Presentation is loading. Please wait.

Presentation is loading. Please wait.

Reviewer Training Manual

Similar presentations


Presentation on theme: "Reviewer Training Manual"— Presentation transcript:

1 Reviewer Training Manual

2 Agenda SecureIT Benefits Reviewers Responsibilities Review Phases User Validation Training Modules Definitions

3 SecureIT Benefits Provides a streamlined and automated process for reviewing access, which enables the following: Security of Microsoft’s financial data through least privilege access Time savings for control owners and reviewers through automation of manual processes Increased accuracy due to automated checks, reporting and oversight Reduced manual monitoring efforts Reduced control deficiencies Centralized evidence retention to support audits

4 Reviewers Responsibilities
Kick-off Upload Validate Remove Sign-off Site Admin Start new review Manage Review Close review Control Owners N/A Upload list of users Review system accounts Remove invalid users Complete sign-off Reviewers Review assigned users SCLOs Access Type Site Admin Full control to all Control Owners Assigned workspaces – upload workbook, review users Reviewers Review assigned users SCLOs Assigned workspaces – sign-off only Auditor Read-only to all

5 Review Phases Kickoff Upload Accuracy Sign-Off Validate Remove
Site Admin kicks off the process Control Owner & SCLO sign-off on completion of review Control Owner uploads list of user and notifies Reviewer Completeness and Accuracy Signoff by the CO and SCLO of the uploaded user list Control Owner removes invalid user Reviewers validate access

6 User Validation Overview
As a Reviewer you will receive an from SecureIT when the Control Owner has finished uploading users. Open the link in the which will direct you to the SecureIT VNext. A pop up message may appear if you have users to review in another applications. In the main menu, click the icon on the left to activate the validation page. Select the application you’re wanting to review from the “Select Application” dropdown. Select the user(s) you’re needing to validate by checking the boxes to the left of the grid. For each user, click the blue “ACTION” button to the right and update the status with either “Retain Access”, “Revoke Access”, or “Not Mine”. See definitions slide for explanation. The tool should auto save after every action you select. Optional: Add a business justification to explain the action taken. (Note: The business justification is found under the “ACTION” submenu under “Update Justification”).

7 User Validation Dashboard View
Below diagrams the main options you’ll have as a reviewer. While using this tool, explore these links as there are many new features to help with your review process. Select Review Name Select Application Review Timer Countdown Tenant Selection Expanded Menu Option Dashboard Validate Users Secure IT Support Feedback / Chat with BOT Reports User status graph for the current review. Goal is to complete all pending

8 User Validation View Benefits Progress of App Progress of Total Review
Holistic view of reviews assigned to you Toggle between reviews and applications Saves your preference settings in the tool Validate users with single or bulk feature Export user list to excel or csv Progress of App Progress of Total Review Action Menu Perform user validation Add justification View history of selected user(s) Options Menu Export data Add / Remove Columns

9 User Validation Reviewing Access
Getting To Validate Users Page Visit your Pop up message may appear if you have users to review in another application. Select the application you’re wanting to review from the “Select Application” dropdown. Important Note: If the application you’re looking for is not in the dropdown, your Control Owner hasn’t enable the review. Validate Users Page Select the user(s) you’re needing to validate by checking the boxes on the left of the grid. You can also do a bulk validation by checking more than one boxes. Once ready, click the blue “Action” button to activate your options. Validate the user by selecting one of the following: 1 2 Retain Access - The user still needs access. Revoke Access - The user no longer needs access. Not Mine - The user is listed under the wrong Reviewer and should be reassigned by the Control Owner.  Indicate the appropriate Reviewer by adding details to the “Justification” field.  Please note this field is required for any users marked as “Not Mine.” Quick Tip 1: As a Reviewer, you may be listed on multiple applications to perform the validation review. Please check the “Select Review” and “Select Application” drop-down menus if you are listed in another workspace to fully complete user validation. Quick Tip 2: By default, the tool is set to display 10 users per page. Ensure you validate all users by completing all the pages in your review

10 Definitions Retain Access - The user still needs access
Revoke Access - The user no longer needs access Not Mine - The user is listed under the wrong Reviewer and should be reassigned by the Control Owner Add/Update Justification - The reason for the action taken - this is required for any Not Mine users

11


Download ppt "Reviewer Training Manual"

Similar presentations


Ads by Google