A medium-sized financial services company recently deployed a new identity governance and administration (IGA) solution to manage user access across on-premises Active Directory and cloud-based SaaS applications. The IGA system uses a role-based access control (RBAC) model with hundreds of roles defined. The company has a policy that all access certifications must be completed quarterly. During the first quarterly certification, the access reviewers complain that they are overwhelmed by the number of entitlements they need to review, and many certifications are not completed on time. The security team also notices that some users have accumulated excessive privileges because role assignments were not properly reviewed. The company wants to streamline the certification process without sacrificing security. Which of the following is the BEST course of action?
Implementing a risk-based certification approach is the most effective strategy for managing extensive entitlement reviews by intelligently prioritizing human effort. High-risk access, such as privileged accounts or access to sensitive data, receives thorough manual scrutiny, ensuring critical security controls are meticulously maintained. Conversely, low-risk, routine access can be efficiently certified through automated processes, significantly reducing reviewer fatigue and operational costs while still meeting compliance requirements for regular access reviews and maintaining overall security.
Why this answer
A risk-based certification approach prioritizes high-risk entitlements for manual review while automating the certification of low-risk access, reducing reviewer fatigue and ensuring critical privileges are scrutinized. This aligns with the principle of 'defense in depth' and addresses the core issue of overwhelming certification volume without compromising security, as low-risk access can be certified based on predefined policies and automated workflows.
Exam trap
The trap here is that candidates may choose option D (automate all certifications) because it seems efficient, but they overlook the critical requirement for human oversight in high-risk access decisions, which is a core principle of identity governance and audit compliance.
How to eliminate wrong answers
Option A is wrong because increasing certification frequency to monthly would exacerbate reviewer overload and likely lead to even more incomplete certifications, as it increases the volume of reviews without addressing the root cause of excessive entitlements. Option B is wrong because eliminating role-based access and assigning permissions directly to users would abandon the RBAC model entirely, leading to a chaotic, unmanageable permission structure that violates the principle of least privilege and increases security risk. Option D is wrong because automating all certifications with scripts that approve access if no violations are detected removes human oversight entirely, which could allow inappropriate access to persist if violations are not detected by the scripts, undermining the certification process's purpose of ensuring proper access governance.