Mayor David D. Ortega, City of Scottsdale | City of Scottsdale website
Mayor David D. Ortega, City of Scottsdale | City of Scottsdale website
The City Auditor’s Office engaged Protiviti to conduct an audit of Identity and Access Management (IAM). IAM encompasses business processes, policies, and technologies designed to manage digital identities, ensuring that users access data only with appropriate credentials. The audit aimed to evaluate the City's IAM processes and controls.
The audit revealed several areas requiring improvement in IAM controls, with priority ratings ranging from critical to low. Two critical priority areas were identified: the excessive number of privileged user accounts and inconsistent implementation of multi-factor authentication across the City. Other non-critical areas for improvement included establishing city-wide policies on user access, enhancing system logging capabilities, improving processes for granting, removing, and modifying access rights, and conducting periodic reviews of such rights.
---