Browse Definitions :
Definition

access governance (AG)

Access governance (AG) is an aspect of information technology (IT) security management that seeks to reduce the risks associated with end users who have unnecessary access privileges. The need for access governance has grown in significance as organizations seek to comply with regulatory compliance mandates and manage risk in a more a strategic manner.

An important goal of access governance is to reduce the cost and effort that’s involved in overseeing and enforcing access policies and management procedures, including recertification. To this effect, access governance software tools can help track access, validate change requests, automate the enforcement of role-based access control (RBAC) or attribute-based access control (ABAC) policies and simplify reporting.

Many access governance software applications combine access control (AC) with identity management capabilities, enforcing a standard set of access rights for business roles while remaining flexible enough to accommodate the needs of super users. Because the software provides transparency, it becomes easier for managers to spot privilege creep and enforce the principle of least privilege (POLP).

In some organizations, the responsibility for access governance is shared by managing members of the organization’s information technology (IT), business and legal teams. Because privileged users continue to serve as a primary vector for security breaches, it’s important for managers to have visibility into access and work together to mitigate risk and decrease the organization’s attack surface. When access governance becomes a cross-departmental effort, the organization becomes better at staying on top of changing regulatory requirements, adhering to internal policies and conducting access reviews on a regular basis. 

This was last updated in October 2016

Continue Reading About access governance (AG)

SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • walled garden

    On the internet, a walled garden is an environment that controls the user's access to network-based content and services.

  • potentially unwanted program (PUP)

    A potentially unwanted program (PUP) is a program that may be unwanted, despite the possibility that users consented to download ...

  • plaintext

    In cryptography, plaintext is usually ordinary readable text before it is encrypted into ciphertext or after it is decrypted.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • Remote Direct Memory Access (RDMA)

    Remote Direct Memory Access (RDMA) is a technology that enables two networked computers to exchange data in main memory without ...

  • storage (computer storage)

    Data storage is the collective methods and technologies that capture and retain digital information on electromagnetic, optical ...

  • storage medium (storage media)

    In computers, a storage medium is a physical device that receives and retains electronic data for applications and users and ...

Close