cancel
Showing results for 
Search instead for 
Did you mean: 

SPM Access Provision CUP

Former Member
0 Kudos

Hi,

When using CUP for Superuser access provisioning, can the risk analysis be configured to identify risks that come by assigning SPM (FF) ID to the Firefighter? When risk analysis is made CUP is not doing combined analysis of access for Firefighter and FF ID. If there are any, only existing risks for the Firefighter are being shown. Risks from the roles assigned to the FF ID are not reported.

Is there any configuration setting that need to be made? Another issue is, even when risk analysis is set to mandatory, approver is able to approve superuser access request with out performing risk analysis. This is looking like a bug. Version 5.3 SP7.

Please help.

R R

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi,

This is know limitation, when risk analyis is perform on the request, CUP consider the role that are there in the request + the roles that are already assigned to the user in the backend system and brings the risks. The risk that may comes to user after assignment of FFID is not considered. Also we have to note that user is not assign the authorization directly they are coming via firefighter application and for which we have the log. like we assign role to FFID than assign FFID to user.

Kind Regards,

Srinivasan