Body
Purpose
This standard establishes the requirements for authorization, access governance, role management, privileged access, and access lifecycle management for University-managed technology solutions.
The standard ensures access to systems, services, applications, infrastructure, and data is granted, reviewed, modified, and removed according to approved business need, least privilege, and applicable governance requirements.
Scope
This standard applies to:
- Applications
- Cloud services
- Infrastructure platforms
- Databases
- Software-as-a-Service solutions
- Data platforms
- Integration services
- Workforce identities
- Privileged identities
- Application identities
- Automation identities
Authorization Principles
Business Need
Access must be granted only in support of approved University academic, research, operational, or administrative functions.
Least Privilege
Identities shall receive only the permissions required to perform approved business functions.
Separation of Duties
Access models should separate responsibilities where appropriate to reduce operational and security risk.
Role-Based Access Control
Access should be assigned through approved roles, groups, and access models rather than direct assignment to individual identities whenever practical.
Access Management Requirements
Role-Based Access
Systems should implement role-based access control where supported and practical.
Role definitions shall be maintained and aligned to business responsibilities.
Group-Based Assignment
Group-based assignment should be used whenever practical to improve consistency, auditability, and lifecycle management.
Direct Assignment Controls
Direct assignment of permissions to individual identities should be minimized and supported by documented justification when required.
Privileged Access
Privileged access shall be governed through approved administrative access management processes.
Administrative access shall be separated from standard user access whenever practical.
- Administrative roles shall be identifiable.
- Privileged access shall be auditable.
- Privileged access shall be periodically reviewed.
Access Lifecycle Management
Provisioning
Access shall be provisioned through approved onboarding and access management processes.
Modification
Access changes shall align with approved governance and change processes.
Removal
Access shall be removed when business need no longer exists.
Access Reviews
Access reviews shall be performed periodically based on workload classification, data classification, business requirements, and applicable obligations.
Access reviews should evaluate:
- Appropriateness of access
- Role assignments
- Privileged access assignments
- Inactive access
- Orphaned accounts
Auditability
Authorization decisions, role assignments, privileged access activities, and access changes shall be auditable through approved monitoring and logging capabilities.
Workload Classification Alignment
Innovation Workloads
Access controls shall support the approved innovation workload control baseline.
Enterprise Workloads
Access controls shall support the enterprise workload control baseline and applicable data protection requirements.
Regulated Workloads
Access controls shall support enhanced authorization, governance, review, monitoring, auditability, and compliance requirements.
Architecture Review
Authorization models that significantly deviate from approved standards, access governance approaches, or architecture patterns require architecture review before implementation.
Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.