Security Harmonization and Inheritance Framework Tool
Security Harmonization and Inheritance Framework Tool (SHIFT) Report enables you to transition from copied security classes to the security inheritance model by analyzing configured security classes, creates extended classes from delivered standard templates, designs role migration changes, and commits those changes in a controlled way. By automating the security inheritance process, SHIFT enables you to inherit from delivered standard templates and add custom security configurations through extended classes.
To access Security Harmonization and Inheritance Framework Tool, select from the Security Administration. If the consolidated Security Administration menu is enabled, select .
See Enabling Security Harmonization and Inheritance Framework Tool.
- Security Class Design
- Draft Extended Class
- Draft RoleSecurityClass
- Migration Results
Security Class Design tab
The Security Class Design tab shows your configured security classes and serves as the starting point for analyzing between those classes and analysis class. This tab enables you to identify which securable objects have been customized, review side-by-side LPL comparisons, and generate extended security classes.
- Security Class: Shows a list of all active, non-template imported configured security classes that have no base class.
- Security Extension Class Analysis: Shows the analysis between each security class and its analysis class, such as Included in Extended Class, Exclusion Override, Security Class, Analysis Class, Securable Object Type, Securable Object Name, Condition, Actions, and related override details.
- Compare: Shows a side-by-side LPL comparison between the configured security class and the analysis class. Both LPLs are sorted alphabetically by policy header, and differences are highlighted for consistent comparison.
- Security Class Changes Detail: Shows the details of which securable objects were added, removed, or modified, with the related securable object type, object name, configured access, analysis access, configured conditions, and analysis conditions.
| Action | Description |
|---|---|
| Import Configured Security Classes | Imports all configured security classes with no base class information into the report for analysis. Running this action clears all existing analysis and detail data.
Note: All invalid security class are flagged with a red alert icon, not allowing you to run any actions on it.
|
| Generate Analysis For Security Class | Generates analysis for a single security class. Right-click a security class to analyze and select this action. |
| Generate All Analysis | Generates analysis for all the security class in the list. This action skips both invalid and excluded security classes. |
| Exclude From Analysis |
Excludes the selected security class from analysis when is run. Excluded classes are identified by a purple tag. To include the excluded security class in future analysis, right-click the class and select . |
| Update | Edits the analysis class for the selected security class. You cannot run this action for invalid security classes. |
| Exclude From Extended Class | Excludes the selected securable object from the extended class when generated.
Note: After analysis, securable objects in the Security Class default to Exclusion Override = No (included in generation), and objects found only in the Analysis Class default to Exclusion Override = Yes (excluded from generation). Use to override the default setting.
|
| Include In Extended Class | Includes any excluded securable object from the extended class when generated.
Note: After analysis, securable objects in the Security Class default to Exclusion Override = No (included in generation), and objects found only in the Analysis Class default to Exclusion Override = Yes (excluded from generation). Use to override the default setting.
|
| Override Action | Adds an analysis class object with a custom action policy. |
| Clear Override | Removes a previously applied action override. |
| Override Condition | Overrides the condition for an analysis class securable object with a custom condition. |
| Create Extended Class |
Generates an extended security class containing only the required overrides identified through security class analysis.
When you create an extended security class, select any of these naming options when prompted:
|
| Purge All | Deletes all analysis records. |
| Purge | Deletes the selected analysis record. |
Draft Extended Class tab
The Draft Extended Class tab shows all the extended classes created through the Create Extended Class action on the Security Class Design tab. Records on this tab are read-only, including the names of the extended class, security class, and base class.
| Action | Description |
|---|---|
| Purge All | Deletes all extended security class records. |
| Delete | Deletes the selected extended security class. |
- You cannot delete or purge an extended security class record if it is currently assigned to a role. You must remove the role assignment first to proceed with these actions.
- You cannot create an extended security class with the same name.
Draft RoleSecurityClass tab
The Draft RoleSecurityClass Design tab shows the list of Role Security Class Migration and current Role Security Class list. This tab is used to reassign roles from their current security class to the newly extended security class.
- Role Security Class Migration: Shows a list of role-to-security class mappings for migration. Each row includes these status tags:
- Green tag: Green tag in the Extended Security Class column indicates that an extended security class is assigned for the role.
- Purple tag: Purple Yes tag in the Excluded column indicates that the row is excluded from migration.
- Yellow alert: Indicates that the row must be reviewed.
- Role Security Class List: Shows all current role-security class assignments in the system.
| Action | Description |
|---|---|
| Sync From Role Security Class |
Deletes all existing migration rows and resyncs the Role Security Class Migration list with the current Role Security Class list. The sync process skips only roles with the _ST suffix and imports all other roles. Newly synced rows are marked in the Excluded column by default, enabling you to selectively include rows for migration by running the action. |
| Generate New Security Design | Clears the staging table and migration result, then copies all non-excluded rows into the staging table. |
| Exclude From Design Migration |
Excludes the selected migration row during design migration generation. To include the excluded migration in future generation, right-click the row and select . |
| Replace With Security Class | Replaces the selected security class in the migration list with any security class from the Security Class list. This action also clears the extended class. |
| Replace With Extended Security Class | Replaces the selected security class in the migration list with a different extended security class from the Extended Security Class list. |
| Generate Design For Selected | Adds the selected migration row to the staging table without clearing the existing staged data. |
| Delete | Deletes the selected row from the migration design. |
| Purge All | Deletes all Role Security Class Migration records. |
| Comment | Enables direct editing of the Comment field within each record in the migration list. |
Migration Results tab
The Migration Results tab shows details of the staged migration entries generated from the Draft RoleSecurityClass tab. Use this tab to review migration entries, including the Role, Extended Role, Security Class, Extended Security Class, and Migrated column values, before running the action and to verify the result after migration.
- Green: The migration is created successfully.
- Orange: The migration already exists and is skipped.
- Red: The migration failed.