Educause Security Discussion mailing list archives

Re: Standard operations question


From: Frank Barton <bartonf () HUSSON EDU>
Date: Thu, 21 Feb 2019 15:20:10 -0500

Jared, I think this falls under the "Trust, but verify" category. At the
end of the day, the business unit that engaged the services is responsible
for the account(s) and service(s), however, it would behoove the datacenter
operations team to periodically proactively check with the business unit in
question to make sure that it is still active on their end, and that it
didn't just drop off their radar.

Possibly to the point of having the account automatically expire, and
require a proactive "hey, please keep the account active for another
quarter/6-months/etc." on a regular basis.

Frank

On Thu, Feb 21, 2019 at 3:16 PM Jared Evans <jared.evans () gallaudet edu>
wrote:

Thanks for your responses. I apologize if my question wasn't clear
enough.  My question was geared towards who would be responsible for
periodically re-validate the continued need for the account, if it has not
been deactivated by our automated process for accounts flagged for
expiration or termination.  I agree that this responsibility falls on the
system owner and wanted to check in with this group to make sure I'm not
missing anything else.



-- 
Frank Barton, MBA
Security+, ACMT, MCP
IT Systems Administrator
Husson University

Current thread: