Recertification (Dictionary Entry)

Context

IAM

Term

Recertification

Synonyms

Review and Certify

Definitions

A process and detective control that validates the appropriateness of user access to applications, systems, and information.

It consists in determining who is responsible and has authority for reviewing and certifying which access rights and roles, routing a recertification request to that person, having that person process the request which consists in reviewing the access rights and roles and confirming that they are appropriate for the individual’s current responsibilities, and revoking all access rights and roles that are found inappropriate.

Recertification is one activity that participates to the management of identities throughout their lifecycle. After initial provisioning, the identity responsibilities, the organization and its environment continuously evolve making it necessary to realign the identity access rights and roles to present requirements.

The goals of recertification are:

  • to mitigate risks linked to the use or abuse of inappropriate access rights and roles,

  • to assure and demonstrate compliance.

Sources

See Also

 


Follow us on LinkedIn | Discuss on Slack | Support us with Patreon | Sign-up for a free membership.


This wiki is owned by Open Measure, a non-profit association. The original content we publish is licensed under a Creative Commons Attribution 4.0 International License.