Chat now with support
Chat with Support

Security Analytics Engine 1.2 - User Guide

Security Analytics Engine Overview Plugins Conditions Shared Policies Applications Auditing Issued Alerts Policy Overrides Fallback Password

Editing a risk policy

After a risk policy is added to an application, it appears listed on the Applications page and can now be edited.

To edit a risk policy

  1. On the Applications page, select the application currently using the risk policy.
  2. Click the button to open the Edit Application dialog.
  3. In the Policies section, select the risk policy to edit and click the button to open the Edit Policy dialog.
  4. (Optional) To change the alerting configuration for the risk policy, click Alerting to expand the section and make any necessary changes.
  5. To change the conditions currently used by the risk policy, click the button to open the Select conditions to monitor dialog.
  6. After making changes to the selected conditions, click OK to close the Select conditions to monitor dialog and return to the Edit Policy dialog.
  7. Use the slider bars to assign each condition a percentage according to how much of a risk you consider a user that triggers the condition during an access attempt.
  8. To add or edit the modifiers for a condition, use the button to the left of the condition name to open the Select condition modifiers dialog.
  9. After selecting modifiers for the condition, click OK to close the dialog.
  10. Each modifier now appears listed beneath the original condition with a scroll bar set at 100%. Move the slider to set the impact each modifier will have on the condition score. Depending on how each modifier was configured on the Conditions page (Can increase risk, Can decrease risk, or Can both increase or decrease risk), the following settings are available:
    • 0% - A modifier set to this percentage automatically causes the condition score to be 0% regardless of any other modifiers triggered. (Can decrease risk or Can both increase or decrease risk)
    • 10%-90% - A modifier set between these two percentages decreases the condition score when triggered. (Can decrease risk or Can both increase or decrease risk)
    • 100% - A modifier set to this percentage will not affect the condition when triggered. (Can decrease risk, Can increase risk, or Can both increase or decrease risk)
    • 110%-200% - A modifier set between these two percentages increases the condition score when triggered. (Can increase risk or Can both increase or decrease risk)
  11. (Optional) To preview possible risk scores that can occur for the risk policy, click the button in the upper right corner of the dialog to enable Preview Mode. Edits to the risk policy are allowed while preview mode is active.
    • Select the check boxes to the left of any conditions or modifiers to preview the risk score that occurs if they are triggered during an access attempt. The Risk Score field at the top of the dialog updates as selections are made.
    • Click the button to close preview mode.
  12. Once you have finished editing the risk scores, click the Accept button to approve the changes and close the Edit Policy dialog.
  13. Click the Save button on the Edit Application dialog to save the application and return to the Applications page.

Deleting a risk policy

After a risk policy is added to an application, it appears listed on the Applications page and can be deleted.

To delete a risk policy

IMPORTANT: The Security Analytics Engine is not aware of applications’ usage of risk policies. Before deleting a risk policy, ensure that the application is not sending requests to evaluate the risk policy that is to be deleted.
  1. On the Applications page, select the application currently using the risk policy.
  2. Click the button to open the Edit Application dialog.
  3. In the Policies section, select the risk policy to delete and click the button.
  4. A dialog is displayed confirming that you want to delete the selected risk policy. Click the Delete button.
  5. The deleted risk policy no longer appears listed in the Policies section of the Edit Application dialog. Click Save to return to the Applications page.

Adding and managing shared risk policies in an application

Shared risk policies allow for the same risk policy to be used by multiple applications. Shared risk policies can only be viewed, duplicated and selected for use by an application on the Applications page. The creation and management of shared risk policies is done through the Shared Policies page (see Adding and managing shared risk policies for more information). See the following sections for more information:

Adding a shared risk policy to an application

To add a shared risk policy to an application

NOTE: Shared risk policies can only be selected for use by an application on the Applications page. The creation of shared risk policies is done through the Shared Policies page (see Adding a new shared risk policy for more information).
  1. On the Applications page, select the application which will use the shared risk policy.
  2. Click the button to open the Edit Application dialog.
  3. The Policies section of the Edit Application dialog is used for adding and managing the risk policies assigned to the application. To add a new shared risk policy, click the button to open the Available Shared Policies dialog.
  4. Select a shared risk policy from the list of available shared risk policies. To select multiple shared risk policies, use the CTRL or Shift keys.
  5. Click the Accept button to approve your selection and return to the Edit Application dialog.
  6. (Optional) To preview a selected shared risk policy, click the button. Click the Close button to close the preview and return to the Edit Application dialog.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating