ARMI - KN

test

Posts about Netsuite:

Identity and Access Management (IAM) Lifecycle in NetSuite

Identity and Access Management (IAM) Lifecycle in NetSuite

Identity and Access Management (IAM) Lifecycle: How User Provisioning and Deprovisioning Functions in NetSuite

In NetSuite, user provisioning and deprovisioning is managed through the Employee Record, which serves as the central control point for creating accounts, assigning roles or global permissions, and managing access throughout the user’s lifecycle. When a new user is onboarded, their account is created and roles are assigned directly within the Employee Record, while the Manage Roles page is used to customize role definitions / design. Administrators can also grant Global Permissions directly via the Employee Record—a capability that requires careful oversight, as it can bypass role-based controls and introduce privilege creep if not closely monitored.

NetSuite Single Sign-On (SSO) & Identity Management – Security and Control Considerations

NetSuite Single Sign-On (SSO) & Identity Management – Security and Control Considerations

Why Single Sign-On Security Matters

When it comes to securing your NetSuite environment, centralizing authentication is one of the most effective control decisions you can make. Single Sign-On (SSO) security not only streamlines the login process for end users but also allows administrators to enforce consistent password, MFA, and session controls across all systems, ensuring consistent authentication controls are applied. From a compliance standpoint, this centralization pays off—whether you’re preparing SOX evidence, aligning with GDPR, or simplifying audit testing, SSO reduces the number of moving parts and the likelihood of gaps.

NetSuite Password Policy: Strengthening Your Digital Front Door

NetSuite Password Policy: Strengthening Your Digital Front Door

Why A Strong Password Policy Matters

Think of your NetSuite environment like your company’s HQ. If the front door is flimsy, it doesn’t matter how many security cameras or motion sensors you have—someone’s going to stroll in and help themselves to your sensitive data, financial data, or, if the account happens to be privileged, potentially grant themselves keys to the kingdom and wreck mayhem in any way they see fit. That’s why password security isn’t just a “nice to have,” it’s a must-have, especially if you’re subject to SOX compliance. The NIST SP 800-63B guidelines, basically the “how to do passwords right” manual, state the following:

Enforcing Role Separation: IT Provisioning vs Configuration in NetSuite

Enforcing Role Separation: IT Provisioning vs Configuration in NetSuite

Why IT Provisioning and IT Configuration Roles Must Be Separate

In NetSuite, separating access provisioning from system configuration isn’t just about following a segregation of duties checklist—it’s about sharply defining who can do what and ensuring there’s oversight every step of the way. Provisioning rights are limited to a small, approved group who can create, deactivate, and maintain user accounts and role assignments, while configuration rights are given only to those responsible for managing workflows, system settings, and integrations. This separation reduces the risk of accidental configuration changes by provisioning admins, minimizes the number of accounts that could alter key controls, and lowers the probability of critical ITGCs or ITACs being bypassed.

Managing Dormant and Inactive User Accounts

Managing Dormant and Inactive User Accounts

Inactive User Accounts: Security and Compliance Context

Managing dormant and inactive user accounts is a critical component of ERP security and compliance. Frameworks like NIST SP 800-53 and ISO 27001 require periodic reviews of user credentials, and SOX demands timely access revocation for systems impacting financial reporting. The rationale is simple—an unused account is still a potential entry point for an attacker, and the longer it sits unnoticed, the higher the risk it will be exploited.