Overview

DirX Identity provides a comprehensive role model for controlling access rights to resources in connected systems. A set of features like access policies or approval workflows allows securing the assignment of access rights. DirX Identity also allows using segregation of duties (SoD) policies to detect conflicting assignments as early as possible. Mitigation workflows can be started to approve exceptions to these rules.

Use Cases

This document describes two SoD use cases in detail. Be aware that other use cases are possible that are not described in this document.

Using DirX Identity SoD Policies

This use case works with DirX Identity’s built-in SoD policies. It allows configuring rules for any type of privilege. If you define rules at the permission or role level, you can control SoD over many different target systems.

Use Case Comparison

The following table compares the two use cases described in this document to help you with your decision process.

Table 1. Use Case Comparison
Criteria DirX Identity SoD Policies Using SAP GRC (Access Control)

Complexity of solution setup

Low

High

Pre-configured SoD policies

Few

Comprehensive

SoD policies on role / permission level

Yes

No

SoD policies on group level

Yes

Yes

Hierarchical SoD policies

Yes

No

The table presents the following evaluation criteria:

Complexity of solution setup – the effort and complexity involved in setting up the initial solution.

Pre-configured SoD policies – the availability of pre-configured SoD policies that can be directly used in compliance processes.

SoD policies for role / permission level – whether the use case offers the option of setting up SoD policies at the role or permission level.

SoD policies for group level - whether the use case offers the option of setting up SoD policies at the group level.

Hierarchical SoD policies - whether the use case offers the option of setting up SoD policies at different levels, for example between a role and a group.

General Hints and Guidelines

Segregation of duties (SoD) policies can help to fulfill compliance regulations. However, additional checks require additional time, and that will slow down your company processes. Therefore, we recommend that you:

  • Set up only those SoD policies that are truly necessary.

  • Configure only the minimum number of necessary SoD checks in your request workflows.