What are Access Reviews?
To put it simple: Access reviews make sure the right people have the right access level to applications.
Background
Companies have to meet the requirements of regulatory standards and compliance frameworks like GDPR, ISO27001, PCI DSS and HIPAA. Regulations may require periodic access reviews to assess who have access, to which systems, and the level of access. In Teisko we approached the problem by talking to our customers, walking through the current processes and tools together. We talked about the key challenges, identified the goods, the bads and the uglies of the current approaches to Access Reviews, and came up with a functional, efficient and easy-to-use formula. Our access reviews are easy of use, with a simple but powerful user interface for both administrators and reviewers.
The simple steps of an Access Review
- Start by registering to Teisko if you haven’t done so already. You can run 3 access reviews for free annually with the Teisko Free plan.
- Choose the app to be reviewed and add the users (read more about how to add users with ease).
- Create a new review for the selected app and define the reviewer of each user.
- Activate the Access Review. The reviewers gets an email with a link to the review Portal. The review Portal is used to review and approve or revoke the access.
- Reviewers log in to the Portal using Microsoft SSO or a one-time password. When the reviewer is finished with reviewing all users assigned to him/her, the reviewer separately confirms that the review is ready.
- When all reviewers have completed their user reviews, the Access Review is automatically set to Finished.
- When the Access Review is in Finished state, the admin can take the actions required to close the Access Review.
- When Closing the Access Review, a PDF-file is generated and attached automatically on the Access Review page.
Some things to keep in mind
- Keep an eye on both human and non-human accounts and don’t forget the shared accounts! In one of our customer environments the requirements included quarterly reviews for human accounts and annual review of the non-human accounts including shared system accounts. With Teisko you can easily select the scope for the access review and select the users on different criterias into the reviews.
- Whenever possible, add the user’s role to ensure the access review is sufficient and the reviewer has all needed information in use.