Previous Topic: Encrypt Policy ActionNext Topic: Integration with CA Identity Manager


New Database Security Models

Security models ensure that reviewers can only see events they are permitted to see when searching the CMS database for events.

CA DataMinder now supports a new policy-based security model. It also allows multiple security models to be active at the same time. You configure security models in the Administration console.

Policy-based Security Model

This model ensures that reviewers can only see specific types of event. For example, this model can be used to ensure that HR reviewers only see events that relate to HR issues such as employee behavior, while Legal reviewers only see events that relate to legal issues such as litigation threats or a breach of attorney client privilege.

The model is based on policy classes. For categorization purposes, you can associate individual triggers with a policy class, such as ‘Employee Behavior’ or ‘Legal’. When a trigger fires, the policy class is stored with the associated event.

Likewise, each reviewer has a policy role. A policy role links a user to a collection of policy classes. In effect, the policy role determines which policy classes a user is permitted to see. When the user runs a search, the results only include events associated with these policy classes.

Important! Certain reports, particularly the compliance reports, and the Review Queue are not designed for use with Policy security models. See the reference below for details.

Support for Multiple Database Models

CA DataMinder now supports multiple database models, including the original model based on management groups, variants of this original model (for example, to prevent reviewers reviewing their own e-mails), plus the new policy-based model.

You can choose which security models are active on your CMS and multiple models can be active at the same time. However, each reviewer can only be linked to a single model. For example, some reviewers may only be permitted to see events linked to users in their own management group. Other reviewers may only be permitted to see specific types, or categories, of event.

More information:

Policy Security Models Not Compatible With Some Features