IBM Support

How to restrict GUI user privileges to the minimum in InfoSphere Guardium

Troubleshooting


Problem

In Guardium, each user account is required to have one of four roles: [] user, cli, admin [] or [] accessmgr []. The [] user [] role is the one with the less privileges and it is assigned by default. Having this role, users have the ability to do certain things that you do not desire such as: create, delete and alter the queries, reports and audit processes that have been created for their environment, as well as access almost every Guardium application.

Symptom

Users created with user role can perform activities you do not desire.

Cause

Default user role includes the ability to perform activities you may not desire.

Resolving The Problem

Add the review-only role for the user, in addition to the user role. review-only role will restrict to the minimum the user privileges in the GUI.

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"}],"Version":"8.2;9.0;9.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21674895