Who Goes There? Unmasking Identity and Access Management (IAM) in a Spooky Distributed Environment
October 29, 2026 | 1:00 PM - 2:00 PM
October 29 @ 1:00 pm – 2:00 pm EDT
Secure identity and access management (IAM) is critical to protect systems and sensitive information by ensuring that only authorized individuals receive the appropriate level of system access. But do you really know who is lurking in your systems? In a distributed environment, complex role structures and distributed ownership of access controls can make it difficult for IAM audits to identify access risks and evaluate whether access is appropriately governed. Whether you are an experienced IT auditor or dress up like one, this session will equip you with the knowledge to conduct effective IAM audits within distributed environments. We will provide insights into the key components for conducting IAM audits in distributed environments, leading practices and strategies to consider, common challenges to avoid, and a real-world example of an IAM audit conducted within a distributed environment.
After attending this webinar, participants will be able to…
- Identify the critical elements of an effective IAM audit within a distributed environment
- Recognize common challenges and pitfalls in IAM audits within distributed environments
- Explore a practical IAM audit example
Delivery Method: Group Internet
Field of Study: Auditing
Advance Preparation: None
Prerequisites are required: No
Cost: $25 for non-members
Recommended CPEs: 1
Resources
Host Information

Ashley Romero, CISA
Cyber Risk Services Senior Consultant
Baker Tilly
Ashley is a Senior Consultant with Baker Tilly, a national accounting and advisory firm. Her experience includes conducting information technology (IT) and cybersecurity audits, advisory reviews, risk assessments, and IT regulatory compliance assessments (e.g., NSPM-33, HIPAA, NIST). Her clients primarily include higher education institutions, real estate organizations, and research institutions. Ashley is a Certified Information Systems Auditor (CISA) and is involved with the Institute of Internal Auditors (IIA).

Amanda Guessford, CPA, CISA
Cyber Risk Services Manager
Baker Tilly
Amanda Guessford is a Manager, Certified Information Systems Auditor (CISA), and Certified Public Accountant (CPA) with Baker Tilly, a national accounting and advisory firm. She has 8 years of experience providing cybersecurity and IT regulatory compliance assessments (e.g., NSPM-33, CMMC, HIPAA, HITRUST, FISMA, NIST, OMB A-123, IT SOX), risk assessments, internal control reviews, and process reviews to assist organizations in achieving their internal audit objectives and enhance their cybersecurity posture. Her clients have included higher education institutions, not-for-profit organizations, and research institutions. Amanda has presented on multiple occasions for national and regional events hosted by organizations such as ACUA, IIA, and NCURA, including presenting at previous AuditCon events. Additionally, Amanda has presented numerous webinars for both ACUA and Baker Tilly, which can be found on the Baker Tilly website.

Matt Abraham, CISA
Cyber Risk Services Senior Consultant
Baker Tilly
Matt is a Senior Consultant with Baker Tilly, a national accounting and advisory firm. His experience includes providing information technology (IT) and cybersecurity risk advisory, internal audit, internal control solutions, and IT regulatory compliance assessments (e.g., CMMC, NIST, IT SOX) to assist organizations in achieving their internal audit objectives and enhance their cybersecurity posture. His clients have included higher education institutions, research institutions, and not-for-profit organizations. Matt is a Certified Information Systems Auditor (CISA).
