Past Roundtable Session

VISO Roundtable Series
for Virginia Information Security Officers

Employee Onboarding

Session Focus

SEC 530 · Security Controls · Access Management

Meeting transcript summary and resources from this VISO Roundtable session.

Session Details

Series
VISO Roundtable Series
Topic
Employee Onboarding
Focus Area
SEC 530 · Security Controls · Access Management
Format
Roundtable Discussion

Meeting Summary

This roundtable focused on employee and contractor onboarding from a cybersecurity and compliance perspective, particularly in relation to SEC 530 controls and requirements. The discussion highlighted lessons learned from streamlining onboarding processes, collecting appropriate compliance artifacts, and managing application access efficiently.

Key Discussion Points

1. Onboarding as a Security Function

Employee onboarding is often viewed primarily as an HR responsibility, but the discussion emphasized that it also plays an important role in information security and compliance. Proper onboarding ensures that employees and contractors receive the appropriate access while meeting organizational security requirements.

2. SEC 530 Compliance & Control Requirements

The team discussed their experience working with SEC 530 controls, including efforts to streamline processes and identify the documentation and artifacts needed to demonstrate compliance.

3. Lessons Learned & Process Improvement

Over approximately the previous year and a half, the team worked on improving onboarding processes and gathering the necessary compliance evidence. The roundtable provided an opportunity to share lessons learned, discuss what worked well, and identify areas where processes could be improved.

4. Application Access Management

A major part of the discussion focused on determining which applications employees should have access to based on their roles and responsibilities.

Instead of manually submitting an access request for every application for every new employee, the team developed a pre-approved application access matrix. This matrix identifies:

  • Available applications
  • Employee positions/roles
  • Applications approved for each position
  • Pre-approved access based on role

This approach reduces repetitive access requests and makes the onboarding process more efficient.

5. Application Access Request Process

The team also discussed situations where a new application is not yet included in the approved application matrix.

For these cases, an Application Access Request process was developed. This process allows users to request access to applications that are not already pre-approved and includes appropriate approval and denial workflows.

Session Outcome

The roundtable was described as productive, with participants contributing questions, experiences, and feedback. The discussion around onboarding and application access generated enough interest that the topic could potentially be extended into a future session to explore additional capabilities and process improvements.

Key Takeaways

  • Employee onboarding should be treated as both an HR and security function.
  • Security controls should be incorporated into the onboarding process from the beginning.
  • Maintaining the right compliance artifacts can simplify SEC 530 control validation.
  • A role-based application access matrix can significantly reduce repetitive access requests.
  • Pre-approved application access improves onboarding efficiency while maintaining appropriate security controls.
  • A formal application access request process is important for applications outside the approved access matrix.
  • Continuous collaboration and feedback can help organizations improve their onboarding and access-management processes.