Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

User access certification

Subject: User access certification
Date: Mon, 17 Dec 2007 18:25:13 +0200
Hi Folks,

In our company we are currently conducting "user access certification" project.

The purpose of the project is to:
* review user accounts by their direct managers and make sure they
have appropriate access rights and privileges are granted on "least
privilege" principle according to their responsibilities;
* get rid of shared accounts;
* cleanup accounts that belong to people that left the company;

This is one of the SOX requirement and has to be done periodically.
Right now the process is not automated and all information and
evidence exchange are organized simply via email and excel docs which
is very inefficient since we have about 40 business critical systems
and thousands of users.

My question is does anybody use any software packages that automate
the process like id-certify for example for the purpose?

I appreciate your input on this.

White

<Prev in Thread] Current Thread [Next in Thread>