Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 9236

Re: Role Owner Defination

$
0
0

Amir shah wrote:

 

Hi Madhu and Prasant  ,

 

Thank you on your feedback , i going to propose to have a Shared User ID and Group e-mail for the 1st approver

Amir,

Yikes. A shared user ID as role approver?? What kind of audit trail does that provide? When the auditors show up to ask, "who approved that user for that inappropriate role," you have no accountability, because anyone with access to that shared account could have done it.

What kind of auditor signed off on shared IDs in the first place? That is a very poor control.

Please tell me you will reconsider.

 

Gretchen


Viewing all articles
Browse latest Browse all 9236

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>