Migration process
Overview of the process to migrate the data from IBM Security Verify Governance - Verify Governance (ISVG-GOV) system (alternatively called as IGI) to IBM Verify Identity Governance (IVIG).
Overview
This topic describes the recommended migration process to migrate your ISVG-IGI data to IVIG .
Migration process
It is recommended to follow following execution flow for performing the IGI Migration.
-
Read all the configurations from IGI.
-
Read User configurations
-
Read Application configurations
-
Read Account configurations
-
Read OU configurations
-
Read Role configurations
-
Read Provisioning rules
-
Read Campaign configurations
-
Read Email notifications
-
-
Read, convert and load OUs
-
Read OU
-
Convert OU
-
Load OU
-
-
Read Users using the IGI Migration utility.
-
Read Users
-
Load users into IVIG via datasource/feed service.
-
-
Read, convert and load services.
-
Read connectors
-
Convert connectors - This will automatically convert and load the services in IVIG.
-
Once the service is loaded into IVIG, please update the service password on the service form and perform a test connection operation.
-
Create the required policies for this service like adoption policy and provisioning policy.
-
Then perform a service reconciliation.
-
Once the service reconciliation is successful, enable access for all the required reconciled groups.
-
-
Read, convert and load roles.
-
Read roles - This will read application and organizational roles and generate separate CSV files for both.
-
Convert roles - This will convert the application roles from CSV to JSON format.
-
Load roles - This will automatically load application roles and its composition. It will then convert and load the organizational roles and its composition.
-
-
Read, convert and load risks.
-
Read risks.
-
Convert risks.
-
Load risks.
-
-
Read, convert and load mitigations.
-
Read mitigations.
-
Convert mitigations. - This will convert and load the mitigations in IVIG. It will also associate the mitigations to applicable risks.
-
-
Read, convert and load business activities.
-
Read business activities.
-
Convert business activities. - This will convert and load the business activities in IVIG. It will also perform below mappings,
-
Associate business activities with the existing risks.
-
Associate business activities with the existing permissions.
-
Finally, associate risky users to mitigations. If all users aren't evaluated by the time this script is called, it is recommended to use load mitigations with operation as retry. Below is an example for the same.
./migration.sh -dbu <IGI_DB_User> -dbp <IGI_DB_Password> -ivigu <IVIG_User> -ivigp <IVIG_Password> -o retry -e mitigations
-
-