IAM Governance and Compliance: - Ensure IAM processes adhere to policies, industry standards, and regulatory requirements.
- Develop and enforce governance policies, procedures, and standards to enhance the IAM program.
- Govern the onboarding of applications to IAM solution by ensuring minimum Security controls are covered in each integration including role matrices, RBAC and access recertification cycles.
Access Management: - Govern and ensure Role-based access controls (RBAC) and Segregation of Duties (SoD) principles are maintained for the access of internal applications and infra items.
- Govern user access review cycles, including access certifications.
- Ensure Privileged access is as per defined process and maintained logs are enough to track any unauthorized activity.
- Review aspects of Multi factor authentication and conditional policies for internal teams.
- Review and work on complete user life cycle management to identify weak areas of access, controls required for implementation and tracking open items.
- Coordinate with internal teams to rectify non-compliant access issues.
Role Management: - Design and maintain role definitions and role-based access control frameworks.
- Analyze and optimize role assignments to ensure appropriate access levels.
Risk Assessment and Mitigation: - Perform risk assessments related to identity and access management.
- Identify and mitigate potential security risks associated with IAM processes and systems.
|