Friday, May 8, 2009

Group Management and Auditing

Welcome to my blog. As the managing director of Tools4ever Inc., I have involvement at some level with virtually every prospect and client that we have in the eastern half of the United States. Over time, I will endeavor to explain some of our clients unique situations and how were able to assist. To protect our clients and confidential information, I will not disclose the companies’ names. Feel free to contact me via this blog to learn more.
The first situation I would like to discuss involves a medium-sized financial institution located in the northeast. When they approached us, they were in need of a web-based system for group management compliance auditing. Every 90 days, they required managers to sign off a paper report indicating the members of distribution and security groups they managed were accurate. Obviously, the shortfalls were many. When the paper was returned, IT admins need to go into Active Directory and make edits as required. Other times managers simply ignored the paper work leaving potential security breaches.
After a thorough analysis of the requirements, we presented a solution that delivered what the client was looking for and also provided suggestions on how to expand the use of the product. A decision to move ahead was made by the client and we set about delivering a proof of concept, at no risk, to prove the capabilities.
In the end, the client was satisfied with the proof of concept and purchased the solution. Basically, the end result provided the following:
For Managers
  1. Automated email notification to managers that a review of their groups was pending.
  2. A website to allow managers to view all of their groups and the members thereof.
  3. The ability to add / remove individuals from each group as appropriate.
  4. The ability to electronically sign off on the accuracy.
For IT
  1. Consolidated reporting on who has/ has not verified the groups
  2. Automatic escalation procedure when a review has not occurred within a defined timeframe. (15, 30 and 60 days)
  3. A portal to provide easy modification of group ownership when a manger departed.
  4. Ability to maintain white lists of groups that should never need verification.
For all employees
  1. An easy method to view what groups they belong to.
  2. Ability to request membership in other groups (requires managerial / IT approval)
In the end, we were able to implement a web-based solution for this client in approximately 40 hours of remote consulting services. Thorough testing in their environment and modifications to the original scope resulted in another 10 hours of work. The client now has a fully automated solution to time consuming issue and can generate audit reports on demand. The project was delivered on time and under budget