Previous Topic: Securing Resources Using EPM Application ObjectsNext Topic: How to Create Application Security Policies


Secure Applications Using Enterprise Policy Management

Enterprise Policy Management (EPM) is an access management model that lets you protect business applications without an in-depth knowledge of SiteMinder-specific concepts and components.

EPM presents policy configuration in the context of securing an application. To protect an application, you create an Application object and are only required to provide data for configuration settings that do not have defaults. Modifying other settings is optional. EPM therefore makes policy configuration more straightforward. You can manipulate additional SiteMinder settings that allow you to define more fine-grained protection of an application; however, such manipulation is not required.

For the administrator already familiar with SiteMinder domain-based policies, there is a relationship between the application-oriented concepts and the underlying SiteMinder policy objects. This relationship is reflected in the Administrative UI and is shown in the following table:

Application Dialogs and Group Boxes

Underlying SiteMinder Component

General settings

Defines the policy domain

Components

Defines the realm

Resource

Specifies the rule

Application Roles

Define the policy users

Application roles define the set of users who have access to a resource or group of resources defined in an Application object. Roles can include all users in configured user directories, be limited to selected groups, organizations, and users with matching user attributes, or specified using a named or unnamed expression.

EPM offers the following benefits: