Auditing Identity and Access Management 2nd Edition

Auditing Identity and Access Management 2nd Edition

This guide provides an overview of Identity and Access Management (IAM), the set of policies, processes, and technologies used to ensure that users have appropriate access to IT systems and resources.

The document focuses on three core IAM objectives:

  • Identity: ensuring that every digital identity can be linked to a specific individual or accountable owner.
  • Authorization: defining and managing user access rights according to job responsibilities and business needs.
  • Authentication: verifying that users are who they claim to be through mechanisms such as passwords, access codes, or biometric controls.

The guide also highlights additional key control areas, including risk-based access management, security event logging, and monitoring of system activities to detect unauthorized or suspicious behavior.

Given the critical importance of protecting information assets, boards and senior management require assurance that IAM controls are properly designed and effectively implemented. The document therefore emphasizes the role of internal audit in assessing the effectiveness of access governance, user provisioning, authentication controls, and monitoring processes to support cybersecurity, compliance, and risk management objectives.

Guida pratica

Riservato ai soci

Auditing Identity and Access Management 2nd Edition

Questo contenuto รจ riservato ai soci.
Per accedere diventa socio oggi o accedi!