You are on page 1of 6

IDM Access Review for NCB

NCB IDM Access Review


NCB Compliance Management Team
Agenda
 Access Review Introduction
 Certification Use Case
 Prerequisites for Certifications
 Notification
Access Review Introduction
Identity certification is the process of reviewing user entitlements and access-privileges within an
enterprise to ensure that users have not acquired entitlements that they are not authorized to have. It also
involves either approving (certifying) or rejecting (revoking) each access-privilege

Type Description Paradigm


User Certification Allows line-of-business managers to certify User Centric/Business Oriented
employee access to roles, accounts, and
entitlements.

Role Certification Allows role owners to certify role content Privilege-centric / Technical
and/or role members. Also certifies Access-
policies associated with each role

Allows the person who is responsible for a Privilege-centric / Technical


Application Instance particular system or application to review
Certification the set of users who have accounts on that
system or application.

Entitlement Allows entitlement owners to certify user Privilege-centric / Technical


Certification accounts that have a particular privilege
Certification Use Case
Prerequisites for Certifications
 Requestable Catalog Item as “Certifiable”
 Application Instance (EBS, NBL, LOS etc)
 Entitlements (Application end role/job functions)
 Roles

 Defining Certifier in request Catalog


 Reviewer who will certifying the access

 Defining Risk Configuration for Each Entity


 High
 Medium
 Low
Notification
 Email Notification

 Reminders

 Escalation

 Expiry of Certification

You might also like