Review all IT access by manual & automated processes, and then to document, track and manage all IT access.
Implement best secure access management practices such as least privilege or just-in-time access.
Establish IT access role catalogs for internal IT consultants, IT business users and IT vendors.
Establish IT risk access for all IT access role catalogs and follow IT risk process.
Minimize IT access risk where applicable and negotiate least privilege or just-in-time access.
Obtain IT & business owners approvals for prepared IT access role catalogs and IT risk access results.
Periodically share or present IT access role catalogs and IT risk access results to relevant stakeholders.
Perform continuous reviews.
IT Security Governance:
Assist in development of IT security access requirements in IT security policy.
Establish IT security access management procedures for all IT landscape to meet IT security policy requirements for all layers of access including systems, networks, applications, development and others.
Assist in development of RACI, KPIs, KRIs and resulting reports for access.
Compliance and Monitoring: ??????????Periodically perform user access reviews to ensure compliance of all IT access matrix.IT Risk Management:
Establish IT access risk for all role catalogs.
Ensure compliance with IT risk framework.
Support in annual IT access risk assessment with all key stakeholders.
Support in preparing dynamic IT access risk scenarios as per alfanar business requirements.
Dynamically manage IT access risk process with inputs from day-to-day IT business issues, Tech&Ops issues, IT auditors? reports, IT security consultant?s IT security compliance and monitoring reviews.
Support in establishing IT access risk KPIs and KRIs.
Support in establishing IT access risk dashboard for different stakeholder requirements.
Support in establishing IT access risk reports as directed by IT security manager, IT management & ITMB.
Support in establishing providing input for IT access risk results into IT business continuity process.
IT Business Continuity:
Perform impact analysis for providing or removing IT access from users.
Synergies all options for IT access to have timely recovery operations as per BIA.
Assist IT BCP preparation to ensure IT access risk are managed and mitigated during all case scenarios.
Be active stakeholder in IT BCP testing and results discussions.
IT Security Consultancy:??????????Review and provide guidance to GIT teams and business staff for IT access subject.