Regardless of a company’s size, how it manages employee turnover, staff mobility, and increased use of consultants and contractors are causes for concern by auditors in terms of how user access rights are handled.
Whether it’s for a Sarbanes-Oxley Act audit or an IT risk assessment, determining access to a corporate network containing digital assets and intellectual property should be a high priority. More often than not, however, user access gets the attention it needs only after a breach or act of fraud. By implementing some solid user access policies and procedures, companies can minimize their exposure to security breaches.
Auditors should start by asking corporate managers to produce lists of current employees, employees terminated since the start of the year and users who have been denied access; policies and procedures that govern the granting of user access and file-sharing privileges; and the process for granting new access rights when employees move to different positions. They also need to know what review process is in place to verify that each user needs his or her current privileges, as well as the company’s termination procedure.
When checking a random sampling of terminated employees against users who have been denied access, auditors can determine how effective controls are at disabling old accounts. Frequently they find that employees who left a company five years ago still have full privileges, including e-mail, Internet and VPN access, as well as use of company-paid cell phones. Another concern is when employees move up in rank but retain their old access rights, which may allow, for example, an employee to create false vendor accounts or approve payment for his own invoices.
Is the role of auditors simply to audit? That depends on their company, but what makes them more valuable is their ability to address best practices on how to minimize lax user-access privileges. My favorite solution is to create a “passport” that HR assigns to every employee containing that employee’s job description, department, manager, access rights and file-sharing privileges. Ideally, each job description should have a predefined template including this information. As an employee moves vertically or horizontally in the company, the new position should have its own passport, and each employee should be allowed only one passport. This prevents employees from retaining unnecessary access.
HR should have an exit interview with all employees leaving the company to collect keys, pagers and cell phones, and provide legal documents that require signatures. At that time HR should send an e-mail to all groups responsible for terminating benefits and physical, IT and telecom access. Taking action today should minimize the potential for fraud and negative media attention.




