Blog

Enhancement: SOD - Policy Audit Events

Author

  • Colin

    SailPoint

This enhancement is brought to you by Idea GOV-I-3607

Description

We’re introducing SoD audit events that capture when SoD policy definitions are created, updated, or deleted.

Background

Compliance teams utilize Separation of Duty policy to adhere to internal and external regulations that dictate an identity may not have ability to perform two functions. A common example of an SoD policy is ensuring someone cannot both write checks and cash checks. Customers create a SoD policy for toxic access using access items (entitlements).

Current Situation

An auditor may review SoD policies during a quarterly audit to evaluate whether the policy definition aligns with the applicable regulation. For example, the auditor may review cases where ISC detects a violation of the write-check/cash-check SoD policy.

Problem

Audit durations can increase when Compliance teams are unable to easily provide evidence that the write-check/cash-check policy has not materially changed since the last audit.

Solution

Policy Audit events written to SailPoint audit event service for create, update, and delete SOD policy.

SOD Policy Update event

Update SOD Policy event details

Who is affected?

All customers with compliance. All Suites customers.

Important Dates

Sandbox: Feb 12
Production: Week of February 16

Action Required

No action required.

To ask questions and learn more please visit the Developer Community.