Oracle Waveset 8.1.1 Business Administrator's Guide

Managing Attestation Duties

You can manage attestation requests from the Waveset Administrator or User interface. This section provides information about responding to attestation requests and the duties involved in attestation.

Access Review Notification

During a scan, Waveset sends notification to Attestors when attestation requests require their approval. If attestor responsibilities have been delegated, the requests are sent to the delegate. If multiple attestors are defined, each attestor receives an email notification.

Requests appear as Attestation work items in the Waveset interface. Pending attestation work items are displayed when the assigned attestor logs in to Waveset.

Viewing Pending Attestation Requests

View attestation work items from the Work Items area of the interface. Selecting the Attestation tab in the Work Items area lists all the entitlement records requiring approval. From the Attestations page, you can also list entitlement records for all of your direct reports and for specified users for which you have direct or indirect control.

Acting on Entitlement Records

Attestation work items contain the user entitlement records requiring review. Entitlement records provide information about user access privileges, assigned resources, and policy violations.

The following are possible responses to an attestation request:

If an attestor does not respond to a request by taking one of these actions before the specified escalation timeout period, notice is sent to the next attestor in the escalation chain. The notification process continues until a response is logged.

Attestation status can be monitored from the Compliance -> Access Reviews tab.

Closed-Loop Remediation

You can avoid rejecting user entitlements by:

Requesting Remediation

If defined by the access scan, you can route a pending attestation to another user for remediation.


Note –

The Dynamic Entitlements option on the Create or Edit Access Scan pages enables this feature.


ProcedureTo Request Remediation From Another User

  1. Select one or more entitlements from the list of attestations, and then click Request Remediation.

    The Select and Confirm to Request Remediation page appears.

  2. Enter a user name, and then click Add to add the user to the Forward to field. Alternatively, click ... (More) to search for a user. Select the user in the search list, and then click Add to add the user to the Forward to list. Click Dismiss to close the Search area.

  3. Enter comments in the Comments field, and then click Proceed.

    Waveset returns to the list of attestations.


    Note –

    Details of the remediation request appear in the History area of the individual user entitlement.


Rescanning Attestations

If defined by the access scan, you can rescan and reevaluate a pending attestation.


Note –

The Dynamic Entitlements option on the Create or Edit Access Scan pages enables this feature.


ProcedureTo Rescan A Pending Attestation

  1. Select one or more entitlements from the list of attestations, and then click Rescan.

    The Rescan User Entitlements page appears.

  2. Enter comments about the rescan action in the Comments area, and then click Proceed.

Forwarding Attestation Work Items

You can forward one or more attestation work items to another user.

ProcedureTo Forward Attestations

  1. Select one or more work items in the attestation list, and then click Forward.

    The Select and Confirm Forwarding page appears.

  2. Enter a user name in the Forward to field. Alternatively, click ... (More) to search for a user name.

  3. Enter comments about the forwarding action in the Comments field.

  4. Click Proceed.

    Waveset returns to the list of attestations.


    Note –

    Details of the forwarding action appear in the History area of the individual user entitlement.


Digitally Signing Access Review Actions

You can set up digital signing to handle access review actions. For information about configuring digital signatures, see Signing Approvals. The topics discussed there explain the server-side and client-side configuration required to add the certificate and CRL to Waveset for signed approvals.