12.07.2015 Views

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 2: Addressing Business NeedsThis section contains the following topics:Processing Business Changes (see page 21)Complying with Business Policies (see page 22)Enforcing Segregation of Duties Requirements (see page 25)Transforming Data in the User Store (see page 26)Applying Custom Business Logic (see page 27)Approving Business Changes (see page 28)Processing Business ChangesYou can automate the processing of certain identity management tasks by usingidentity policies. An identity policy is a set of business changes that occurs whena user meets a certain condition or rule. You can use identity policy sets to:■■■Automate certain identity management tasks, such as assigning roles andgroup membership, allocating resources, or modifying user profileattributes.Enforce segregation of duties (see page 25). For example, you can create anidentity policy set that prohibits members of the Check Signer role fromhaving the Check Approver role, and restricts anyone in the company fromwriting a check over $10,000.Enforce compliance. For example, you can audit users who have a certaintitle and make more than $100,000.<strong>Identity</strong> policies that enforce compliance are called compliance policies.The business changes associated with an identity policy include:■■■Assigning or revoking roles, including provisioning roles (when <strong>CA</strong> <strong>Identity</strong><strong>Manager</strong> includes provisioning)Assigning or revoking group membershipUpdating attributes in a user profileFor example, a company may create an identity policy which states that all VicePresidents belong to the Country Club Member group and have the role SalaryApprover. When a user’s title changes to Vice President and that user issynchronized with the identity policy, <strong>CA</strong> <strong>Identity</strong> <strong>Manager</strong> adds the user to theappropriate group and role. When a Vice President is promoted to CEO, she nolonger meets the condition in the Vice President identity policy so the changesapplied by that policy are revoked, and new changes based on the CEO policy areapplied.Chapter 2: Addressing Business Needs 21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!