IAM question - need to define access controls (xbac rules) on a couple of applications, new to the field & do not know head from tail, what would be a good place to start analysis on?
Context: applications with multiple rights/entitlements, already has users at different levels within the company. We are to start by proposing some rules that can be put on identity attributes that'll later be defined with in our chosen system.

like
Posting as :
works at
You are currently posting as works at

Actually a lot of tools like Sailpoint and Saviynt have OOTB rulesets that have SOD violations already defined for common apps like SAP,oracle etc.

like

If you can get the user list with the profile attributes as well as the permissions in the various systems, you can create a matrix to look at common access that exists today. For example, you may see everyone with the Title=“After Market Sales” has access of some sort to the CRM system. You can look at these common privileges and start to define suggestions that anyone with the “After Market Sales” Title gets these baseline permissions. Always go least privilege since it’s better to have someone need to request additional access than let them see/do too much by default. Also, I agree with CD1’s comment. You don’t want someone that can submit payment orders also able to approve payment orders, ABAC should optimally be set up with segregation of duties in mind regardless of how the organization has permissions today.

like

Have you tried reaching out to your engagement manager for guidance? It’s OK not to know if new to the field.

like

Yes I've set up some calls already to brainstorm, & have started proposing some rules myself with information at hand that are logical, but would be great to get insight from people who have previous experience doing it.

like

start with the risks inherent with conflicts, not the tech itself

like

Segregation of Duty conflicts

NIST 800-63

Start by getting an export of job title to entitlement granted

See if there are common entitlements can be grouped at a higher level or department, like ALL USERS, then you can break it down further

Kind of depends on your authentication method. Are we talking SAML or certificate attributes? Or are you authenticating one way and using cloud attributes once authenticated for access authorizations?

Related Posts

like

Real talk- is joining Biogen as a data scientist a smart move, post adu drama and fresh CEO? Afraid that the company will restructure right after I join…

like
like

Capital One Venture or CSR?

like

How job security in Persistent system?
What is the bench period? .Are projects generally short term or long term.?

like

Hi All,

Is legato is asking its employees to work from home or office or hybrid?

Thanks in advance.

How is it working in Beckman Coulter like?

I have an offer with Accenture in hand..and I had confirmed my decision of joining with the recruitment team when they asked again. Now I have got a different offer and thinking to join there. Accenture has been sending onboarding related mails. Should I inform them regarding my change of decision over mail. Will it cause any issue??

Anyone had luck finding a good therapist who actually understands ADHD? Getting advice like "try taking a walk every day" and "practice these breathing exercises" is driving me crazy. I need actual solutions and shit, not just platitudes and internet worksheets.

like
like

I can sense resource cut in coming few month in MasterCard India in non technical profiles. Anyone else feel the same ? Should we be cautious.

likefunny

Is anyone recruiting for a sales development manager/ SDR manager at their company right now. Im based on the UK and would love a recommendation or referral. I have 8 years of sales experience with 4 in tech sales (mainly new business and hunting). Thank you in advance.

I am taking the MA RE salesperson exam soon. Can anyone share their experience- any tips or tricks? Any practice material you would recommend?

like

How do you make small talk with people you don’t really have much in common with? Working with a few people in the team and feel like there’s a wall between us I can’t break 😞

like

Looking for SAP BRIM books/notes

like

“Absolutely no rush on this today—just send it by 6am tomorrow!”

likefunny

Are text message breakups acceptable? Better than complete ghosting right

like

Are there any good networking groups/clubs for young professionals in DC?

like

Has anyone recently done an H1B transfer? How long is it taking on premium processing?

like

Dear Abby- please make it possible to download so that I can take credit for finding and sharing with team.

like

Additional Posts in Cyber Security Bowl

Any tripwire pros here? How did you get started?

like

How long did you guys study for The new cissp exam , and how are the questions like on the exam

like

Would you leave cyber consulting potentially Senior Manager to go work as Senior Customer Success Manager at a tech company ? What are your thoughts?

like

Wonder if anyone can offer advice on which cert to pursue next? I obtained my CompTIA Security+ last year and wondering if I should go for the CySA+ or Pentest+ next. I also have my AWS CCP and will be sitting for the Solutions Architect soon as well. Currently not doing security stuff at work but would love to keep my skills going. I was hoping one of these next certs will help me finally break into a security role and love the idea of pentesting but not sure if the CySA+ is more beneficial.

like

Does anyone know if Focal Point Data Risk is a good place to work at? Their recruiter reached out for a Principal Consultant role and I am wondering if they are a reputed name in the industry.

like

Message me if you need a referral to PwC cybersecurity, financial crimes, or regulations. Please no noobs. Only experienced professionals with at least 1 YOE

likefunny

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

What books would you recommend for someone who is just starting out in security and wants to build strong fundamentals?

funny

Liability not to exceed twice what they paid for the services. If it’s pro bono, 2 x $0 ...

like

Any recommendations for resume revamp?

What would you folks say is the best and most achievable route to take for true Program Manager (minimal tech exp) with Sec+, picking up CISSP, and wanting to get more into the technology? Thoughts?

What cert to go for next? Currently have AWS-SAA and Security+. Thinking about CISSP but how difficult is it compared to the AWS-SAA?

likefunny

What technical interview questions can I expect for a Cloud ISSO position?

like

What do you think is the better option? Both offers are around the same salary (~100k EUR in Denmark).

Solutions Specialist (security) at Microsoft or Manager in digital solutions (security) at MasterCard? Also in respective of the long term career? I have 2.5 YOE

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Would you expense a speeding ticket on your way to an IR?

funnylike

What is the process to get CISSP cert with pwc’s help? I heard that the firm pays for the exam fee and provides stipend for the study material. Anybody have any insight into this?

Anyone here made the switch from IT audit to cyber? How did you get your foot in the door, trying to explore this route.

likehelpful

I have a younger family member (almost 13) who is very interested in cybersecurity. How can this person learn and grow in a safe manner if he/she isn’t near a city with youth clubs and etc? Idea is to reinforce ethics, but this material is far too advanced for the parents.

like

Advice on moving away from being a practitioner and into policy?

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal