Skip to main content

Example: Segregation of duties

A simple example of a certification campaign is where sensitive groups are managed on an Active Directory target system. A product administrator defines SoD rules, and periodically starts a certification campaign to invite group owners to log into Bravura Security Fabric and certify the group members.

The group owner can remove inappropriate group membership. If a user is in violation of an SoD rule (due to having too many group memberships for example) the reviewer can either request an exception or remove group membership in order to resolve the SoD rule violation.

Configuration

To set up this certification campaign, the administrator would:

  1. Log into Bravura Security Fabric as an administrator with the ”Manage certification process” right.

  2. Click Manage certification process.

  3. Click Start entitlement certification campaign .

  4. On the Items to review tab, select Segregation of duties rules, then select the checkbox next to the applicable rule to review.

    3605.png
  5. Click the Reviewers tab to choose reviewers for the campaign.

  6. Click Continue to choose a single reviewer.

  7. Click Select… .

  8. Search for and select the appropriate user.

    3606.png
  9. Click the Submit tab.

  10. Enter a Certification campaign description.

    3607.png
  11. Click Launch campaign.

  12. Click Start new campaign.

    3608.png
Review

To complete the review, the reviewer would:

  1. Log into Bravura Security Fabric .

  2. Click the notification link or Review entitlements and configurations.

    The certification app shows a list of users in violation of the rule.

    3610.png
  3. Click the resolve icon 3611.png next to a user’s name to open the request wizard.

    The default pre-defined request is ”Default resolution for segregation of duties rules”.

    3612.png
  4. Click the request exception icon 3613.png to submit a request to allow the user to keep the conflicting entitlements.

  5. Type a reason for the exception and modify the expiry date if necessary.

    3614.png
  6. Click Apply .

    3615.png
  7. Click Save.

    The request is now saved and will be submitted upon sign off.

  8. Click the resolve icon 3611.png next to another user’s name to open the request wizard.

  9. Click the revoke icon 3616.png to remove one of the conflicting entitlements.

    3617.png
  10. Click Save.

  11. Click Finish to complete the review.

  12. Enter My password.

  13. Click Sign off.

    Bravura Security Fabric notifies relevant authorizers to review the request.