Previous Topic: AuditorsNext Topic: Authority


Scope

For your security hierarchy, the security administrator is responsible for the scope of authority. CA Top Secret provides several different levels of control ACID scope. Each level corresponds to a level in your corporate structure.

For example, a division control ACID (VCA) is responsible for administering security for all the ACIDs within a particular division (including ACIDs assigned to departments associated with that division).

The following table shows an example of how an organization could define its security administrators to CA Top Secret, and the scope that results:

Title

Scope

Example

MSCA

Entire installation

The master SCA (MSCA) can create all CA Top Secret administrators, including SCAs, LSCAs, ZCAs, DCAs, VCAs, and auditors.

SCA

Entire installation

An SCA's scope of authority depends on the administrative authorities that they were granted. An SCA can create ZCAs, DCAs, VCAs, Profile, and User ACIDs, but not other SCAs.

LSCA

A zone and/or another LSCA

An LSCA can have all the authority of an SCA, but unlike the SCA, the LSCA must have a scope of authority assigned to it. This scope of authority can be one or more LSCAs and/or zones.

ZCA

A zone

A zone security administrator can:

  • Permit access to resources owned by his zone, all connected divisions, departments and users within that zone.
  • Define profiles and perform maintenance for ACIDs that are within his scope.
  • Create ACIDs in his zone.
  • Permit ACIDs in other zones to access his zone's resources, but cannot perform maintenance for ACIDs in other zones.

VCA

A division

A divisional security administrator can:

  • Permit access to resources owned by his division, all departments and users within that division, and can define profiles and perform maintenance for ACIDs that are within his scope.
  • Create ACIDs in his division.
  • Permit ACIDs in other divisions to access his division's resources, but cannot perform maintenance for ACIDs in other divisions.

DCA

A department

Department administrators have the same scope over a department that a VCA has over a division. DCAs can also create ACIDs in their department.