Authorizations Insight for Infor rules

To review or modify Authorizations Insight for Infor rules:

  1. Select Design > Business Controls > Rule Books on the navigation bar.
  2. Click the arrow option corresponding to an existing rule book. The details page is displayed.
  3. Click the arrow option corresponding to a rule on the Rules tab. The details page is displayed.
  4. Review this information.
    Rule Name
    The name of the rule.
    Control Number
    The identification number of the rule.
    Note: This number can be alpha numeric or numeric.
    Control Type
    The type of control based on the rule created. Possible values:
    • Security Controls: Authorizations Insight rules to monitor security models.
    • Transaction Monitoring Controls: Process Insight rules to monitor business transactions.
    Insight
    The name of the Insight for which the rule is created. Select Authorizations Insight for Infor.
    Application (Maximum 2)
    The application for which the rule is created. You can select maximum two applications.
    Rule Type
    The type of the rule.

    The basic rule type for the Authorizations Insight for Infor are:

    • Sensitive rule
    • Conflicts rule
      Note: To create a Conflict rule, you must select the Sensitive or Conflict rule type and click the Convert to Conflicts Rule option on the Conditions tab.
    • Limit rule
    Object
    The Infor GRC business objects for the creating a condition. The objects displayed are based on the Rule type selected. Possible values of objects:
    • For Sensitive and Conflicts rule, the objects are:
      • Permission
      • Role
    • For Limit rule, the objects are:
      • Permission
      • Role
      • User
    Status
    The status of the rule.
    Priority
    The priority assigned to the rule.
    Expiry Date
    The date up to which the rule is valid.
    Note: When selecting an expiry date, select a date in the future. The rule expires on the specified date and is not available for analysis after this date.
    Risk Description
    The additional information related to the rule.
    Control Objectives
    The reason for the existence of the rule.
    Documentation
    The documentation for the rule, if any.
    Supporting Documentation
    The reference documents added to the rule. You can add reference documents from IDM (Infor Document Management), for additional information. Select the document type, specify the document name and click Add. The selected documents are displayed at the bottom of the page. Click the document to view the details.
    Owners
    The ownership assigned for the rule. You can assign the role of Users and Owners for the rule.
    Compensating Controls and Exclusions
    You can review this information:
    • The compensating controls assigned to the rule for mitigating violations. You can assign compensating controls to the rule, using the Assign option.
    • The objects that are excluded from the rule. You can exclude objects. See Exclusions.
    Note: You can also use this tab to create new compensating controls for assigning to the rule, using the New option. See, Working with compensating controls.

    The compensating controls assigned to the rule can also be removed using the Remove option.

  5. Click the Conditions tab to review the conditions created for the rule.
  6. Click Save to save the rule, if modified.