Once a resource has been placed under governance, you can view details, assign a business owner, and publish the resource to the IT Shop.
|
Note: If you rename or move a resource, the data governance system considers this a new resource that needs to be governed. The original governed resource is marked as "stale". To rectify this, you need to search for the resource in question and place it under governance again. Also, any associated business ownership that existed needs to be recreated on the new resource. |
Managing governed data details
Managing business ownership for a resource
Publishing resources to the IT Shop
From the Governed data view you can modify the properties assigned to a governed resource, assign a business owner to a governed resource, and publish a governed resource to the IT Shop.
To manage governed resources
In the Manager, open the Governed data view.
The General tab displays the resource information, including:
Available in IT Shop: A check in this check box indicates that the resource is available through the IT Shop.
|
Note: Select this check box to publish the resource to the IT Shop. For details, see the One Identity Manager Data Governance Edition IT Shop Resource Access Requests User Guide or Publishing resources to the IT Shop. |
No longer found: A check in this check box indicates that the resource was renamed or deleted.
|
Note: A resource is deemed stale if it has not been scanned by any of your agents or if the resource has been moved or renamed. |
Risk Index (calculated): Displays the calculated risk of all assignments to this data.
For a list of the governed data risk index functions provided with Data Governance Edition, see Appendix: Governed data risk index functions
|
Note: Before risk calculations can be performed on governed data, the required schedule must be enabled. In the Designer, select Base Data | General | Schedules and enable Calculate risk indexes of governed data. For more information, see the One Identity Manager Risk Assessment Administration Guide. |
Select the Business Owner tab to assign an owner for the resource or modify the current owner.
For more information, see Managing business ownership for a resource.
Click the Save toolbar button to save your changes.
Removing a resource from governance, also removes it from the IT Shop.
To remove a resource from governance
Publishing a resource to the IT Shop makes it available for users to request access to it. It also places the resource under governance if it is not already governed.
|
NOTE: In order for a DFS link, target share path or folder to be placed under governance or published to the IT Shop, both the DFS server hosting the DFS namespace and the share server where the DFS link is pointing to must be added as managed hosts. If the required servers (those that contain DFS security details) are not already managed, a message box appears listing the servers that need to be added as managed hosts. Click the Add managed hosts with default options button to deploy a local agent to the servers listed in the message box and complete the selected operation. Click Cancel to cancel the selected operation and manually add the servers as managed hosts. |
Each request is processed by a policy-based approval process, which determines whether access to the data can be assigned or not. Authorized persons, in this case the business owner and group owner, can approve or deny IT Shop requests. The request history also makes it possible to follow who requested what resource and when it was requested, renewed or canceled.
You can quickly see all the resources that have been placed under governance and manage (add and remove) resources in the IT Shop from the Resource browser or Governed data view in the Manager.
You can publish NTFS shares and folders, and SharePoint objects from the site level and below.
|
NOTE: This functionality is not available for NFS managed hosts. |
|
Note: This functionality is not available for Cloud managed hosts. |
To place a resource under governance and publish it to the IT Shop
In the Manager, navigate to the required resource.
For example, to use the Resource browser:
In the Publish to IT Shop confirmation dialog, confirm the display name of the selected resource and click Publish Resources.
When placing a share under governance, you can use the backing folder security or share permissions for self-service resource access requests in the web portal. The Use backing folder security for self-service option is selected by default and uses the backing folder security for the share. Clear this option to use the share permissions for the share.
When placing a DFS namespace under governance, select the type of security to be used:
Back in the Resource browser, "True" appears in both the Governed Resource and Published to IT Shop columns. The assigned business owner is also added to the Business Owner column. The governed resource is also added to the Governed data view.
Users are now able to request access to the resource from within the web portal and set in motion the request workflow.
To publish a governed resource to the IT Shop
In the Manager, navigate to the governed resource.
For example, to use the Resource browser:
For example, to use the Governed data view.
Back in the Resource browser and Governed data view, "True" appears in Published to IT Shop column. The assigned business owner is also added to the Business Owner column.
To remove a resource from the IT Shop
Removing a resource from the IT Shop, does not remove the item from governance. However, removing a resource from governance removes it from the IT Shop.
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy