Previous Topic: Use Case: Certifying CA IdentityMinder Provisioning Role AssignmentsNext Topic: Integration Concepts


Use Case: Maintaining Compliant CA IdentityMinder Roles

As an Administrator, you want to be sure that when a new employee is added to CA IdentityMinder, they automatically get privileges that are appropriate to their function within the company, and compliant with business policies.

Integrating with CA GovernanceMinder and enabling Smart Provisioning in an CA IdentityMinder environment provides suggested roles and compliance checking when you create or modify users, roles, and accounts in CA IdentityMinder.

For example, a new employee starts in the finance department at your company When you create the new user in CA IdentityMinder, you specify that this person is part of the finance department. When you submit the Create User task in CA IdentityMinder, CA GovernanceMinder returns a list of the following suggested roles for the new user:

In addition, CA GovernanceMinder verifies that the existing privileges (if any) of the new user do not violate any business policy rules (BPRs).

Perform the following process to be sure that any new user added to CA IdentityMinder gains the appropriate privileges that are compliant with company policy.

  1. Integrate CA IdentityMinder and CA GovernanceMinder.
  2. Import CA IdentityMinder user, role, and account data to CA GovernanceMinder.

    This procedure creates the Master and the Model configuration in CA GovernanceMinder.

  3. Clean up the imported data in CA GovernanceMinder.

    This procedure removes suspect entities and suspect relationships between entities and updates the Model configuration.

  4. Create Business Policy Rules (BPRs) in CA GovernanceMinder that reflect business restrictions and limitations regarding user privileges.
  5. Run the BPRs created in Step 4 against the Model configuration.
  6. Export any changes made to the Model configuration during Step 5 back to CA IdentityMinder.

    This step updates the Master also.

After completing this process, CA GovernanceMinder suggests roles and performs compliance checks against business policy restrictions and limitations when you create and modify users, roles, or accounts in CA IdentityMinder. Any day-to-day changes made in CA IdentityMinder that affect users, roles, or accounts are updated in CA GovernanceMinder using Continuous Update.