ITGC – User Access Termination Testing

ITGC – User Access Termination Testing

πŸ”’User Access Deprovisioning

🧭 Planning:
Selected due to risk of orphaned accounts. Pulled 12-month HR termination logs and matched to active system users.

🎯 Objectives:

  • Ensure timely revocation of access

  • Identify residual access after user separation

πŸ“Œ Procedures:

  • Cross-referenced HR terminations with system logs

  • Tested termination to deactivation timing

  • Reviewed account disabling procedures

πŸ“‘ Working Papers:

  • WP-ITGC-UD001: Deprovisioning control test

  • Evidence: HR exit list, AD user status reports

πŸ“Š Findings:

  • ❗ 3 accounts remained active >10 days post-termination

  • ⚠️ Manual tickets not promptly closed

  • ⚠️ No central oversight on deactivation timelines

🧰 Tools Used:
HR termination reports, AD export, Excel, deactivation tracker

βœ… Recommendations:

  • Enforce 24-hour deactivation SLA

  • Auto-disable accounts based on HR triggers

  • Implement reconciliation scripts between HR and AD

Leave a Reply