Risk assessment
Nova distinguishes two kinds of risk information:
- the risk rating of an entitlement or business role – a fixed classification maintained by administrators;
- risk findings – conflicts that Nova derives from rules for an access request. They are described under Segregation of duties.
The levels
A role is rated “Critical”, “Medium”, “Low” or “No Risk”. “Not Scored” stands for a missing classification and is the default for new roles. There is no “High” level for roles; it only occurs in risk findings.
Maintenance
- Administrators set the rating in the “Risk” field of an entitlement or business role.
- A business role's rating stands on its own: Nova does not derive it from the entitlements it contains. Exception: when role mining creates a business role, Nova takes over the highest rating of its entitlements.
- With the add-on module “GRC-Berechtigungsanalyse (SAP Access Control)”, administrators can transfer the risks determined with the GRC rule set as ratings onto the SAP roles in Nova. For each role the highest risk counts; “High” becomes “Critical”. Nova overwrites an existing rating.
Where the rating appears
- under “Roles”, in the list and in the detail view of every entitlement and business role;
- on an identity's assignments;
- in a request, next to the requested roles;
- in recertification, on every item – recorded when the campaign is created – and, after completion, under “Risk reduction (revoked)”;
- on the “Dashboard”:
- “Risk Exposure” – number of assignments of critically rated entitlements and how many identities hold them;
- “Risk Distribution” – all entitlement assignments, direct and through business roles, by level;
- “Top Risk Users” – up to five identities with the most assignments of critically rated entitlements;
- “Risk Scoring” in the “Compliance Posture” – the share of entitlements that carry a rating.
What the rating does
The risk rating on its own changes no approval workflow and adds no review step. Which steps a request runs through is defined by the role's approval workflow; additional steps only arise from risk findings. The rating feeds into the recertification flag “External w/ high access” and serves role mining and AI analyses as context.
AI analysis of an identity
If an AI mode is active, administrators can have an AI analysis created for an identity. It estimates a risk level and names anomalies and recommendations. The result can be edited and saved; it changes no ratings and no assignments. See Overview and modes.