Marcus Tornberg Super Contributor.
Super Contributor.
647 views

Risk of permissions assigned to user

Hi!

I have a question related to how IG (3.0) calculates user risk.

I am looking at a user with 64 permissions (looking at the User from Catalog/User/<user> and tab Permissions.

When I look at the Risk Factors tab for this user, the Base Score for "Risk of permissions assigned to the user" is set to 102.

Looking at Policy/Risk/User Risk Score, I have configured "Number of permissions assigned to the user" with Low range 30 and High range 150.

Why is the Base Score for "Risk of permissions assigned to the user" is set to 102?

I have tried to understand the documentation in this regard, but I fail to make sense of it.

Also, I have another question. Is it possible to display the risk specified for each permission in a review? So far I have only been able to display the User calculated risk, and not the risk set for the permission.

Best regards
Marcus
0 Likes
3 Replies
AutomaticReply Absent Member.
Absent Member.

Re: Risk of permissions assigned to user

marcus,

It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

These forums are peer-to-peer, best effort, volunteer run and that if your issue
is urgent or not getting a response, you might try one of the following options:

- Visit https://www.microfocus.com/support-and-services and search the knowledgebase and/or check
all the other self support options and support programs available.
- Open a service request: https://www.microfocus.com/support
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.microfocus.com)
- You might consider hiring a local partner to assist you.
https://www.partnernetprogram.com/partnerfinder/find.html

Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.microfocus.com/faq.php

Sometimes this automatic posting will alert someone that can respond.

If this is a reply to a duplicate posting or otherwise posted in error, please
ignore and accept our apologies and rest assured we will issue a stern reprimand
to our posting bot.

Good luck!

Your Micro Focus Forums Team
http://forums.microfocus.com



0 Likes
jmontm42 Absent Member.
Absent Member.

Re: Risk of permissions assigned to user

marcus_jonsson;2493316 wrote:
Hi!

I have a question related to how IG (3.0) calculates user risk.

I am looking at a user with 64 permissions (looking at the User from Catalog/User/<user> and tab Permissions.

When I look at the Risk Factors tab for this user, the Base Score for "Risk of permissions assigned to the user" is set to 102.

Looking at Policy/Risk/User Risk Score, I have configured "Number of permissions assigned to the user" with Low range 30 and High range 150.

Why is the Base Score for "Risk of permissions assigned to the user" is set to 102?



It sounds like you have 2 Risk Factors in your policy configured. What is the weight of those factors? The first is "Risk of permissions assigned to user." Is this set to avg or maximum? Also, "Number of permissions assigned to the user" with the ranges has a weight assigned as well. That data might help us figure out how its calculating.

marcus_jonsson;2493316 wrote:

Also, I have another question. Is it possible to display the risk specified for each permission in a review? So far I have only been able to display the User calculated risk, and not the risk set for the permission.


I don't think it is possible in version 3.0 to display risk for each review item, however, in 3.5 which came out last month, you can add additional fields to the reviews, and permission risk is one of them. So you would be able to do this easily with 3.5.

--Jim
0 Likes
Marcus Tornberg Super Contributor.
Super Contributor.

Re: Risk of permissions assigned to user

Hi Jim!

Sorry for the late response, I have been on vacation.

This image shows the settings in details form User Risk Score.
https://snag.gy/ozjiWk.jpg

I do not belive I have two risk factors in play.

Thanks for the information about 3.5, I have it installed in my lab environment, and nice to have this feature in place.

Best Regards
Marcus
0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.