Lacework
Access helpful articles and other FAQs on Lacework
vschmitt_FTNT
Article Id 380797
Description When checking the overall risk of an IAM account under the CIEM dossier, the overall risk is sometime not the highest risk of its component.
This article will explain why and in which case this overall risk is calculated to be higher.
Scope CIEM, FortiCNAPP
Solution

In the CIEM, the Risk Severity of an IAM account can be higher than the risk of each of the composite property risk.
This is the case for the an admin user that has not been used for 180 days:

 

kbarticleallowsfulladmin.png

 

In this example, the user has the following high risk: Allows full admin, but has also a low risk: Unused user (for 180 days).
The combination of these 2 risks will create an overall Critical risk for the following reason because Lacework's CIEM considers Unused User to be a significant factor worth elevating the Risk Severity from High to Critical.