---
title: Cognos Security – The High Cost of Not Knowing
description: Understanding Cognos security and applying it correctly is the cornerstone of any successful implementation of security in a Cognos environment.
image: https://www.envisn.com/hubfs/security-cube.png
---

[![envisn](https://www.envisn.com/hs-fs/file-15282154-gif/images/logo.gif?width=120&name=logo.gif "envisn")](https://www.envisn.com)

[![Request a Demo](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/70307/973f9256-ef61-4ab8-ab2d-a004a90a18be.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/70307/973f9256-ef61-4ab8-ab2d-a004a90a18be)

[![cognos security as youve never seen it - learn more about netvisn](https://www.envisn.com/hs/cta/cta/default/70307/3166c389-8135-4d84-9988-99dc8d523426.png)](https://www.envisn.com/hs/cta/cta/redirect/70307/3166c389-8135-4d84-9988-99dc8d523426)

# Envisn's IBM Cognos Blog

## [Cognos Security – The High Cost of Not Knowing](https://www.envisn.com/envisn-cognos-blog/cognos-security-the-high-cost-of-not-knowing)

Posted by [The Envisn Team](https://www.envisn.com/envisn-cognos-blog/author/the-envisn-team)

- [Tweet](https://twitter.com/share)

*![cognos security dimensions](https://www.envisn.com/hs-fs/hubfs/security-cube.png?width=300&name=security-cube.png)By Paul Hausser, [Envisn, Inc.](https://www.envisn.com/)*

Of all the areas of Cognos administration the one that appears to cause the most anxiety is security. This likely is the result of the fact that there are so many ways that security can be applied within Cognos Analytics. The distinction between groups and roles, for example, and how they each should be used is one of the least understood aspects of correctly applying security in Cognos. Yet doing this correctly is the cornerstone of any successful implementation of security in Cognos.

A question frequently asked, but not often openly expressed, is this: ***“Is security correctly applied across our Cognos environment?”* **

You can be sure that the larger the environment the more likely this question has been on the minds of some people, likely more than once. Any major breach of data security often results in the loss of someone’s job.

## Key Questions

So what’s behind this anxiety? Well, first off, simply asking the question clearly implies that there is some defined model for how security ***should be applied*** across the environment and that it’s detailed enough to cover all key dimensions of security. This presumes that one was created at some point in time and updated as the organization changed and evolved. Often however, the existing Cognos security model has been in place for a few years and the person or persons that created it are no longer around.

Secondly, this also implies that we have a means of clearly determining if the security we currently have in place across Cognos is correctly aligned with our model. Without a tool that enable us to do this relatively easily and quickly this could be seen as an impossible task and likely never addressed at all. But there are tools that make this possible and will enable you to assess all dimension of security across your Cognos environment. This means groups, roles, objects, folders, accounts, data items, etc. – everything.

In the figure below we see an analysis of roles in a sample environment. There are 47 total roles in this one and they are laid out in a way that we can see that some roles include not only accounts but other roles as well. It also shows how some of these may overlap.

[![cognos security roles report](https://www.envisn.com/hs-fs/hubfs/security-roles.jpg?width=700&name=security-roles.jpg)](https://www.envisn.com/cognos-security-management)

## Responsibilities

Perhaps the biggest question of all is, *“Who is responsible for insuring that security is correctly applied across the Cognos environment?”* Is it assigned to one person, a group or some combination? Without a single point of focus you should probably be nervous at this point.

So how do you get your arms around this? A good beginning would be to simply begin asking questions and see where it leads.

Every Cognos administrator should asked themselves the question, *“How much is it worth for me to know that our security model is correctly applied across Cognos?”* If it hasn’t already been answered, then just asking the question is likely to result in action of some type. The key is to have it focused on getting actionable results.

Some guidelines on getting the answer and dealing with results to these questions:

- 1. Don’t ask the question unless you’re prepared for what’s required to get the answer. This implies having a tool or tools that enables you to get the answer relatively easily and quickly.
- 2. Don’t ask the question unless you’re prepared to do something with the results. Often this can mean a lot of work to fix things that need to be changed.
- 3. Depending on what you find it can often be easier to create a new security model than trying to fix an existing one that has been corrupted over time. Often this happens for two principal reason:   
       *a.* People assigning new users or creating new groups and roles do not understand how groups and roles differ and how they should best be used.   
       *b.* Too many people have the ability to make changes to the security model.
- 4. Stay in the lanes. Use groups and roles for what they are intended for and minimize exceptions to using them whenever possible. For more on correctly implementing Cognos security download our **[eBook](https://www.envisn.com/mastering-ibm-cognos-security)** on this subject.
- 5. Restrict the number of people able to assign or make changes to security to the fewest number possible.

In an age when there is a clear expectation that the data the company uses to manage itself at all levels is rock solid secure there’s a high cost to not knowing if that’s really true.

*© - Envisn, Inc. – All rights Reserved. [Cognos Security made Simple with NetVisn](https://www.envisn.com/netvisn)  
*

*[![Learn more about how you can manage Cognos Security more efficiently with Netvisn.](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/70307/5535547f-38e0-4788-a1c6-4e2f29dee513.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/70307/5535547f-38e0-4788-a1c6-4e2f29dee513)*

 

 Topics: [Cognos Security](https://www.envisn.com/envisn-cognos-blog/topic/cognos-security), [Cognos BI administration](https://www.envisn.com/envisn-cognos-blog/topic/cognos-bi-administration), [Cognos Analytics](https://www.envisn.com/envisn-cognos-blog/topic/cognos-analytics)

