New Capability: SoD Violation Reporting for Compliance Teams

:new_button: New Capability

SoD Violation Reporting in Access Intelligence Center

:speech_balloon: Aha! Ideas Portal

GOV-I-3182 — SoD violation reports in AIC

:sparkles: Description

You can now monitor, triage, and evidence your Separation of Duties compliance program from Access Intelligence Center. An SoD sheet with health KPIs and out-of-the-box visualizations provides instant access to the knowledge required for violation status summaries, status by policy risk, status by violation owner, violations by department, and policy effectiveness.

SoD data goes past the current snapshot of open violations. You can see open violation backlog and aging, how violation volume trends over time, with 30-day rolling averages of open violations by department and by violation owner, and how long mitigation takes.

:red_exclamation_mark: Problem

The SoD violation UI does not enable customers to easily build reports for auditors or to monitor their compliance program health.

Compliance teams have not had an easy way to see which policies or departments produce violations repeatedly, which violation owners are carrying the heaviest load, how long violations sit before they are mitigated. Customers have had a hard time supplying evidence of what the policy is, what violations are detected, and that a control process is consistently followed.

:light_bulb: Solution

The Access Intelligence Center allows organizations to visualize, track, and analyze identity and governance data over time through various dashboards.

We now include SoD data in Access Intelligence Center dashboard. SoD in Access Intelligence center includes with a set of default visualizations, KPIs, and filters to enable customers to get answers to common questions.

Customers can drill into SOD policy and violation data to get exactly what they need to work with their internal and external stakeholders.

Customers with AIC edit capability can leverage the Business Intelligence tool to duplicate sheets and build custom sheets to answer their and their stakeholders’ questions.

How you get there: From the Access Request Center - use Access Intelligence Center dashboard tile.

:busts_in_silhouette: Who is affected?

This capability is for All SailPoint Human Fabric customers (including former Identity Security Cloud customers).

Requirements: Customers must own Separation of Duties and Access Intelligence Center. To create your own sheets customers must own Human Fabric Business Plus (formerly Identity Security Cloud Business Plus).

:clipboard: Action required

No action is required if your tenant already has the SoD and AIC — the SoD sheet appears in Access Intelligence Center after rollout.

To get value from it quickly:

  1. Navigate to Access Intelligence Center page (Typically under yourtenant.identitynow.com/ui/ic/access-intelligence-center)

  2. Click the Access Intelligence Center tile.

  3. In the supplied visualization, view potentially problematic policy, identities, and departments.

  4. (Optional) Create custom sheets and filters. Share with your stakeholders such as violation owners or policy owners.

Documentation:

:date: Important dates

Sandbox: week of September 23rd

Production: week of September 30th