Thursday, August 20, 2015

GRC Audit Reports-Access Controls

Find the list reports used for Audit 

Search Requests- Within "Access Management" workspace of GRC NWBC.  This shows the Request IDs, the Request Type, the Approval status, and the Creation Date.
Provisioning Logs - Within "Access Management" workspace of GRC NWBC.  This shows granular detail for each request, such as User(s), what type of item was provisioned (role, FFID, etc.), the item name, the status of provisioning, the target connector for which provisioning took place.
Risk Analysis Reports - User Level / Role Level SOD reports.  Shows how many SOD issues are present in the landscape and any mitigation that has been assigned.
Mitigating Controls Assignments - manually download this using program "GRAC_DOWNLOAD_MIT_ASSIGNMENTS" in GRC system.  Shows all assigned MCs to Users
EAM Reason Code and Activity Report - Within "Reports and Analytics" workspace of GRC NWBC.  Shows which Reason Codes have been used by Firefighter End Users and the frequency.
EAM Consolidated Log Report - Within "Reports and Analytics" workspace of GRC NWBC.  Shows all Firefighter activity in granular detail.  Includes all report types from Firefighter logs.
Rule set Changes:
NWBC>Reports and Analytics > Audit Reports > Change Log
Report    : By Function, Risk, Rule Set, Organization Rule. Changed On field based
 They will analyze below points and be prepare with below data in EAM
 1. The Number of FF IDs, FF ID Owners, FF ID Controllers from reports
2. Number of Unique Owners, Controllers
3. FF IDs with Same Owner and Controller
4. Number of Unique FF IDs across All Systems/Clients (if you are using more target systems)
5. Number of Logins per FF ID
6. Number of Logs per Controller

No comments:

Post a Comment