Mitigated Roles
Use
Use the Mitigated Roles screen to assign mitigating controls to a role.
Prerequisites
You must first define a mitigating control before you can assign it to a role to mitigate an access risk.
Assigning Mitigating Controls to Roles
-
Choose .
The Mitigated Roles screen displays a list of existing roles to which mitigating controls have been assigned.
-
Choose Assign.
The Roles Mitigation dialog box opens.
-
Enter information in the required fields marked with an asterisk (*).
-
Access Risk ID – Select the field to enter the access risk ID.
-
Control ID – Enter the control ID.
-
Monitor – Automatically populated with system data after you choose the control ID.
-
Valid From – Start of the mitigating control period.
-
Valid To – End of the mitigating control period.
-
Status – Choose Active or Inactive from the dropdown list.
-
-
Choose Add to associate a system to the mitigating control.
-
Choose Add to associate a role to the mitigating control.
-
Choose .
The mitigating control you assigned is included in the list on the Mitigated Roles screen.
Deleting Mitigating Controls from Roles
-
Choose .
The Mitigated Roles screen displays a list of existing roles to which mitigating controls have been assigned.
-
Select the role you want to delete and choose Delete.
Confirm your decision to delete this mitigating control.
-
Choose Yes.
The mitigating control is removed from the Mitigated Roles screen.

