As a security administrator, use security requests to register any required changes in the security setup. In Security and compliance studio, you can create security requests from the Security management workspace.
For each security request type, a different type-specific section is added to the Security request page. In this section, fill in or add the required type-specific information.
This table shows the available security request types, for each type the related section, and a description of what to do in this section (see step 9):
Type | Type-specific section | Description |
---|---|---|
General | - | Request a security configuration change that is not related to any of the types. |
Create user | Create users | Request the creation of a user.
You can set the From date and To date fields to define the period when the user must be active. When approved, the user is created but is only active in the defined period. Once the defined period is over, the user is automatically deactivated. |
Assign role to user | Assign roles to user | Request to add one or more roles to an existing user. To each role, assign the companies in which the user has the role. You can assign:
You can set the From date and To date fields to define the period when the role must be assigned to the user. When approved, the role is only assigned in the defined period. Once the defined period is over, the role is automatically removed. |
Remove role from user | Remove roles from user | Request to remove one or more roles from an existing user. You can set the From date and To date fields to define the period when the role must be removed from the user. When approved, the role is only removed in the defined period. Once the defined period is over, the role is automatically re-assigned. |
Disable user | Disable users | Request to disable one or more existing users. You can set the From date and To date fields to define the period when the user must be disabled. When approved, the user is only disabled in the defined period. Once the defined period is over, the user is automatically re-enabled. |
Enable user | Enable users | Request to enable one or more existing users. You can set the From date and To date fields to define the period when the user must be enabled. When approved, the user is only enabled in the defined period. Once the defined period is over, the user is automatically disabled. |
Delete user | Delete users | Request to delete one or more existing users. |
Create role | Create role | Request to create a role. Use a security scenario to indicate all securable objects and related access levels that are required for the role to perform one or more tasks. You can select an existing scenario or upload a task recording that defines the scenario. |
Modify role | Modify role | Request to modify one or more roles. For each role, you can use a security scenario to indicate all securable objects and related access levels that are required for the role to perform one or more tasks. You can select an existing scenario or upload a task recording that defines the scenario. |
Lock role | Lock roles | Request to lock one or more roles. |
Unlock role | Unlock roles | Request to unlock one or more roles. |
Delete role | Delete role | Request to delete one or more roles. |
Create rule | Enhanced SoD rules | Request to create one or more enhanced segregation of duties rules. |
Resolve conflict | Enhanced SoD conflicts | Request to solve one or more enhanced segregation of duties conflicts. |
Delete rule | Delete enhanced SoD rule | Request to delete one or more enhanced segregation of duties rules. |
Add stand-in | Create stand-in | Request to appoint a stand-in for one or more users for a specified period. You can request a stand-in for yourself or for another user. You can select which roles to assign to a stand-in user instead of automatically assigning all roles of the primary user. You can assign specific roles to limit security risks and only assign the necessary roles to the stand-in user. In the Create stand-in section, click Assign roles, and choose which of the primary user’s roles to assign to the stand-in user. You can only select roles that are not yet assigned to the stand-in. |
Cancel stand-in | Remove stand-in | Request to remove a stand-in appointment for one or more users for a specified period. You can request to cancel a stand-in for yourself or for another user. |
Create business risk | Create business risk | Request to add an operational risk for your company. You can link the risk to enhanced segregation of duties rules. |
1. | Click Security management. |
2. | On the Requests tab, click New. |
3. | In the Request field, type a value. |
  |
Note: The Request ID is usually generated from the number sequence set in the Security and compliance studio parameters. If no number sequence is set, you must manually enter the Request ID. After saving, you cannot edit the Request ID. |
4. | In the Type field, select an option. |
5. | For informational purposes, define where the security request originates from. |
  | In the Origin field, select an option. |
6. | For informational purposes, you can define the security area to which the security request applies. |
  | In the Area field, enter or select a value. |
7. | Expand the Status section. |
8. | In the Priority field, select an option. |
9. | For each security request type, a different type-specific section is added to the Security request page. For more information, refer to the table in the topic description. |
  | In the type-specific section, fill in or add the required information. |
  |
Note: For type 'General', no type-specific section is added. |
10. | In the Description section, enter a description of the security request. |
11. | Sub-task: Define applicable period. |
11.1 | You can optionally fill in the Start date and End date. These dates define the period to which the security request applies. For example, the period during which a stand-in is required. |
  | Expand the Details section. |
11.2 | In the Start date field, enter a date. |
11.3 | In the End date field, enter a date. |
11.4 | For informational purposes, you can define an external reference to which the security request is related. |
  | In the External reference field, type a value. |
12. | Close the page. |
The Implement approved security requests batch job undoes the change on the To date.
Note: The Implement approved security requests batch job is configured and started automatically when you install Security and Compliance Studio.
Related to | Notes |
---|---|
Manage security requests |
  |