1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
How would you define governance in plain terms?
Governance is the set of rules and check-ins that make sure things are being done the right way, similar to household rules where chores get checked and house keys get tracked so everyone knows who's responsible for what.
Why does governance matter for a company's security?
Employees change roles or leave, but their old access doesn't disappear automatically, and leftover, unnecessary access is one of the top causes of data breaches, so governance catches this before it becomes a real problem.
What is a certification, in the SailPoint sense?
A certification is a formal, recorded "yes, this access is still needed" decision made by a responsible person, similar to a library asking you to confirm you still need the books you've borrowed instead of letting them pile up.
Can you walk through the five-step governance lifecycle?
Access Granted, Periodic Review, Certify or Revoke, Audit the Process, and Repeat; access is granted, reviewed on a schedule, a keep-or-remove decision is made, the process itself is audited, and then the cycle repeats.
What is a certification campaign, and what everyday scenario illustrates it?
A campaign is a scheduled, organized project where many certifications happen at once across many people, similar to a building manager doing a periodic room-by-room inventory of keys, asking "do you still need this key?"
What are the four main types of certification campaigns?
Manager Campaign (a manager reviews their direct reports' access), Application Owner Campaign (the system owner reviews everyone with access to it), Role Campaign (confirming a bundled set of access still makes sense), and Entitlement Campaign (focusing on one specific permission).
What is access recertification, and how does it relate to campaigns?
Recertification means re-confirming access that was already granted to check it's still appropriate, happening on a repeating schedule; campaigns are often the organized vehicle that makes recertification actually happen.
How is access recertification different from a new access request?
A new access request is about getting something you don't already have and goes through an approval workflow, while recertification reviews access someone already has and simply results in a keep or remove decision.
What are the possible outcomes when a reviewer evaluates a line item during recertification?
The access is either approved and kept because it's still needed, or revoked and removed because it's no longer needed; some tools also allow delegating the decision to someone who knows the employee's work better.
What typically happens if a recertification deadline is missed?
Reminders escalate automatically to the reviewer's manager, and many companies configure SailPoint to auto-revoke the access if no decision is made by the deadline, treating an unreviewed item as a risk rather than a neutral default.
What is a compliance review, and how does it differ from an individual certification?
A compliance review is a structured check confirming the company as a whole is following outside rules, while a certification asks whether one specific person still needs one specific piece of access; certifications are often the evidence compliance reviews rely on.
What are some common regulations or standards that drive compliance reviews?
SOX (financial reporting controls), HIPAA (patient health information), GDPR (personal data privacy), and PCI DSS (payment card data security).
Can you walk through the general compliance review process?
Identify Requirement, Gather Evidence, Compare to Standard, Report Gaps, and Fix & Re-Check; figuring out which rule applies, collecting proof, comparing practice to the rule, documenting gaps, and then fixing and rechecking, as a repeating cycle.
What is an audit, and what analogy is used to describe it?
An audit is an independent examination confirming that rules, controls, and processes were actually followed, compared to hiring an independent home safety inspector who has no stake in the outcome and reports honestly.
What is the difference between an internal audit and an external audit?
An internal audit is performed by the company's own team, happens more frequently, and focuses on catching problems early; an external audit is performed by an outside firm or regulator, happens on a set schedule, and formally certifies compliance to outsiders.
What is an audit trail, and why is it valuable?
An audit trail is a timestamped record of every governance action, like who reviewed a certification and what decision they made; it's often the single biggest factor in passing an audit smoothly, since it doesn't depend on memory or a saved email.
What is the difference between a "finding" and "remediation" in audit terminology?
A finding is a specific problem an auditor discovered that needs to be fixed, while remediation is the action taken to actually fix that finding.
What is a quality control audit, and how is it different from a regular audit?
A quality control audit checks the quality of certification decisions themselves, not just whether a decision was made, asking whether a reviewer actually looked carefully or just clicked Approve on everything without thinking.
What is "rubber-stamping," and how does a quality control audit help catch it?
Rubber-stamping is approving items without genuinely reviewing them, often flagged when a reviewer approves 100% of items in an unusually short amount of time; quality control audits sample completed certifications to detect and correct this pattern.
What does a quality control audit typically check for, beyond rubber-stamping?
It samples a portion of completed certifications, checks segregation-of-duties conflicts (no one approving access that creates a conflicting combination of powerful permissions), and compares certification decisions against what a person's actual current job requires.