What Is Access Certification?

Identity and Access Management (IAM) plays a critical role in securing an organization’s IT infrastructure and sensitive data. Access Certification, an important component of IAM, refers to the process of regularly reviewing the permissions and roles users hold. In this post, we’ll look at what Access Certification is and how you can implement it at your company.

What Is Access Certification?

Access Certification is a review process set up to confirm the correctness of access rights and remove unnecessary permissions. The main goals of this process are:

Access Certification is carried out within the company by both managers and the relevant permission owners, and it ensures that what permissions and roles users actually need is clearly determined.

How Is an Access Review Performed?

To better understand an Access Certification process, let’s walk through this scenario:

Many of these employees will have gone through various organizational changes over the course of their careers. As a result, there will definitely be cases where certain permissions are no longer used, or employees shouldn’t hold them at all. The access review process addresses exactly this problem.

The key steps followed in the process are:

  1. Collecting User and Permission Data: The IAM system reports the current permissions and roles of users to all managers in the company via a dashboard.

  2. Manager Review: Each manager analyzes the permissions of the employees on their team and decides which permissions are necessary and which are not. They either approve the permissions or flag them for removal.

  3. At the end of the process, depending on how the IAM team has configured things, permissions or roles may be removed from employees directly, or — depending on the setup — the permission matrix is automatically updated with flagged items after review by the Information Security team.

  4. Applying Updates: Unnecessary permissions are removed or adjusted through the IAM system.

Alignment with the Zero-Trust Model

Access Certification aligns perfectly with the logic of the Zero-Trust security model. Zero-Trust is built on the principle of “never trust, always verify.” This model requires that all access held by employees be continuously verified, and that only the permissions actually needed are granted.

The Access Certification process:

Entitlement Owner: A Second Layer of Control

To make Access Certification even more effective, you can introduce the concept of an Entitlement Owner at your company.

The entitlement owner, by better understanding the purpose and criticality of the role within the company, decides who the relevant permission should actually be granted to.

This model adds a two-layer control system on top of the review performed by the manager.

Throughout the user lifecycle, many permissions, roles, or access rights get requested. Access Certification ensures that these access grants are reviewed regularly, creating a structure aligned with the need-to-know and need-to-access principles. A thorough review conducted once a year:

By putting this process in place at your company, you can take your IAM strategy a step further and build a security infrastructure aligned with the Zero-Trust model.

I’ve also written about this topic before, and the following posts may be useful for going deeper into the subject.

Review Process for Permission and Role Owners

Permission Review Efforts in Identity and Access Management

User Permission Review Reporting (Dashboard)

server screenshot