Blog
Enhancement: SOD - Policy Audit Events
Author
Colin
SailPoint
This enhancement is brought to you by Idea GOV-I-3607
Description
We’re introducing SoD audit events that capture when SoD policy definitions are created, updated, or deleted.
Background
Compliance teams utilize Separation of Duty policy to adhere to internal and external regulations that dictate an identity may not have ability to perform two functions. A common example of an SoD policy is ensuring someone cannot both write checks and cash checks. Customers create a SoD policy for toxic access using access items (entitlements).
Current Situation
An auditor may review SoD policies during a quarterly audit to evaluate whether the policy definition aligns with the applicable regulation. For example, the auditor may review cases where ISC detects a violation of the write-check/cash-check SoD policy.
Problem
Audit durations can increase when Compliance teams are unable to easily provide evidence that the write-check/cash-check policy has not materially changed since the last audit.
Solution
Policy Audit events written to SailPoint audit event service for create, update, and delete SOD policy.
SOD Policy Update event
Update SOD Policy event details
Who is affected?
All customers with compliance. All Suites customers.
Important Dates
Sandbox: Feb 12
Production: Week of February 16
Action Required
No action required.
To ask questions and learn more please visit the Developer Community.