DPAS SCR: 02099



  • SCR Number
    02099
  • Title
    Access History Inquiry
  • DPAS Module
    Enterprise
  • Reporting Organization
    VSCOS
  • State
    New
  • History
    1/7/2025
  • Description

    Change Request: Process Improvement

     

    Description: DPAS is in need of an inquiry system that provides clear visibility into user access history for both current and past role assignments. This data is essential for IO’s and AIO’s as it helps them verify whether users have the appropriate roles and access levels. Without this information it becomes challenging to assess compliance and ensure that users are not over-privileged or under privileged. Therefore, implementing such a system is crucial for maintaining proper access control.

    The challenge of meeting organization audit requirements significantly affects the ability to conduct a thorough DPAS annual user access review. This situation makes it difficult to ensure that only authorized individuals have access to sensitive information. Additionally, the ongoing monitoring of user access becomes less effective leading to potential security risks. Without proper oversight the organization may struggle to identify unauthorized users or detect unusual activities. As a result maintaining a secure environment becomes increasingly challenging.
    Having clear visibility into data management processes is crucial for DPAS Security and Support personnel. This transparency reduces the need for Database Administrators (DBAs) to run scripts just to collect necessary information for organizations and audit Program Control Boards (PCBs). With easier access to data support teams can respond to user inquiries more quickly and effectively. This improvement not only benefits the users but also helps Information Owners manage their data better. Overall enhancing visibility streamlines operations and increases efficiency across the board.
     

     

    Recommended: Creating an Access History Inquiry is essential for monitoring user permissions. This inquiry will provide clear records of when a user's tier and role access were added or removed. It will display both current and historical information showing the exact date and time of each change. By organizing this data administrators can easily track adjustments and ensure users have the correct access levels. Overall, this tool will help maintain security and accountability within the system.

    Mission Critical: Each year IO/AIO is responsible for conducting a user audit and informing the DPAS PMO once it is completed. Monitoring roles and user access such as ensuring there is a separation of duties and preventing unauthorized access to MAs or warehouses is crucial for every agency. Unfortunately the current system tools used for this task are displaying incomplete information making it difficult to effectively perform these important functions.

    Benefits: By providing an history Inquiry for UIC and Maintenance Activity the IO/AIOs will have a clearer understanding of the UIC and Maintenance activity required for each user. This will help in determining whether these UIC or Mx Activity are essential for the user to effectively utilize the system. Having this history will streamline the process of assigning UIC and Mx Activity  ensuring that each user has the necessary permissions and access rights. This will ultimately lead to a more organized and efficient system for all users involved.

    Frequency: Daily

    Users: Unsure how many Agencies and IO/AIOs are in DPAS, but this will impact all of them.