Control Assessment for Logical Access Control to an organization’s HR Management System.
Control deficiency (ineffective): a manual and inconsistent process is enforced when a change in Management Title or Pay occurs in the organization. There are several actions involved to remediate:
Address the short term: assign specific individuals as admins of the HR Management System to restrict access.
Develop and implement a change control process for changes in title or pay that is documented as part of a Standard Operating Procedure.
Configure single sign-on (SSO) access of the procurement system for those designated admin users.
A deficiency in one control - logical access control to HR Process - results in creating 3 findings to move towards remediation.