cancel
Showing results for 
Search instead for 
Did you mean: 

Risk Analysis/SOD check in Identity Management

Former Member
0 Kudos

Hi IDM gurus,

Can IDM do SOD check on its own (without GRC integration) using its own simple rule set?

Thank you,

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

I shall wait for few more answers.

Former Member
0 Kudos

Hi Saayi,

There is functionality at the Role level for this. The "Mutual Exclusions" tab can be used to prevent the users of one role from having another role -- i.e. a Buyer cannot also be an Approver, for example. Not nearly the functionality of GRC, but it could be used for many scenarios.

Best Regards,

Matt

Former Member
0 Kudos

Hi

I think you can, but this is not a standard feature and will consume a HUGE amount of worktime and brainwork

I think you will need to create a SoD table in your database which contains all unwanted relations between your Roles & Privileges MSKEYS (ideally). On the other hand I think the standard SoD contains mappings between TCodes and/or activities which are not available in IdM.

In your IC you could create a conditional task with a custom SQL-query that returns if the (any?) combination of current role/ auto-role/ privilege/ auto-privilege assignments and the desired role /... is contained in that table and reacts on the outcome.

But I can only imagine that this solution will be really complex (a custom-built GRC) and error-prone - and still without Compliance or any audit-data.

Maybe there are other solutions... or it might be (in the long-term) cheaper (and safer) to license GRC?!

BR

Michael

Former Member
0 Kudos

Thank You.

The client is not obliged for any regulatory compliance.

They have their own access controls ( 16-20).

A solution for the workflow with SOD check against these limited controls is required.

Rgds.