EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
EY SOC reporting teams help companies communicate trust and confidence in the internal control environment around the services they provide to customers.
Read more
When a user leaves a company or changes roles, does their access to company systems update as well? All too often, it’s not the case, and it is harder to manage than it seems.
Effective identity and access management (IAM) policies and procedures help prevent unauthorized access, data breaches and fraud. To achieve this, organizations must monitor all internal and external users — their statuses, roles and access requirements — across the company, while keeping pace with rapidly changing technologies in both large, complex internally hosted and cloud environments.
Periodic review of user access is among the biggest IAM issues for organizations. In a recent informal survey taken during our 13th annual EY System and Organization Controls (SOC) Reporting Virtual Conference, more than half of the respondents identified these reviews as their greatest IAM challenge.
Periodic user access reviews require a comprehensive and accurate inventory of both internal and external user access. All access must be reviewed by appropriate management, with necessary changes implemented as identified. Any instances of unauthorized access should be evaluated to determine whether such access has been used inappropriately.