Corrective Actions:
A. Perform Timely Access Revocation and Strengthen User Access Reviews
‐ The District implemented a new automated solution to terminate SSO and PS SIS access. This was implemented October 2024.
‐ The District’s plan is, upon implementation of the automated solution to deprovision...
Corrective Actions:
A. Perform Timely Access Revocation and Strengthen User Access Reviews
‐ The District implemented a new automated solution to terminate SSO and PS SIS access. This was implemented October 2024.
‐ The District’s plan is, upon implementation of the automated solution to deprovision SSO and PS SIS access, our team is planning on performing annual user access for SSO and PS SIS reviews beginning Q1 2025. The District is also implementing Pathlock that will introduce user access
reviews.
‐ For SAP access revocation the SAP Team is looking into options to deprovision users and audit user access through internal or third-party tools. The District anticipates selection of the tools by June 30, 2025. Upon implementation of the selected SAP tools the District will perform periodic access reviews for regular users.
Personnel responsible for Implementation:
Carmen V. Lidz, Vice Chancellor & Chief Information Office
Expected Date of Implementation:
June 30, 2025
B. Maintain and Review Logs of Users' Activity for both SAP and PS SIS
‐ Upon implementation of Pathlock, the District will perform periodic access reviews for regular users.
‐ Upon implementation of the selected SAP tools, the District will perform periodic access reviews for regular users.
Personnel responsible for Implementation:
Carmen V. Lidz, Vice Chancellor & Chief Information Office
Expected Date of Implementation:
June 30, 2025
C. Implement Data-at-Rest encryption for SAP and PS SIS Servers
‐ The District is in the process of upgrading PS SIS PeopleTools after which we will determine the most expedient path to implementing database encryption. The target completion for the PS SIS database encryption is Q3 of 2025
‐ The District is currently evaluating the feasibility of adding the encryption of the SAP database to the HANA upgrade project. If the District determines that it’s not feasible, we will engage a third party to encrypt the SAP database. The target completion for the SAP database encryption is Q3 of 2025.
Personnel responsible for Implementation:
Carmen V. Lidz, Vice Chancellor & Chief Information Office
Expected Date of Implementation:
Q3 of 2025