Authorizations Insight for Infor rules
To review or modify Authorizations Insight for Infor rules:
- Select Design > Business Controls > Rule Books on the navigation bar.
- Click the arrow option corresponding to an existing rule book. The details page is displayed.
- Click the arrow option corresponding to a rule on the Rules tab. The details page is displayed.
-
Review this information on the Rule
Details tab.
- Rule Name
- The name of the rule.
- Control Number
- The identification number of the rule. Note: This number can be alpha numeric or numeric.
- Risk Description
- The additional information related to the rule.
- Control Objectives
- The reason for the existence of the rule.
- Control Type
- The type of control based on the rule created. Possible values:
- Security Controls: Authorizations Insight rules to monitor security models.
- Transaction Monitoring Controls: Process Insight rules to monitor business transactions.
- Insight (Maximum 2)
- The name of the Insight for which the rule is created. Select Authorizations Insight for Infor.
- Application (Maximum 2)
- The application for which the rule is created. You can select maximum two applications.
- Rule Type
- The type of the rule.
The basic rule type for the Authorizations Insight for Infor are:
- Sensitive rule
- Conflicts rule Note: To create a Conflict rule, you must select the Sensitive or Conflict rule type and click the Convert to Conflicts Rule option on the Conditions tab.
- Limit rule
- Object
- The Infor GRC business objects for the
creating a condition. The objects displayed are based on the Rule type
selected. Possible values of objects:
- For Sensitive and Conflicts
rule, the objects are:
- Permission
- Role
- For Limit rule, the objects
are:
- Permission
- Role
- User
- For Sensitive and Conflicts
rule, the objects are:
- Status
- The status of the rule.
- Priority
- The priority assigned to the rule.
- Expiry Date
- The date up to which the rule is valid. Note: When selecting an expiry date, select a date in the future. The rule expires on the specified date and is not available for analysis after this date.
- Owners
- The user assigned the role of an Owner for the rule. Click the Look up option to assign Owners for the rule.
- Users
- The user assigned the role of an User for the rule. Click the Look up option to assign Users for the rule.
- Click the Conditions tab to review the conditions created for the rule.
-
Click the Compensating Controls and
Exclusions tab to review this information:
- Compensating Controls: The compensating controls assigned to the rule for mitigating violations. You can assign compensating controls to the rule, using the Assign option.
- Exclusions: The objects that are excluded from the rule. You can exclude objects, using the Add option. See Exclusions.
Note: You can also use this tab to create new compensating controls for assigning to the rule, using the New option. See, Working with compensating controls.The compensating controls assigned to the rule can also be removed using the Remove option.
- Click the Supporting Documentation tab to review the reference documents added to the rule. You can add reference documents from IDM (Infor Document Management), for additional information. Select the document type, specify the document name and click Add. The selected documents are displayed at the bottom of the page. Click the document to view the details
- Click Save to save the rule, if modified.