Related Posts
For UK based colleagues- has anyone done self assessment with HMRC although we are part of PAYE? Last year I switched entities and had stocks vest. So apparently went over £100k with sticks vesting. Superficially I made over £100k, but about 50% of vested shares go to paying tax and NIC. I’m a bit baffled as to how I fill out the self assessment form. I had no other income so one would think it’s straightforward… there are questions about foreign investment. Would RSUs be foreign investment? Amazon
Favorite office chair?
McKinsey & Company I received an offer from McKinsey & Company in 2021 and I’ll be starting later this year after graduation. Obviously because of the pandemic, inflation is slowly trending upwards. Has anyone asked for a base salary increase before even starting the job? Any advice on how to approach this?
Additional Posts in Cyber Security Bowl
Any tripwire pros here? How did you get started?
New to Fishbowl?
unlock all discussions on Fishbowl.






Actually a lot of tools like Sailpoint and Saviynt have OOTB rulesets that have SOD violations already defined for common apps like SAP,oracle etc.
If you can get the user list with the profile attributes as well as the permissions in the various systems, you can create a matrix to look at common access that exists today. For example, you may see everyone with the Title=“After Market Sales” has access of some sort to the CRM system. You can look at these common privileges and start to define suggestions that anyone with the “After Market Sales” Title gets these baseline permissions. Always go least privilege since it’s better to have someone need to request additional access than let them see/do too much by default. Also, I agree with CD1’s comment. You don’t want someone that can submit payment orders also able to approve payment orders, ABAC should optimally be set up with segregation of duties in mind regardless of how the organization has permissions today.
Have you tried reaching out to your engagement manager for guidance? It’s OK not to know if new to the field.
Yes I've set up some calls already to brainstorm, & have started proposing some rules myself with information at hand that are logical, but would be great to get insight from people who have previous experience doing it.
start with the risks inherent with conflicts, not the tech itself
Segregation of Duty conflicts
NIST 800-63
Start by getting an export of job title to entitlement granted
See if there are common entitlements can be grouped at a higher level or department, like ALL USERS, then you can break it down further
Kind of depends on your authentication method. Are we talking SAML or certificate attributes? Or are you authenticating one way and using cloud attributes once authenticated for access authorizations?