260 likes | 354 Views
Click the Speaker Icon for Audio. LOGICAL ACCESS Remedy Management System Training - Health Sciences Center -. Logical Access: Definitions and Controls Workflow Documentation Process Remedy Screen Shots Helpful Links. Agenda. Logical Access
E N D
Click the Speaker Icon for Audio LOGICAL ACCESS Remedy Management System Training - Health Sciences Center -
Logical Access: Definitions and Controls Workflow Documentation Process Remedy Screen Shots Helpful Links Agenda
Logical Access Process by which individuals are permitted to use computer systems and the networks to which these systems are attached. Furthermore, applications and networks, and the services they provide, are available only to those individuals who are entitled to use them. DEFINITONS
LA1 A formalized documented system for user access is established LA2 Full user Account information is documented and retained LA3 Authorized approval and documentation LA4 User access is verified by Process Owners LA5 Segregation of duties analysis LA6 Segregation of duties analysis for administrative users LA7 User password requirements are established and enabled LA8 Application password requirements are established and enabled LA9 Automatic lock-out controls are established and enabled LA10 Documentation and control for Terminations LA11 Monitoring Access Reviews LA12 Auto-Logging established, tracked and reviewed CONTROLS
BPO approves the completed access forms User completes required training Product Manager reviews forms for completeness and approval, and documents into a Remedy ticket Access is granted and confirmed HIGH LEVEL WORKFLOW Four Step Process
User Information Type of Request Access Type with Specific Details Statement of Approval Accuracy of request Knowledge of University policies and procedures Required Training has been addressed Segregation of duties has been considered Authorized Approver Signature DOCUMENTATION ACCESS FORM - Basics LA CONTROLS 1-6 AND 10 See “Helpful Links” for your specific application
DOCUMENTATION Product Managers record the following information into Remedy • For New or Change of Access: • Attach Request Form (required) • Verify and/or attach Confidentiality Agreement • Verify User Current Access • Notify Hiring Manager/Process Owner • For Termination of Access: • Attach Request Form or Termination Report (required) • Lock/Disable User Account • Notify Hiring Manager
Change/Delete Access Similar process as a new user request Requires an Access Form Segregation of Duties Analysis for Change Request All Changes recorded in Remedy Termination Requests: submitted prior to users last day Notification to Human Resources prior to users last day DOCUMENTATION LA CONTROLS 10 Key Points to Remember:
REMEDY NOTE: The actions in this tab look different on the web version than the desktop client.
Banner Products Logical Access Information: http://www.slu.edu/services/HR/university_security_forms.html IDX Products Logical Access Information: http://pmoweb.slu.edu/ EHR Products Logical Access Information: http://ehr.slucare.edu/ eRS Products Logical Access Information: http://ers.slu.edu/ Logical Access Change Management Initiative: http://www.slu.edu/x20377.xml HELPFUL LINKS Refer to Product Manager for all other products