Authorized Access
Verify that accounts and permissions were approved by appropriate personnel.
PROJECT 05 / IDENTITY & ACCESS MANAGEMENT
A simulated IAM control assessment evaluating user access, privileged accounts, role-based access control, least privilege, terminated-user access, segregation of duties, access certification, and remediation tracking.
01 / EXECUTIVE SUMMARY
This simulated assessment reviews identity and access management controls for a fictional enterprise financial application containing sensitive business information.
The objective is to determine whether user access remains appropriate based on job responsibilities, whether privileged permissions are adequately controlled, and whether access changes are completed when users transfer or leave the organization.
A population of 125 fictional accounts was reviewed using simulated HR records, application access exports, role assignments, manager certifications, privileged account listings, and termination records.
Eight exceptions were identified. The most significant issues involved terminated-user access, excessive privileged permissions, conflicting financial roles, and incomplete manager certification evidence.
The overall control conclusion is Needs Improvement because access governance processes exist, but several exceptions indicate that important controls are not operating consistently.
All identities, systems, records, findings, and assessment results in this portfolio project are simulated.
02 / CONTROL OBJECTIVES
The review focuses on whether access is authorized, appropriate, limited, periodically reviewed, and removed when no longer required.
Verify that accounts and permissions were approved by appropriate personnel.
Determine whether users have only the access required to perform assigned responsibilities.
Verify that elevated permissions are limited, justified, monitored, and periodically reviewed.
Identify combinations of permissions that could allow incompatible business activities.
Confirm that access is promptly removed when employment or business need ends.
Confirm that managers and system owners periodically recertify user permissions.
03 / METHODOLOGY
Identify the application, review period, user population, privileged roles, and control objectives.
Obtain user, role, privilege, employment, and access certification records.
Compare application accounts against HR and identity records to identify discrepancies.
Evaluate role appropriateness, privilege, authorization, segregation of duties, and termination status.
Confirm identified exceptions with control owners and gather supporting evidence.
Document findings, assign owners, establish remediation, and track closure.
04 / REVIEW POPULATION
05 / CONTROL TESTING
Each access governance control was evaluated using simulated evidence from the user population.
| Control | Population | Exceptions | Result | Risk |
|---|---|---|---|---|
| Active employees have authorized system access | 108 | 1 | Mostly Effective | Medium |
| Terminated-user access is promptly removed | 7 | 2 | Needs Improvement | High |
| Privileged access is appropriately assigned | 12 | 2 | Needs Improvement | High |
| Conflicting financial duties are restricted | 125 | 1 | Needs Improvement | High |
| Quarterly access certification is completed | 125 | 2 | Partially Effective | Medium |
06 / EXCEPTION REGISTER
| ID | User | Exception | Risk | Required Action | Status |
|---|---|---|---|---|---|
| IAM-001 | User-017 | Terminated account remained enabled after employment ended. | High | Disable account and investigate offboarding process failure. | Open |
| IAM-002 | User-041 | Terminated user retained application access beyond required removal timeframe. | High | Remove access and validate termination workflow. | Open |
| IAM-003 | User-063 | Administrative role is not supported by current job responsibilities. | High | Remove unnecessary privileged role and review approval history. | Open |
| IAM-004 | User-088 | Privileged access lacks documented business justification. | Medium | Obtain approval or remove privileged permissions. | Open |
| IAM-005 | User-094 | User can both create and approve financial transactions. | High | Remove conflicting permission and establish preventive segregation-of-duties control. | Open |
| IAM-006 | User-102 | Access exceeds requirements of the user's current role. | Medium | Reduce permissions to approved role baseline. | Open |
| IAM-007 | User-111 | Manager certification evidence was not retained. | Medium | Complete certification and retain review evidence. | Open |
| IAM-008 | User-119 | Quarterly access review was not completed by the required reviewer. | Medium | Complete overdue review and establish escalation for missed certifications. | Open |
07 / PRIORITY FINDING
Review of simulated HR termination records identified an application account that remained enabled after the user's employment ended.
Active accounts belonging to former employees increase the possibility of unauthorized access, misuse of credentials, data exposure, and fraudulent activity.
Account Management
High
Identity & Access Management
Mitigate
Automated or tightly coordinated offboarding controls reduce the opportunity for former employees to retain access after the business relationship ends.
08 / SEGREGATION OF DUTIES
Transaction Creator
Transaction Approver
One user can initiate and approve the same type of financial activity.
Unauthorized or fraudulent transactions could occur without independent approval.
09 / PRIVILEGED ACCESS
Privileged access should have documented business justification tied to job responsibilities.
Elevated permissions should be approved by appropriate system or business owners.
Administrative permissions should be limited to only what the individual requires.
Strong authentication should protect privileged access wherever supported.
Privileged activity should be logged and monitored for suspicious administrative actions.
Elevated access should be reviewed regularly and removed when no longer required.
10 / CONTROL MAPPING
Identity Management, Authentication, and Access Control.
Account Management.
Separation of Duties.
Least Privilege.
Identification and Authentication.
Access Control Management.
11 / REMEDIATION PLAN
| Priority | Action | Owner | Target | Status |
|---|---|---|---|---|
| High | Disable terminated accounts and investigate offboarding failures. | IAM | Immediate | Open |
| High | Remove unnecessary privileged permissions. | IAM / System Owner | 7 Days | Open |
| High | Resolve segregation-of-duties conflict. | Finance / IAM | 7 Days | Open |
| Medium | Complete overdue access certifications. | Managers | 14 Days | Open |
| Medium | Implement automated HR-to-IAM termination workflow. | IAM / HR / IT | 60 Days | Planned |
12 / CONTROL CONCLUSION
Access management processes, role definitions, approval requirements, and recurring access reviews are established.
Exceptions involving termination, privileged access, segregation of duties, and certification indicate inconsistent execution.
High
Retest after remediation completion.
The control environment demonstrates established access governance processes, but identified exceptions require remediation before the control can be considered consistently effective.
13 / GRC TAKEAWAY
Evaluate whether access controls are designed and operating as expected.
Compare system access, employment records, approvals, and certifications.
Identify permissions that exceed legitimate business requirements.
Identify incompatible roles that create fraud or unauthorized-action risk.
Document conditions, risks, severity, ownership, and remediation requirements.
Translate testing results into a clear assessment of control effectiveness.
PROJECT CONCLUSION
This project demonstrates how identity and access controls can be assessed through population analysis, evidence review, least-privilege testing, privileged access review, segregation-of-duties analysis, exception management, remediation tracking, and control-effectiveness conclusions.