首页> 外国专利> Process for removing stale users, accounts and entitlements from a networked computer environment

Process for removing stale users, accounts and entitlements from a networked computer environment

机译:从网络计算机环境中删除过时的用户,帐户和权利的过程

摘要

A method for collecting, presenting to stake-holders, reviewing and cleansing data about users and their entitlements in a networked computer environment, called access certification, is presented. This method begins with automated prompts sent to stake-holders, such as managers or application owners, asking them to review a list of their subordinates or users. Stake-holders are required to either certify or mark for later deletion each user. Next, stake-holders review the detailed security entitlements of each subordinate or user, again either certifying or flagging for deletion each item. Finally, stake-holders are asked to provide an electronic signature, indicating completion of their review process. To motivate stake-holder completion of the process, and to roll-up results across an organization, stake-holders are prevented from completing the signature step until all subordinate stake-holders have likewise completed. The present invention provides a feasible method for identifying and eliminating user accounts that are either no longer needed by their owners, or belong to owners who are no longer legitimate users of an organization's computer systems. The same method is used to identify and eliminate entitlements assigned to users who no longer need them. Removal of such stale, obsolete or incorrect users, login accounts, user objects, group memberships and security, entitlements is essential in order to reduce the security exposure (attack surface) posed by excessive privileges and unused accounts, and to comply with government and other regulations stipulating effective internal controls, especially over financial data, and computer security best practices.
机译:提出了一种在网络计算机环境中收集,呈现给利益相关者,审查和清理有关用户及其权利的数据的方法,称为访问证书。这种方法首先将自动提示发送给利益相关者,例如经理或应用程序所有者,要求他们查看其下属或用户的列表。利益相关者需要证明或标记,以便以后删除每个用户。接下来,利益相关者查看每个下属或用户的详细安全权利,再次确认或标记要删除每个项目。最后,要求利益相关者提供电子签名,以表明他们的审查过程已完成。为了激励利益相关者完成该过程并在整个组织中汇总结果,在所有下级利益相关者同样完成之前,阻止利益相关者完成签名步骤。本发明提供了一种用于识别和消除用户帐户的可行方法,该用户帐户不再由其所有者所需要,或者属于不再是组织计算机系统的合法用户的所有者。使用相同的方法来标识和消除分配给不再需要的用户的权利。删除这些陈旧,过时或不正确的用户,登录帐户,用户对象,组成员身份和安全性,权限是必不可少的,以便减少过多特权和未使用帐户带来的安全风险(攻击面),并遵守政府和其他法规。规定有效的内部控制(尤其是财务数据和计算机安全最佳做法)的法规。

著录项

  • 公开/公告号US2006015930A1

    专利类型

  • 公开/公告日2006-01-19

    原文格式PDF

  • 申请/专利权人 IDAN SHOHAM;

    申请/专利号US20040890902

  • 发明设计人 IDAN SHOHAM;

    申请日2004-07-15

  • 分类号H04L9/32;

  • 国家 US

  • 入库时间 2022-08-21 21:45:04

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号