ITSD Computing and Communications Services News
July, 2003
  All Lab Organizations Using Automated Computer Account Closing System

Beginning Friday, August 1, the Laboratory Directorate and Operations staff, along with the Material Sciences, Chemical Sciences, Life Sciences and ALS Divisions, will join the rest of the Lab in using the Termination Notification System (TNS) to close various computers accounts of employees who end their employment at LBNL. The system provides timely closure of accounts, improving cyber security and saving support funds.

All Lab units will now be covered by TNS, a process that started last year with pilot tests in ASD and Computing Sciences, and continued with Earth Sciences when a Lab-wide rollout started in January.

TNS is activated when an employees leaves the Lab, automatically notifying the supervisor of record and the employee, along with one or more contacts contained in a division specific mail list. Accounts are disabled (the password is removed, denying access to the account) two business days after the termination is detected, then deleted 30 business days later. The process uses the Remedy Work Flow system to control the sequence of events and provide an audit trail for account terminations. This is the system used by ITSD for all computer support requests. Supervisors are given an opportunity to request changes using a Web application developed by ISS.

By automatically closing accounts in a timely manner, TNS solves the following problems:

  • Identifying and closing accounts manually is time-consuming and prone to errors.
  • Computer accounts sometimes left open long after an employee leaves can make the Lab vulnerable to cyber attacks.
  • Computer account closure requests are sometimes incorrect -- the person may be leaving one division and moving to another, and not leaving the Lab. The notification system within TNS minimizes this risk.
  • If accounts are left open, divisions are charged for services that are no longer needed.

Finally, with TNS, files left by former employees are either formally archived or deleted, minimizing support costs.