Loading Events

Who Goes There? Unmasking Identity and Access Management (IAM) in a Spooky Distributed Environment

October 29, 2026 | 1:00 PM - 2:00 PM

October 29 @ 1:00 pm – 2:00 pm EDT


Secure identity and access management (IAM) is critical to protect systems and sensitive information by ensuring that only authorized individuals receive the appropriate level of system access. But do you really know who is lurking in your systems? In a distributed environment, complex role structures and distributed ownership of access controls can make it difficult for IAM audits to identify access risks and evaluate whether access is appropriately governed. Whether you are an experienced IT auditor or dress up like one, this session will equip you with the knowledge to conduct effective IAM audits within distributed environments. We will provide insights into the key components for conducting IAM audits in distributed environments, leading practices and strategies to consider, common challenges to avoid, and a real-world example of an IAM audit conducted within a distributed environment.

After attending this webinar, participants will be able to…

  1. Identify the critical elements of an effective IAM audit within a distributed environment
  2. Recognize common challenges and pitfalls in IAM audits within distributed environments
  3. Explore a practical IAM audit example

Delivery Method: Group Internet
Field of Study: Auditing
Advance Preparation: None
Prerequisites are required: No
Cost: $25 for non-members
Recommended CPEs: 1

Resources

Host Information

Ashley Romero, CISA

Cyber Risk Services Senior Consultant

Baker Tilly

Ashley is a Senior Consultant with Baker Tilly, a national accounting and advisory firm. Her experience includes conducting information technology (IT) and cybersecurity audits, advisory reviews, risk assessments, and IT regulatory compliance assessments (e.g., NSPM-33, HIPAA, NIST). Her clients primarily include higher education institutions, real estate organizations, and research institutions. Ashley is a Certified Information Systems Auditor (CISA) and is involved with the Institute of Internal Auditors (IIA).

Amanda Guessford, CPA, CISA

Cyber Risk Services Manager

Baker Tilly

Amanda Guessford is a Manager, Certified Information Systems Auditor (CISA), and Certified Public Accountant (CPA) with Baker Tilly, a national accounting and advisory firm. She has 8 years of experience providing cybersecurity and IT regulatory compliance assessments (e.g., NSPM-33, CMMC, HIPAA, HITRUST, FISMA, NIST, OMB A-123, IT SOX), risk assessments, internal control reviews, and process reviews to assist organizations in achieving their internal audit objectives and enhance their cybersecurity posture. Her clients have included higher education institutions, not-for-profit organizations, and research institutions. Amanda has presented on multiple occasions for national and regional events hosted by organizations such as ACUA, IIA, and NCURA, including presenting at previous AuditCon events. Additionally, Amanda has presented numerous webinars for both ACUA and Baker Tilly, which can be found on the Baker Tilly website.

Matt Abraham, CISA

Cyber Risk Services Senior Consultant

Baker Tilly

Matt is a Senior Consultant with Baker Tilly, a national accounting and advisory firm. His experience includes providing information technology (IT) and cybersecurity risk advisory, internal audit, internal control solutions, and IT regulatory compliance assessments (e.g., CMMC, NIST, IT SOX) to assist organizations in achieving their internal audit objectives and enhance their cybersecurity posture. His clients have included higher education institutions, research institutions, and not-for-profit organizations. Matt is a Certified Information Systems Auditor (CISA).