Edit SOD Rule Page
Use the Edit SOD Rule page to define new rules for separation of duty polices or edit existing rules. Rules are used to monitor roles or entitlements for conflicts of interest. This enables you to identify high-risk employees and take the appropriate action as needed.
To create or edit a policy, see Working with Policies.
For an overview of developing and using rules in IdentityIQ, see Rules and Scripts in IdentityIQ.
To access the Edit SOD Rule Page, navigate to Setup > Policies, select the SOD Policy you want to edit, then scroll down to the bottom of the page. Select an existing rule from the table, or click Create New Rule. The following information is displayed on an Edit SOD Rule page:
Field Name |
Description |
Summary |
A brief summary of this rule. This information is displayed in the Rules column of the Rules table on the Edit Policy page. |
Description |
A brief description of the rule. |
Policy Violation Owner |
The person responsible for taking action on the policy violations. This can be a specific identity, the manager of the user in violation of the policy, or someone selected according to a rule. You can also assign owners to each individual rule that makes up the policy. If you assign an owner at the rule level, it overrides the policy-level violation owner. Note: Click the [...] icon to launch the Rule Editor to make changes to your rules if needed. If the notification option is enabled, only the owner receives a work item, the observers only receive email notifications. |
Violation formatting rule |
A violation formatting rule adds extra information to a policy violation, like an extra description, or the relevant applications that contain attributes that contributed to the violation. If you want to use a rule to control violation formatting, select a violation rule from the dropdown list. Violation formatting rules are defined when your system is configured. Note: Click the [...] icon to launch the Rule Editor to make changes to your rules if needed. |
Violation business process |
Business processes can be used to define how violation work items are assigned, or how to handle the violation based on decision made on the work item. If you want to use a business process for the violation, select the business process from the dropdown list. A business process specified here for the entire policy will be overwritten by any business process that is specified as part of a policy rule on the Edit Rule pages. |
Disabled |
Enable or disable the rule |
Compensating Control |
A description of exceptions or compensating factors that apply to this rule. For example, certain policies or rules might not apply to users at the executive level in your organization. This field is for documentation purposes only. Information entered here does not impact risk scoring associated with this rule or the reporting of policy violations. |
Correction Advice |
Text entered in this field is displayed if a violation of this policy appears on a certification request and is selected for revocation. Use this field to enter information that can be used by a certifier to make the correct revocation decision. |
Role SOD Rules: |
|
Any of these roles/entitlements |
The lists of conflicting roles that define this rule. If an identity is assigned ANY of the roles from the Any of these table and ANY of the roles from the conflict with any of these table, they are in violation of this rule and their risk score card reflects that violation. |
conflict with any of these roles/entitlements |
|
Entitlement SOD Rule: |
|
First Entitlement Set |
The list of conflicting entitlements that define this rule. |
Second Entitlement Set |
|
Effective Entitlement SOD Rule: |
|
First Entitlement Set |
The list of conflicting entitlements that define this rule. |
Second Entitlement Set |
|
Run or View Simulation |
Use the simulation option to simulate the policy rule before you make it active in your production environment. Before testing the rule, make sure the names of rules are unique in a policy. When you run a simulation for a single rule, only the rule is disabled. The state of the policy is NOT changed. When you run a simulation for all the enabled rules in a policy, the state of the policy is changed to inactive. To activate the policy, you must change the state to Active and save the changes to the policy. |