SecurityPosture

Changing this system option is NOT recommended. The permitted values are "permissive" and "restrictive." The default is "permissive."

Values

permissive;restrictive

Default value

permissive

Usage

The SecurityPosture system option is used in the following situations:

New Columns

Creating a new Column through the netFORUM application (not SQL) in the "Create Column" button:

Permissive: Grant permissions are given to all Groups in Group Column Privilege.

Restrictive: Grant permissions are given only to the Groups AvectraAdmin, netForumAdmin, netForumUser groups.

New Group Item Links

When new Group Item Links are added manually or through the netFORUM Object Wizard:

Permissive: all groups will gain access to new links.

Restrictive: no groups will gain access to new links. Additional access must be granted by using the Set Group Security tool as needed.

Best Practices

If you want to change this to "restrictive", you will incur additional work, but if you want this level of security granularity, this is what you'll need to do.

In practice, we find that very few of our clients use the "restrictive" setting. Instead, they take the approach, "We'll start by giving access to everyone, and then take it back as needed."

Limitations

The various SPs described in Table (add) do not consider this system option. If you are operating with the "permissive" value, then you're fine. If you are operating under the "restrictive" value, then you should run Populate Group Privileges in iWeb and choose "Undefined".

If you have the "restrictive" setting chosen, then when you run the Upgrade Tool, if Group Link Security metadata is pushed, could have the effect of granting more access than you want. If you don't want this to happen, then after running Batch Upgrade step, you'll need to manually delete all the new rows by comparing your upgrade database to a pre-upgrade database. This can be very tedious, because then you'll need to carefully add in the Group Link security records that you do want.