*Your feedback is very important to us - we’d love to hear your comments!*

### Subscribe to Envisn's IBM Cognos Blog

[![mastering ibm cognos security free ebook download](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/70307/f3242640-738f-4821-8e4f-5ff9715968cd.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/70307/f3242640-738f-4821-8e4f-5ff9715968cd)

### Posts by Category

- [Cognos Content Store (22)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-content-store)
- [Cognos BI Best Practices (21)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-bi-best-practices)
- [Cognos Analytics (19)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-analytics)
- [Cognos BI administration (19)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-bi-administration)
- [Cognos Security (18)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-security)
- [Cognos Tools (14)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-tools)
- [Cognos Audit Data (11)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-audit-data)
- [Cognos Reporting (9)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-reporting)
- [Cognos Auditing (8)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-auditing)
- [Cognos 10 (7)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-10)
- [Cognos Framework Manager (7)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-framework-manager)
- [Cognos Metadata (7)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-metadata)
- [BI Trends (6)](https://www.envisn.com/envisn-cognos-blog/topic/bi-trends)
- [IBM Information on Demand (6)](https://www.envisn.com/envisn-cognos-blog/topic/ibm-information-on-demand)
- [Cognos Audit Log (5)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-audit-log)
- [cognos impact analysis (4)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-impact-analysis)
- [Big Data (3)](https://www.envisn.com/envisn-cognos-blog/topic/big-data)
- [Cognos Data Sources (3)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-data-sources)
- [Cognos Documentation (3)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-documentation)
- [Cognos Scheduling (3)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-scheduling)
- [Product Information (3)](https://www.envisn.com/envisn-cognos-blog/topic/product-information)
- [cognos data lineage (3)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-data-lineage)
- [Archiving Cognos Content (2)](https://www.envisn.com/envisn-cognos-blog/topic/archiving-cognos-content)
- [Cognos FM Model (2)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-fm-model)
- [Cognos migration (2)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-migration)
- [Announcements (1)](https://www.envisn.com/envisn-cognos-blog/topic/announcements)
- [Cognos Change Management (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-change-management)
- [Cognos Data Provenance (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-data-provenance)
- [Cognos Hotfiles (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-hotfiles)
- [Cognos Powerplay (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-powerplay)
- [Cognos Triggers (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-triggers)
- [Consolidating Cognos Environments (1)](https://www.envisn.com/envisn-cognos-blog/topic/consolidating-cognos-environments)
- [Impromptu (1)](https://www.envisn.com/envisn-cognos-blog/topic/impromptu)
- [Merging Content Stores (1)](https://www.envisn.com/envisn-cognos-blog/topic/merging-content-stores)
- [Remote Cognos Management (1)](https://www.envisn.com/envisn-cognos-blog/topic/remote-cognos-management)
- [cognos deployments (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-deployments)
- [cognos fm model documentation (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-fm-model-documentation)
- [cognos workspace (1)](https://www.envisn.com/envisn-cognos-blog/topic/cognos-workspace)
- [netvisn (1)](https://www.envisn.com/envisn-cognos-blog/topic/netvisn)

[see all](https://www.envisn.com/envisn-cognos-blog/cognos-security-the-high-cost-of-not-knowing#)

### Posts by Popularity

[![All security settings are fully visible for all users, groups, roles, and objects in Netvisn - learn more](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/70307/4a0fef01-3264-4d06-9272-3b054d9b900b.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/70307/4a0fef01-3264-4d06-9272-3b054d9b900b)

### [Cognos Tools from Envisn](https://www.envisn.com/envisn-products)

[NetVisn](https://www.envisn.com/netvisn)  
[AutoVisn](https://www.envisn.com/autovisn-cogos-scheduler)  
[UniVisn](https://www.envisn.com/univisn-cognos-performance-management)  
[DocuVisn](https://www.envisn.com/docuvisn-cognos-documentation)

### [Cognos Resources](https://www.envisn.com/resources)

[Envisn’s IBM Cognos Blog](https://www.envisn.com/envisn-cognos-blog)  
[Custom Query Library](https://www.envisn.com/custom-query-library)  
[Tutorial Videos](https://www.envisn.com/cognos-demo-videos)  
[Mastering Cognos Security](https://www.envisn.com/mastering-ibm-cognos-security)  
[Content Store Survival Guide](https://www.envisn.com/content-store-survival-guide)  
[Expert Guide to Cognos Audit Data](https://www.envisn.com/cognos-audit-data-expert-guide)

### [Contact Envisn](https://www.envisn.com/contact)

[Request a Demo](https://www.envisn.com/request-a-demo)  
[Support](https://www.envisn.com/support)

512-991-3999  
[info@envisn.com](mailto:info@envisn.com)

### Latest Cognos Posts

| [![youtube](https://www.envisn.com/hs-fs/hubfs/youtube.png?width=30&name=youtube.png)](https://www.youtube.com/user/envisn) | [![linkedin](https://www.envisn.com/hs-fs/hubfs/linkedin.png?width=30&name=linkedin.png)](https://www.linkedin.com/company/envisn-inc./) | [![twitter](https://www.envisn.com/hs-fs/hubfs/twitter.png?width=30&name=twitter.png)](https://twitter.com/Envisn) | [![facebook](https://www.envisn.com/hs-fs/hubfs/facebook.png?width=30&name=facebook.png)](https://www.facebook.com/envisn/) |
| --- | --- | --- | --- |

[![Real Time Analytics](https://static.getclicky.com/media/links/badge.gif)](http://clicky.com/101126274)

![Clicky](https://in.getclicky.com/101126274ns.gif)

3000 Polar Lane, Suite 901, Cedar Park, TX 78613 USA  
*Serving North America, Europe, and the UK with plans to expand to other areas in the near future. **[Privacy, Copyright & Liability](https://www.envisn.com/privacy-copyright-liability)*