control 6

Access Control Management.

11 / REMEDIATION PLAN

Turning findings into action.

Priority Action Owner Target Status
High Disable terminated accounts and investigate offboarding failures. IAM Immediate Open
High Remove unnecessary privileged permissions. IAM / System Owner 7 Days Open
High Resolve segregation-of-duties conflict. Finance / IAM 7 Days Open
Medium Complete overdue access certifications. Managers 14 Days Open
Medium Implement automated HR-to-IAM termination workflow. IAM / HR / IT 60 Days Planned

12 / CONTROL CONCLUSION

Overall control effectiveness.

FINAL ASSESSMENT

Access Governance Needs Improvement

NEEDS IMPROVEMENT
DESIGN

Access management processes, role definitions, approval requirements, and recurring access reviews are established.

OPERATING EFFECTIVENESS

Exceptions involving termination, privileged access, segregation of duties, and certification indicate inconsistent execution.

RISK LEVEL

High

FOLLOW-UP

Retest after remediation completion.

CONCLUSION REMEDIATION REQUIRED

The control environment demonstrates established access governance processes, but identified exceptions require remediation before the control can be considered consistently effective.

13 / GRC TAKEAWAY

What this project demonstrates.

01

Control Testing

Evaluate whether access controls are designed and operating as expected.

02

Evidence Analysis

Compare system access, employment records, approvals, and certifications.

03

Least Privilege

Identify permissions that exceed legitimate business requirements.

04

SoD Analysis

Identify incompatible roles that create fraud or unauthorized-action risk.

05

Finding Management

Document conditions, risks, severity, ownership, and remediation requirements.

06

Control Conclusion

Translate testing results into a clear assessment of control effectiveness.

PROJECT CONCLUSION

Access should match business need.

This project demonstrates how identity and access controls can be assessed through population analysis, evidence review, least-privilege testing, privileged access review, segregation-of-duties analysis, exception management, remediation tracking, and control-effectiveness conclusions.