Previous Topic: Obsolete Digital CertificatesNext Topic: Removing Obsolete Controls


Removing Obsolete User Definitions and Entitlements

We recommend that you use CA Cleanup to identify and remove obsolete items, such as user IDs and security entitlements.

Business Value:

It is common for a site to have obsolete user IDs and security entitlements. Removing these items from the security file helps provide a more secure system by eliminating items that unauthorized users could exploit to gain access to the system or resources.

Additional Considerations:

CA Cleanup provides automated, continuous cleanup of CA Top Secret security files by monitoring security system activity to identify used and unused security definitions. CA Cleanup identifies access unused beyond a specified threshold and generates commands to remove that access. CA Cleanup also identifies and removes unused user IDs and permissions that each user has but does not use.