22.5.2 User ID deletion
a) User ID to be deleted when:
(i) Employee termination
(ii) Employee changes the department and relocation
(iii) Inactivity of id (dormant id)
b) All user IDs must be temporary suspended or permanently removed from the system after a period of inactivity.
c) User ID after a prolong period of inactivity must be removed from system.
d) Audit trail for user ID access creation, modification and deletion should be maintained in the system
22.5.3 Review of User access rights
a) A formal review of user’s access rights is to be coordinated by IT Security once a year to maintain effective control over access to data and information services.
b) User access matrix must be reviewed and sign off by Line Manager to ensure all access to systems are reviewed by immediate supervisor accordingly.
c) Housekeeping of user access to applications is to be conducted by the IT Security on a regular basis.
d) Access to be review when the staff is promoted or transferred to ensure access is commensurate with the new job role.
22.5.4 Suspension / Disabling of User ID
a) User ID is disabled under the following circumstances applies for all systems:-
(i) Staff under suspension
(ii) Staff taking leave more than a specified period at one time
(iii) Staff on no pay leave / unrecorded leave for a specified period.
(iv) Staff on prolong medical leave for a continuous specified working days
b) On a daily basis, Group HR retrieves a list of staff going on leave for specified working days and submits to IT Security to suspend access.
c) Suspension of user IDs is to be reinstated automatically by IT Security through systems or upon notification from their supervisor via email for exception cases such as adding leave, cancellation of leave