Information Technology Services

The Digital Key Ring: Are You Still Carrying the Right Keys? 

Imagine carrying every key you have ever been given

An office key from a previous building. A key to a room you no longer use. A key from a project that ended months ago. 

At some point, most of us would look at that crowded key ring and ask: Which keys do I still need? 

The same thing can happen in our digital lives. As people join George Mason, change roles, move between departments, or support special projects, they may receive access to new systems and information. Over time, some of those digital “keys” may no longer be needed. 

Identity and Access Management (IAM) Helps Manage the Digital Keys 

Identity and Access Management, commonly called IAM, is the combination of processes and technologies used to manage digital identities and access to systems, applications, and data. In simple terms, IAM helps connect people with the resources they need while protecting resources they should not access. 

IAM supports activities many of us already recognize: creating accounts, signing in, using multifactor authentication, receiving access for a new responsibility, and removing access when it is no longer appropriate. The goal is to provide the right access to the right person at the right time. 

Access Reviews: Checking the Key Ring 

An access review is the digital equivalent of checking the keys on your key ring. A supervisor, system owner, or data steward reviews who can use a system or view information and confirms that each person’s access still matches their current responsibilities. 

A helpful question to ask: 

“If this person started in the role today, would I give them the same access?” 

Regular reviews can help departments: 

  • Confirm that access still fits current responsibilities 
  • Find accounts or permissions that are no longer needed 
  • Reduce the risk of accidental or inappropriate access to university information 
  • Support university security and compliance responsibilities 

Outdated access does not necessarily mean someone made a mistake. It often builds quietly as teams, assignments, and projects change. A periodic review gives us a chance to return the digital keys that no longer belong on the ring. 

Who Should Check the Keys? 

Supervisors can review accounts used by employees, contractors, affiliates, student workers, wage workers, and volunteers they oversee. System owners and data stewards can review access to the systems and information under their responsibility. If access no longer matches a person’s role, it should be updated or removed in a timely manner. 

George Mason’s Information Technology Security Standard recommends periodic reviews of accounts and includes annual review requirements for privileged access to certain systems. Annual reviews are a useful baseline, but changes in employment, assignments, or responsibilities may require a review sooner. 

Keep the Keys You Need 

Access reviews are a small habit with a meaningful security benefit. Adding them to annual planning, staffing changes, and project closeout activities helps keep access aligned with real life without creating unnecessary barriers for teaching, learning, research, or university operations. 

The next time responsibilities change, take a moment to check the digital key ring. Keep the keys that are needed, update the ones that have changed, and return the ones that no longer belong. 

Learn more: George Mason Information Technology Security Standard (ITS-STD003)