10.2 Creating and Editing Data Policies

Identity Governance provides default collection data policies and publication data policies. In addition, it enables you to create and edit data policies.

  1. Log in as a Global or Data Administrator.

  2. Select Data Administration > Data Policy.

  3. (Optional) Click the gear icon to customize display settings for collection and publication data policies. For example, you choose to display Analysis Type column.

  4. In the Collection Data Policies or Publication Data Policies tab, select + to create a new policy.

  5. Select the type of metric you want to run:

    • Attribute Changes to monitor changes to attribute values based on your specified criteria in published data.

      If you configure only Entities which changed to match the following criteria, the simple criteria policy returns all entity types that match the criteria.

      For example: “All users whose location is Boston.”

      You can Add optional criteria to this data policy to configure Entities which changed from the following criteria and narrow the results to list only changes from a specified value.

      For the previous example: If you also configure the optional criteria to specify users whose location changed from Chicago, the policy returns only “Users currently located in Boston who previously were located in Chicago.”

    • Criteria to detect and monitor user, permissions, or accounts based on your specified criteria in collected or published data.

    • Entity Changes to detect changes such as addition or removal of entities such as identities, accounts, and permissions, and permission assignments, or monitor changes based on the number of entities in collected or published data.

    • Statistics to detect the number of specified entities such as users, groups, permissions, or accounts in collected or published data .

      NOTE:You cannot calculate violations for these types of statistics and the number of entities is displayed in the Data Sources > Activity page.

  6. Select the desired data source type, analysis type, and entity type for the policy, and specify additional criteria.

    NOTE:When specifying criteria, press Enter after typing a value for it to be included as a parameter in data policy analysis and calculations.

    1. (Conditional) If you select entity analysis type and choose to analyze permissions and account changes in application sources or to analyze user changes in identity sources, add and remove respective data sources as needed to expand or constrain analysis.

    HINT:When selecting dates, in addition to selecting a specific date using the date picker, you can also create date formula that calculates the date based on your criteria.

  7. Save your settings.

  8. Select Data Administration > Data Policy.

  9. (Optional) Select the policy, then select Edit to edit the policy.

  10. (Optional) When editing a policy, select the trashcan icon to delete the policy.

  11. (Optional) If available, select Estimate impact to show estimated violations for the policy.