IT Audit Community

 View Only
  • 1.  Identity and Access Management Review

    Posted 02-03-2025 07:25 PM

    We are currently conducting an Identity and Access Management (IAM) Review, focusing on key areas such as Third-Party Access, User Access Management, Access Logging and Monitoring, and Authorization & Authentication. As part of our planning, we are looking to see if anyone has recently completed an audit in any of these areas and would be willing to share insights, best practices, or key takeaways. Any guidance or experiences would be greatly appreciated.



    ------------------------------
    Millicent Mwai | IT Auditor | University of Oregon
    | mmwai@uoregon.edu
    ------------------------------


  • 2.  RE: Identity and Access Management Review

    Posted 02-09-2025 09:43 AM

    Millicent, 

    IAM is huge, and I'm not sure of your detailed scope. Here are some quick thoughts. I assumed your scope is not PAM. 

    1. You have many different types of users (students, staff, faculty, alumni, emeritus, external researchers/participants, potential students, etc.). You may need to break it down according to the type of user. Normally, requirements and processes differ a lot.... 
    2. Central IAM process versus Distributed IT IAM. What is your scope and coverage of IAM within the institution? 
    3. AD group management. AD groups are usually key in IAM. 
    4. Azure/Entra AD Integration 
    5. Link to good practices (CIS Access control 6.1-6.8, Cobit, NIST CSF PR.AA)
    6. Ensure you cover the specific legal access control requirements: 800-171 (3.1, 3.3, etc.), GLBA, FERPA, and the new proposed HIPAA access controls as applicable
    7. Make sure you assess the IAM program. Usually, the root cause. 

    Let me know if you have any questions.

    This is a fun audit with a lot of value.

    See you all in Oklahoma City on March 9th. I will cover Access control as part of my CMMC session. 

    Johan Lidros CISA, CISM, CGEIT, CRISC, CDPSE, HITRUST CCSFP, ITIL-F



    ------------------------------
    Johan Lidros | President | Eminere Group LLC
    (813) 832-6672 | johan.lidros@emineregroup.com
    ------------------------------