cancel
Showing results for 
Search instead for 
Did you mean: 

Detect obsolete mitigating control assignments?

patrick_weyers
Participant
0 Kudos

Hello,

What report/s would you use to detect obsolete mitigating control assignments?

The scenario is: A user has been assigned a mitigating control, let's say during the CUP workflow, to mitigate a certain risk that came with a certain role. Later, that role is removed from the user. Now the user is in the scope of a mitigating control. However, the user is not even subject to the risk in question anymore.

Which way (periodically?) could you detect these cases and clean up the mitigating control assignments?

Thanks and regards

Patrick

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hey,

My experience of cleaning up controls has not been very straight forward.

I have had to perform various risk analysis reports and look up a list of user accounts that have been marked as "Expired" etc.

It can be slightly more difficult  if, like many organisations, you decide to assign a control with a infinite validity period (i.e. 12.12.9999).

The Business and Internal Control team need to be very proactive about regularly monitoring the controls and reviewing the assignments. This is one reason why I strongly recommend that controls are only assigned for a set period (i.e. 365 days/1 year), so a compulsory review takes place by the control owners/business on a regular basis. This makes the controls much more affective, robust and fit for purpose.

Happy to hear other's opinions and ideas.