Managing attestation policy (page description)
To open the Attestation Policy Settings page go to Attestation > Governance Administration > Attestation Policy Settings.
On the Attestation Policy Settings page, you can:
-
Display attestation policies
-
Set up attestation policies
-
Copy attestation policies
-
Edit attestation policies
-
Delete attestation policies
The following tables give you an overview of the various features and content on the Attestation Policy Settings page.
Table 220: Controls
Edit |
Opens the Edit attestation policy page (see Editing attestation policies (page description)).
Use this button to edit the attestation policy. For example, you can:
-
Set up a schedule after the attestation case is generated
-
Disable the attestation policy
-
Select an identity to be responsible for granting or denying approval of attestation cases
-
Enable or disable automatic closing of obsolete attestation cases by the system
-
Create/edit condition for ascertaining which objects to attest |
Copy |
Use this button to copy the attestation policy. |
Delete |
Use this button to delete the attestation policy. |
Show disabled policies |
Use this button to display disabled attestation policies. For example, you can display a disabled attestation policy to edit and re-enable it. |
New attestation policy |
Use this button to create a new attestation policy. This opens the Create New Attestation Policy page. |
Table 221: Columns
Attestation policy |
Shows you the name of the attestation policy. |
Attestation procedure |
Shows you the name of the attestation procedure used by the attestation policy. |
Compliance frameworks |
Shows you the name of the compliance frameworks used by the attestation policy.
Compliance frameworks are used for classifying attestation policies, compliance rules, and company policies according to regulatory requirements. This could be internal requirements or auditing requirements. |
Calculation schedule |
Shows you how often an attestation run is started with this attestation policy. Each attestation run creates a new attestation case respectively. |
Owner |
Shows you the name of the identity that created the attestation policy. |
Actions |
Using the buttons (see the previous table) you can edit, copy, or delete the attestation policy. |
TIP: You can show less data by using the column filters. For more information, see Filtering.
Creating new attestation policies (page description)
To open the Create New Attestation Policy page go to Attestation > Governance Administration > Attestation Policy Settings > New attestation policy.
On the Create New Attestation Policy page you can create a new attestation policy.
The following tables give you an overview of the various features and content on the Attestation Policy Settings page.
Table 222: Controls
Create |
Use this button to save the attestation policy with your settings. |
Cancel |
Use this button to cancel creation of the new attestation policy. |
You can specify the following main data.
Table 223: Attestation policy main data
Disabled |
Specify whether the attestation policy is disabled or not. Attestation cases cannot be added to disabled attestation policies and, therefore, no attestation is done. Completed attestation cases can be deleted once the attestation policy is disabled. |
Attestation policy |
Enter a name for the attestation policy. |
Description |
Enter a description of the attestation policy. |
Attestation procedure |
Click Assign/Change and specify which objects will be attested with this attestation policy.
NOTE: The selection of the attestation procedure is crucial. The selected attestation procedure determines, amongst other things, the available options when conditions are added. The available options are modified to match the attestation procedure. |
Approval policies |
Specify who can approve the attestations. Depending on which attestation procedure you selected, different approval policies are available. |
Attestors |
Click Assign/Change and then select the identities that can make approval decisions about attestation cases.
NOTE: This field is only shown if you have selected an attestation policy in the Attestation policy menu that demands attestation by an approver (for example, Attestation by selected approvers). |
Calculation schedule |
Specify how often an attestation run is started with this attestation policy. Each attestation run creates a new attestation case respectively. |
Time required (days) |
Specify how many days attestors have to make an approval decision about the attestation cases governed by this policy. If you do not want to specify a time, enter 0. |
Owner |
Select the identity that is responsible for this attestation policy. This identity can view and edit the attestation policy. |
Risk index |
Use the slider to define the attestation policy's risk index. This value specifies the risk for the company if attestation for this attestation policy is denied. |
Compliance frameworks |
Click Assign/Change and add a compliance framework to use.
Compliance frameworks are used for classifying attestation policies, compliance rules, and company policies according to regulatory requirements. For example, internal requirements or auditing requirements. |
Close obsolete tasks automatically |
Specify whether attestation cases pending for this attestation policy are automatically closed if new attestation cases are created (for example, when there is a new attestation run of this attestation policy).
If an attestation run with this attestation policy is started and the option is set, new attestation cases are created according to the condition. All pending, obsolete attestation cases for newly determined attestation objects of this attestation policy are stopped. Attestation cases for attestation objects that are not recalculated, remain intact. |
Approval by multi-factor authentication |
Specify whether approvals about attestation cases governed by this attestation policy require multifactor authentication (for example Starling 2FA). |
In the Object selection, you use conditions to specify which objects are to be attested. The following table gives you an overview of the various features in the Object selection view.
