You can use attestation to test the balance between security and compliance within your company. Managers or others responsible for compliance can use One Identity Manager attestation functionality to certify correctness of permissions, requests, or exception approvals either scheduled or on demand. Recertification is the term generally used to describe regular certification of permissions. One Identity Manager uses the same workflows for recertification and attestation.
There are attestation policies defined in One Identity Manager for carrying out attestations. Attestation policies specify which objects are attested when, how often, and by whom.Once an attestation is performed, One Identity Manager creates attestation cases that contain all the necessary information about the attestation objects and the attestor responsible. The attestor checks the attestation objects. They verify the correctness of the data and initiate any changes that need to be made if the data conflicts with internal rules.
Attestation cases record the entire attestation sequence. Each attestation step in an attestation case can be audit-proof reconstructed. Attestations are run regularly using scheduled tasks. You can also trigger single attestations manually.
Attestation is complete when the attestation case has been granted or denied approval. You specify how to deal with granted or denied attestations on a company basis.
Detailed information about this topic
You can display attestation cases that involve identities for which you are responsible.
In addition, you can obtain more information about the attestation cases.
To display attestation cases
-
In the menu bar, click Responsibilities > My Responsibilities.
-
In the navigation, click Identities.
-
On the Identities page, click the identity whose attestation cases you want to display.
-
In the Edit Identity pane, click the Attestation tab.
This displays all the identity's attestation cases.
-
(Optional) To display more details of an attestation case, click the relevant attestation case.
Related topics
You can grant or deny approval to attestation cases of identities for which you are responsible.
To approve an attestation case
-
In the menu bar, click Responsibilities > My Responsibilities.
-
On the Identities page, click the identity whose attestation cases are pending your approval.
-
In the Edit Identity pane, click the Attestation tab.
-
On the Attestation tab, click (Filter).
-
In the Filter Data pane, under State, select the Pending option.
-
Click Apply filter.
-
Perform one of the following actions:
-
To approve an attestation case, select the check box next to the attestation case in the list and click Approve below the list.
-
To deny an attestation case, select the check box next to the attestation case in the list and click Deny below the list.
-
In the Approve Attestation Case or the Deny Attestation Case pane, perform the following actions:
-
In the Reason for your decision field, select a standard reason for your approval decision.
-
In the Additional comments about your decision field, enter extra information about your approval decision.
TIP: By giving reasons, your approvals are more transparent and support the audit trail.
-
Click Save.
Related topics
You can display the rule violations of identities for which you are responsible.
You can also display mitigating controls for each rule violation.
To display identities' rule violations
-
In the menu bar, click Responsibilities > My Responsibilities.
-
In the navigation, click .
-
On the Identities page, click the identity whose rule violations you want to display.
-
In the Edit Identity pane, click the Rule Violations tab.
-
(Optional) To display the mitigating controls of a rule violation, click View mitigating controls next to the rule violation.
Related topics