1 LOGICAL ACCESS Remedy Management System Training - Health Sciences Center - Click the Speaker Icon for Audio
2Agenda Logical Access: Definitions and ControlsLogical Access: Definitions and Controls WorkflowWorkflow Documentation ProcessDocumentation Process Remedy Screen ShotsRemedy Screen Shots Helpful LinksHelpful Links
3DEFINITONS Logical Access Process by which individuals are permitted to use computer systems and the networks to which these systems are attached. Furthermore, applications and networks, and the services they provide, are available only to those individuals who are entitled to use them.
4CONTROLS LA1 A formalized documented system for user access is established LA2 Full user Account information is documented and retained LA3 Authorized approval and documentation LA4 User access is verified by Process Owners LA5 Segregation of duties analysis LA6 Segregation of duties analysis for administrative users LA7 User password requirements are established and enabled LA8 Application password requirements are established and enabled LA9 Automatic lock-out controls are established and enabled LA10 Documentation and control for Terminations LA11 Monitoring Access Reviews LA12 Auto-Logging established, tracked and reviewed
5 1.BPO approves the completed access forms 2.User completes required training 3.Product Manager reviews forms for completeness and approval, and documents into a Remedy ticket 4.Access is granted and confirmed HIGH LEVEL WORKFLOW Four Step Process
6 ACCESS FORM - Basics User Information Type of Request Access Type with Specific Details Statement of Approval –Accuracy of request –Knowledge of University policies and procedures –Required Training has been addressed –Segregation of duties has been considered Authorized Approver Signature LA CONTROLS 1-6 AND 10 DOCUMENTATION See “Helpful Links” for your specific application
7DOCUMENTATION For New or Change of Access: Attach Request Form (required) Verify and/or attach Confidentiality Agreement Verify User Current Access Notify Hiring Manager/Process Owner For Termination of Access: Attach Request Form or Termination Report (required) Lock/Disable User Account Notify Hiring Manager Product Managers record the following information into Remedy
8DOCUMENTATION 1.Change/Delete Access 1.Change/Delete Access Similar process as a new user request Requires an Access Form Segregation of Duties Analysis for Change Request All Changes recorded in Remedy 2.Termination Requests: submitted prior to users last day 3.Notification to Human Resources prior to users last day Key Points to Remember: LA CONTROLS 10
9REMEDY
10REMEDY
11REMEDY
12REMEDY
13REMEDY
14REMEDY
15REMEDY
16REMEDY
17REMEDY
18REMEDY
19REMEDY
20REMEDY
21REMEDY
22REMEDY
23REMEDY NOTE: The actions in this tab look different on the web version than the desktop client.
24REMEDY
25REMEDY
26 HELPFUL LINKS Banner Products Logical Access Information: IDX Products Logical Access Information: EHR Products Logical Access Information: eRS Products Logical Access Information: Logical Access Change Management Initiative: Refer to Product Manager for all other products