Table 224: Controls in the object selection
All conditions must be fulfilled: |
Enable this option to have new attestation cases created for all objects that meet each of the conditions the next time the attestation policy is run. If one of the objects to attest does not fulfill a condition, this object is not attested. In addition, use of this option generates a intersecting set of all the individual conditions of the selected objects. |
At least one condition must be fulfilled: |
Enable this option so that new attestation cases are created for all objects that meet at least one of the conditions the next time the attestation policy is run. Use of this option generates a superset of all the individual conditions of the selected objects. |
Add condition |
Use this button to create a new condition. Conditions specify which objects to attest. For more information about the different conditions, see Appendix: Attestation conditions and approval policies from attestation procedures. |
Number of objects matching in total |
Click the displayed number to preview all objects that to attest. |
Edit condition |
Use this button to edit an existing condition. |
Delete condition |
Use this button to delete and an existing condition. |
Refresh |
Use this button to update the total number of matching objects. |
Editing attestation policies (page description)
To open the Edit attestation policy page go to Attestation > Governance Administration > Attestation Policy Settings > (Edit attestation policy).
On the Edit attestation policy page, you can:
-
Set up a schedule after the attestation case is generated
-
Disable the attestation policy
-
Select an identity to be responsible for granting or denying approval of attestation cases
-
Enable or disable automatic closing of obsolete attestation cases by the system
-
Create/edit condition for ascertaining which objects to attest
The following tables give you an overview of the various features and content on the Edit attestation policy page.
Table 225: Controls
Save |
Use this button to save the attestation policy with the changes you have made. |
Delete |
Use this button to delete the attestation policy. |
Cancel |
Use this button to discard the changes to the attestation policy. |
You can change the following main data.
Table 226: Attestation policy main data
Disabled |
Specify whether the attestation policy is disabled or not. Attestation cases cannot be added to disabled attestation policies and, therefore, no attestation is done. Completed attestation cases can be deleted once the attestation policy is disabled. |
Attestation policy |
Enter a name for the attestation policy. |
Description |
Enter a description of the attestation policy. |
Attestation procedure |
Click Assign/Change and specify which objects will be attested with this attestation policy.
NOTE: The selection of the attestation procedure is crucial. The selected attestation procedure determines, amongst other things, the available options when conditions are added. The available options are modified to match the attestation procedure. |
Approval policies |
Specify who can approve the attestations. Depending on which attestation procedure you selected, different approval policies are available. |
Attestors |
Click Assign/Change and then select the identities that can make approval decisions about attestation cases.
NOTE: This field is only shown if you have selected an attestation policy in the Attestation policy menu that demands attestation by an approver (for example, Attestation by selected approvers). |
Calculation schedule |
Specify how often an attestation run is started with this attestation policy. Each attestation run creates a new attestation case respectively. |
Time required (days) |
Specify how many days attestors have to make an approval decision about the attestation cases governed by this policy. If you do not want to specify a time, enter 0. |
Owner |
Select the identity that is responsible for this attestation policy. This identity can view and edit the attestation policy. |
Risk index |
Use the slider to define the attestation policy's risk index. This value specifies the risk for the company if attestation for this attestation policy is denied. |
Compliance frameworks |
Click Assign/Change and add a compliance framework to use.
Compliance frameworks are used for classifying attestation policies, compliance rules, and company policies according to regulatory requirements. For example, internal requirements or auditing requirements. |
Close obsolete tasks automatically |
Specify whether attestation cases pending for this attestation policy are automatically closed if new attestation cases are created (for example, when there is a new attestation run of this attestation policy).
If an attestation run with this attestation policy is started and the option is set, new attestation cases are created according to the condition. All pending, obsolete attestation cases for newly determined attestation objects of this attestation policy are stopped. Attestation cases for attestation objects that are not recalculated, remain intact. |
Approval by multi-factor authentication |
Specify whether approvals about attestation cases governed by this attestation policy require multifactor authentication (for example Starling 2FA). |
In the Object selection, you use conditions to specify which objects are to be attested. The following table gives you an overview of the various features in the Object selection view.
Table 227: Controls in the object selection
Adding conditions |
Use this button to create a new condition. Conditions specify which objects to attest. For more information about the different conditions, see Appendix: Attestation conditions and approval policies from attestation procedures. |
Number of objects matching in total |
Click the displayed number to preview all objects that to attest. |
Editing conditions |
Use this button to edit an existing condition. |
Deleting conditions |
Use this button to delete and an existing condition. |
Refresh |
Use this button to update the total number of matching objects. |
Attestation escalation approval (page description)
To open the Attestation Escalation Approval page go to Attestation > Escalation.
If the are attestations pending and the approver responsible is not available for an extended period or has no access to Web Portal, the fallback approver or member of the chief approval team must make an approval decision. For more information about the chief approval team, see the One Identity Manager Attestation Administration Guide.
On the Attestation Escalation Approval, you can display attestation cases grouped by attestation policy and then, on the Attestation Escalation Approval - <attestation policy> page, approve the attestation cases (see Attestation escalation approval – Attestation policy (page description)).
The following table gives you an overview of the various features on the Attestation Escalation Approval page.
Table 228: Columns
Attestation policy |
Shows you the name of the attestation policy for which there are pending attestation cases. |
Attestation Cases |
Shows you how many pending attestation cases there are for this attestation policy and whether they are overdue. |
Review |
Shows you the progress of completed attestation cases in this attestation run. The color of the bar refers to the percentage of the attestation run's progress.
|
TIP: You can show less data by using the column filters. For more information, see Filtering.