Recommendation Contents
OIG recommends that the Chief Information Officer (CIO) require system owners to annually revalidate user and administrator accounts, remove those accounts that no longer require access, and certify to the CIO that revalidation has been completed.
