IAM question - need to define access controls (xbac rules) on a couple of applications, new to the field & do not know head from tail, what would be a good place to start analysis on?
Context: applications with multiple rights/entitlements, already has users at different levels within the company. We are to start by proposing some rules that can be put on identity attributes that'll later be defined with in our chosen system.

like
Posting as :
works at
You are currently posting as works at

Actually a lot of tools like Sailpoint and Saviynt have OOTB rulesets that have SOD violations already defined for common apps like SAP,oracle etc.

like

If you can get the user list with the profile attributes as well as the permissions in the various systems, you can create a matrix to look at common access that exists today. For example, you may see everyone with the Title=“After Market Sales” has access of some sort to the CRM system. You can look at these common privileges and start to define suggestions that anyone with the “After Market Sales” Title gets these baseline permissions. Always go least privilege since it’s better to have someone need to request additional access than let them see/do too much by default. Also, I agree with CD1’s comment. You don’t want someone that can submit payment orders also able to approve payment orders, ABAC should optimally be set up with segregation of duties in mind regardless of how the organization has permissions today.

like

Have you tried reaching out to your engagement manager for guidance? It’s OK not to know if new to the field.

like

Yes I've set up some calls already to brainstorm, & have started proposing some rules myself with information at hand that are logical, but would be great to get insight from people who have previous experience doing it.

like

start with the risks inherent with conflicts, not the tech itself

like

Segregation of Duty conflicts

NIST 800-63

Start by getting an export of job title to entitlement granted

See if there are common entitlements can be grouped at a higher level or department, like ALL USERS, then you can break it down further

Kind of depends on your authentication method. Are we talking SAML or certificate attributes? Or are you authenticating one way and using cloud attributes once authenticated for access authorizations?

Related Posts

Can someone explain 704(b) in simple terms?

like

The outright tyranny of ordering a Popeyes combo meal…I must have a side and a drink when all I want is tenders.

It is just too much

funnylike

What would a fair day rate be for a pharma/health agency? Also, is it worth taking the gig just for money? I have other gigs to put in my book. Thanks!

like

Hi Fishes,

Anyone here from
Tiger Analytics can guide how much salary can i ask in HR discussion round fro Java, SQL developer (Analyst) having 1 yr 10 month of experience in Java background?

Tiger Analytics Accenture Cognizant Infosys

like

What are everyone's thoughts on executive MBA vs. traditional MBA? I'm currently pursuing a traditional MBA but sometimes I wonder what could've been 😅

like

Anyone in need of a hybrid to plug a gap in their team/an extra resource in the lead up to Christmas? If so get in touch.

Not in London? No worries. UK based / happy to work remotely.

Junior level, with experience.

like

Any attorneys do title? Is it worth it?

like

Which company is better Infosys or capegemini? Capgemini provides 1 lakh extra salary than Infosys

like

Working in reporting of private equity funds. Hands on experience in Tableau and MySQL. Good knowledge of Analytics part and writing down commentary for return on investment fir private equity funds.
Serving notice period.
LWD: 13th April
Please help me if you have any opportunities
Location: Delhi/NCR

like

Ok 🐠-es: favourite airport lounge? I’m quite partial to my weekly wine and hoummous at the Qantas Domestic Business lounge at Melbourne airport, however Canberra has a prettier layout. And, go!

Post Photo
like

Grant Thornton strives to be “middle of the road” as far as comp from what I’ve heard at recruiting events. True/false?

like

Deloitte 🐠: any insights into reasonable signing bonus expectations? Starting the process with the Government and Public Services group...

like

Any CPAs on here have their MMJ card? Little worried about the impacts of licensing if I go get the card.

like

What is everyone’s thoughts about Hilton? Just got asked to interview

like
like

How is the job security at Delta Air Lines ?
Do they layoff frequently?

HR had mentioned there were no layoffs at tech during the pandemic.

like

Audit lay off people during recession ?

like

Has anyone at a mega fund like KKR or Apollo experienced coinvesting and actually being able to put money into a deal?

like

Hi friends I am shifting to Bangalore next week, Currently I am in Gujarat so my bike is having Gujarat passing number plate, So now I want to know that is it mandatory to get BLR passing number plate for my bike or I can use it with Gujarat passing.. pls suggest...

Thanks in advance!!

like

Hi Fishes,

I am looking for a Job opportunity. I would like to know if anyone can help me to forward my resume or connect me to the concerned person.

I can send my resume if there is any ongoing recruitment or any vacant position in your organization. It would be great if you could refer to my resume.

Skill- Selenium with Java, Cucumber, TestNG, Maven, Git, Jenkins, SQL.

YOE - 2.3 years

NP - 60 days

Thanks In Advance!

like

Additional Posts in Cyber Security Bowl

What’s the recommended YOE for Analyst / Sn Analyst (Threat Intel) at Mandiant? Sn Analyst postings ask for a relevant degree OR 5 YOE - is this correct? Regular analyst posting asks 2 YOE

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Tired of your job and want to come to KPMG Cyber Services? Drop me a burner here.

likefunny

Anyone that has experience with the Crypsis Group willing to share an opinion on them?

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

What do you think is the better option? Both offers are around the same salary (~100k EUR in Denmark).

Solutions Specialist (security) at Microsoft or Manager in digital solutions (security) at MasterCard? Also in respective of the long term career? I have 2.5 YOE

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Which companies or industries pay the most money for cybersecurity jobs?

Other than a client project, what's a good way to get trained up on cloud security?

like

Need to recertify my AWS-SAA cert. any recommendations on best resources given the new test format (SAA-CO2)?

like

What books would you recommend for someone who is just starting out in security and wants to build strong fundamentals?

funny

What can I expect in raise % going from Senior to Manager?

On a phone call today, my client suggested our project team provide 24/7 coverage for scanning support. My team size is two, including myself.

Post Photo
likefunnysmart

Any recommendations for resume revamp?

I’m 4 years into cyber. Focused almost exclusively on strategy and controls assessments.. got my CISSP. What actual exit opps are there for me? Seems like all job postings are technical. If I need to go technical, what skills do you recommend i pursue?

like

Would you leave cyber consulting potentially Senior Manager to go work as Senior Customer Success Manager at a tech company ? What are your thoughts?

like

Anyone completed their GCTI certification from SANS recently and willing to help share their index?

Not being lazy, but mine didn't work well in my practice test.

TIA!

like

How is Booz Allen cyber strategy and risk management consulting? Got a recruiter inquiry

like

Any B4 IAM consultants make the move to Accenture? How is the talent experience (employee apps for time & expense, expense/travel policies, well being subsidy, stock options, etc) compared to what you’d find at D or EY? How do you find the quality of projects, and your role as a SC (which I understand is just “Consultant” at Accenture)? Worth making the jump or do you miss B4 life?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal