Description | When checking the overall risk of an IAM account under the CIEM dossier, the overall risk is sometime not the highest risk of its component. This article will explain why and in which case this overall risk is calculated to be higher. |
Scope | CIEM, FortiCNAPP |
Solution |
In the CIEM, the Risk Severity of an IAM account can be higher than the risk of each of the composite property risk.
In this example, the user has the following high risk: Allows full admin, but has also a low risk: Unused user (for 180 days). |
Labels: