The ever-increasing demand for transparency is causing IT departments to intensify the monitoring of IT permissions.
Many organizations, including the heavily regulated banks and insurance companies, are establishing attestation and recertification procedures in order to achieve and demonstrate compliance with industry and governmental regulations such as Sarbanes Oxley, HIPAA, FERC and Basel III.
This paper explains the concepts of attestation and recertification and then details the levels of sophistication organizations can achieve in their traditional recertification processes. Last, it explains how to implement a modern, role-based attestation and recertification architecture.