Governance, Risk, and Compliance (GRC)

 View Only

SECURITY RULES - CREATION

  • 1.  SECURITY RULES - CREATION

    Posted Wed July 31, 2024 02:55 PM

    Hello,

     
    I have developed security rules with a property RESTRICT only read and this security rules apply only to users that is in the user group specified.
     
    Here is an example of how I use my read security rules: 
     
    Line 1: (END_USER_PROFILE IN 'Administrateur Local' OR END_USER_PROFILE IN 'Operateur' OR END_USER_PROFILE IN 'BCM End User') = Profiles that are not affected by the security rule
     
     Line 2: Or (END_USER IN GROUP 'Non-conformity risks' AND [SOXRisk]. [OPSS-Shared-Basel]. [Risk Group level 1] IN ('Risks of non-compliance') = All users who are in the "Risks of non-compliance" group will only see risk sheets with a referentieles "Risk of non-compliance".
     
    Now the problem I encounter is the following:  I made another security regle but with an access in creation (with all the accesses) and this security rule has the same logic as above but with the specificity: FOR (INTENDED PARENT OF TYPE [SOXRisk]: END_USER IN GROUP 'Non-conformity risks' AND [SOXRisk]. [OPSS-Shared-Basel]. [Group Risk Level 1] IN ('Risks of non-compliance').
     
    The problem is that this safety rule has no effect and I would like to know if you have any suggestions regarding how to fix this problem.
     
    Thank you for your feedback.
    Best regards,
    Koutam Moulaye.


    ------------------------------
    moulaye koutam
    ------------------------------