Rules Introduction to Policies, Rules, and Conditions

10-6 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager The All Users option links a policy to all users. If group linking shows All Users, all the available linking is ignored. If a user selects group linking as All Users, the link option would be disabled.

10.1.9 Run Mode

Run mode is either All Users or Linked Users. It determines if a policy is evaluated for all users or for the user groups linked to that policy. If a policy is being evaluated as a nested policy then the run mode is ignored.

10.1.10 Trigger Combinations and Triggers

Trigger combinations are additional results and policy evaluation that are generated if a specific sequence of rules trigger. Trigger combinations can be used to override the outcome of rules. Each trigger combination can specify alerts, actions and either a score or another policy to run. Trigger combinations evaluate sequentially, stopping as soon as a rule return combination is matched. Alerts are added to any actions and alerts triggered by individual rules. Action group replace the actions returned by the individual rules. When a trigger combination triggers another policy, that policy is said to be nested within the policy. A policy can be nested within other policies and also can be evaluated on its own. For information on trigger combinations, see Section 10.13, Working with Trigger Combinations. For an example of setting up a trigger combination, see Section 10.34.7, Use Case: Trigger Combination.

10.1.11 Nested Policies

A nested policy is a secondary policy used to further quantify the risk score in instances where the original result output by the system is inconclusive. Nested policies can be assigned to ensure a higher degree of accuracy for the risk score. A nested policy in a trigger combination is executed only when a specific sequence of rule results is sent from the primary policy. Nested policies therefore reduce false positives and negatives.

10.1.12 Evaluating a Policy within a Rule

Oracle Adaptive Access Manager can evaluate another policy as part of a rule by using the System: Evaluation Policy condition. The result of the evaluated policy is propagated. This is called a condition execution.

10.1.13 Scores and Weight

The score is a number configured by the user that is assigned to a rule when the rule evaluates to true. The user can configure a scoring policy that is used to combine the scores of the rules in a policy and assign a score to the policy. The scores from various policies are combined using a policy set level scoring policy. Weight is the multiplier values used on policies scores to influence the total score. For more information on scores and weights and how they are used in risk assessment, see Chapter 14, Using the Scoring Engine.