Related Posts
Hi I am on notice notice period and my last working date is November end. I have total 6.5 years of experience in digital transformation and it strategy. Can anyone refer me for this same position I am more interested in the IT strategy consulting role/ M&A? Deloitte @ Deloitte Monitor Accenture Strategy&
No constraint for travelling
Capital One Venture or CSR?
Looking for SAP BRIM books/notes
Additional Posts in Cyber Security Bowl
Any tripwire pros here? How did you get started?
New to Fishbowl?
unlock all discussions on Fishbowl.



Actually a lot of tools like Sailpoint and Saviynt have OOTB rulesets that have SOD violations already defined for common apps like SAP,oracle etc.
If you can get the user list with the profile attributes as well as the permissions in the various systems, you can create a matrix to look at common access that exists today. For example, you may see everyone with the Title=“After Market Sales” has access of some sort to the CRM system. You can look at these common privileges and start to define suggestions that anyone with the “After Market Sales” Title gets these baseline permissions. Always go least privilege since it’s better to have someone need to request additional access than let them see/do too much by default. Also, I agree with CD1’s comment. You don’t want someone that can submit payment orders also able to approve payment orders, ABAC should optimally be set up with segregation of duties in mind regardless of how the organization has permissions today.
Have you tried reaching out to your engagement manager for guidance? It’s OK not to know if new to the field.
Yes I've set up some calls already to brainstorm, & have started proposing some rules myself with information at hand that are logical, but would be great to get insight from people who have previous experience doing it.
start with the risks inherent with conflicts, not the tech itself
Segregation of Duty conflicts
NIST 800-63
Start by getting an export of job title to entitlement granted
See if there are common entitlements can be grouped at a higher level or department, like ALL USERS, then you can break it down further
Kind of depends on your authentication method. Are we talking SAML or certificate attributes? Or are you authenticating one way and using cloud attributes once authenticated for access authorizations?