Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SailPoint certification cycles: is your control coverage really continuous?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Continuous controls monitoring validates access controls between SailPoint certification cycles, turning point-in-time reviews into a running evidence trail across privileged activity, access changes, and segregation of duties conflicts, according to SafePaaS. The audit issue is not whether access was reviewed, but whether controls stayed effective after the review closed.

NHIMG editorial — based on content published by SafePaaS: continuous controls monitoring and SailPoint certification cycles

Questions worth separating out

Q: How should IAM teams close the gap between access reviews and continuous control assurance?

A: They should treat certifications as snapshots and add a continuous evidence layer for privileged activity, access changes, and SoD conflicts.

Q: Why do periodic access reviews fail as the main governance control?

A: Because they assume access can remain in place until the next review without creating meaningful risk.

Q: What evidence should continuous controls monitoring produce for auditors?

A: It should produce a running trail showing access changes, policy evaluations, privileged activity, remediation actions, and approvals across the full period under test.

Practitioner guidance

  • Map the control gap between certification cycles Inventory where access reviews end and continuous evidence begins, then identify the systems, roles, and SoD rules that are invisible during that gap.
  • Extend monitoring beyond the platform of record Apply the same evidence model to SailPoint-governed and non-SailPoint applications, including ERP and custom business systems, so audit coverage does not vary by application owner.
  • Tie SoD checks to live changes Validate segregation of duties on entitlement changes, configuration updates, and privileged actions as they happen, rather than waiting for a manager certification to surface the conflict.

What's in the full article

SafePaaS's full article covers the operational detail this post intentionally leaves for the source:

  • Detailed monitoring patterns for privileged activity, access changes, and SoD conflicts across identity workflows
  • Implementation guidance for combining SailPoint certifications with continuous evidence collection in adjacent systems
  • Coverage considerations for ERP and business-managed applications that sit outside standard certification cadence
  • Examples of the audit evidence model used to support control effectiveness claims across the full period

👉 Read SafePaaS's analysis of continuous controls monitoring for SailPoint environments →

SailPoint certification cycles: is your control coverage really continuous?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Continuous controls monitoring solves an evidence problem, not an access problem. Periodic certification answers a narrow question: was access appropriate when the reviewer looked at it? Continuous monitoring answers the harder question: did the control remain effective after the review closed? That distinction matters for identity governance because audit findings often arise in the unobserved space between checkpoints. Practitioners should treat continuous controls monitoring as the missing period coverage layer in the control stack.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to the same study.

A question worth separating out:

Q: How can teams tell whether observability is improving identity governance?

A: Teams can tell observability is improving governance when it changes decisions, not just dashboards. Look for fewer unknown access paths, faster investigation of anomalous identity actions, and better prioritisation of recertification and privilege cleanup. If visibility does not change remediation, it is only producing more telemetry.

👉 Read our full editorial: Continuous controls monitoring closes the gap between SailPoint reviews



   
ReplyQuote
Share: