SlideShare una empresa de Scribd logo
1 de 27
Descargar para leer sin conexión
30.10.2013
FSP GmbH | Product Presentation
Agenda

Company Overview
Product Presentation
Access Governance Suite
Live Demo
Discussion

30.10.2013

ORG Product Presentation

2
Company Overview

Founded in 2002
Headquarters: Cologne
Represented throughout
Germany
40 employees
30.10.2013

ORG Product Presentation

3
Company Overview:
Software & Consulting

Software

Business Consulting
• Access Governance Concepts
• Process Optimization
• Project- / Test Management

IT Consulting & Development
• Software Development
• IT Security

• IT-Project- / Test Management

30.10.2013

ORG Product Presentation

4
Company Overview:
Customers

30.10.2013

ORG Product Presentation

5
Agenda

Company Overview
Product Presentation
Access Governance Suite
Live Demo
Discussion

30.10.2013

ORG Product Presentation

6
Access Management:
Conventional method

RACF

Group

SAP HR

SAP-Role

Indiv. Applications

Groups / Individual Rights

P&C Administration

Individual Rights

Partner System

Individual Rights

Notes/Outlook

Group

LDAP

e.g. Group Membership

Databases
Employee

Several System-Administrators

Indiv. / Role

Individual Systems often use Individual Rights

New Entry, Fluctuation,
Departmental Change
30.10.2013

ORG Product Presentation

7
Solution: ORG
Central administration of user rights

Interfaces:
SPML-Systems:
- Novell Identity Manager
- IBM Tivoli Directory Integrator
- openSPML

Directory Systems
‐
‐
‐
-

Employee
New Entry
Fluctuation
Departmental Change

Central, lean Administration
User Rights based on:
- Roles/Rights model
- Attributes

Other systems
‐ SAP R3
‐ RACF
‐ INTERFLEX

APIs
-

External
Known customer
Prospect
…

Microsoft AD
IBM Tivoli Directory Server
openLDAP
Novell eDirectory
SUN one Directory Server
…

Java (SE & EE)
Windows / Unix (C)
z/OS (Cobol, PL/1, C)

automated provisioning

30.10.2013

ORG Product Presentation

8
ORG Architecture:
Basis for USPs

30.10.2013

ORG Product Presentation

9
Model: Entities

OrganizationalUnit

Position

User

Organizational
Structure

Client

Location

Role

Role group

Competence scheme

Role model

Permissions

Competence
Role conflict

30.10.2013

ORG Product Presentation

10
Model: Historicizing, life cycle

Time

Status:
future

Create

Status:
current
Edit or delete
No physical deletion:
The database entry is
marked as „deleted“

Status:
historicized
Expired or deleted

Historicizing of all changes of an
object or a relation between objects
including the initiator and the time

30.10.2013

ORG Product Presentation

11
SPML Webservice: Architecture

Interface to approval workflow:
• ORG Approve
• Lotus Notes
• SharePoint
• etc.

• Interface to higher-level systems:
• HR-Systems (z.B. SAP HR, …)
• IDM-Systems (z.B. IBM TIM, Novell IDM, …)
• etc.
30.10.2013

ORG Product Presentation

12
Approval Workflow (with ORG Approve)

• Self Service
• Appliable permission requests depend on the owners role
(e.g. a normal employee is not permitted to request an
executive‘s role)
• 4-eyes principle supported
(parallel and sequentially)
• MaRisk AT 7.2 conform

30.10.2013

ORG Product Presentation

13
Standard: RBAC

30.10.2013

ORG Product Presentation

14
Model: Standard software

Modeling
• User and Role are always available.
• Position, Role group and
Organization Unit are optional.

External system
User
Organization
- unit

Typical use

Position

• Storage systems with their own
detailled permissions.
• E. g. the system has to enable roles
or groups to carry authorizations.

Role group
Role

Examples
• LDAP-Directory (z.B. Active Directory)
• SAP
• RACF
30.10.2013

User

Role or group

Indiv. rights

ORG Product Presentation

15
ORG Connector: Architecture

30.10.2013

ORG Product Presentation

16
ORG Connector: Attribute mapping

Attribute mappings are free configurable
Source in ORG can be:
Attribute of the user
Values of a users competence to a random Competence Scheme
Composite values via formation rule

30.10.2013

ORG Product Presentation

17
USP: Fine Grained
Attribute based, more than role based

30.10.2013

ORG Product Presentation

18
Model: Homegrown software

Modeling
User
• Users and competency scheme are
always available
• Position, role group, role and OU
are optional.
• Competencies can be defined for
users, roles or positions.

Typical use
• House developments
• Systems in which an
exit is provided for the procurement of
allowances.

30.10.2013

Position

Organization
- unit

Role group

Role

Competence
Competence scheme

ORG Product Presentation

19
ORG APIs: Access to runtime db

30.10.2013

ORG Product Presentation

20
Process logic: Runtime DB access

Application
life

Functional
Authorization capsule

ORG
API

Verify the payout
isPayoutPermitted(userid,value)
hasCompetence(userid,“PayoutContract“,“Life“,value
)

Database-consultation

Result (Yes or No)
Result (Yes or No)

•
•

The Process-logic is basically at all APIs the same.
It makes sense to summarize all functional authorizations of a application to one specific Functional
Authorization capsule.

30.10.2013

ORG Product Presentation

21
Interfaces

SPML systems:
• Novell Identity Manager

• IBM Tivoli Directory Integrator
• openSPML
Other connectors available for:
Directory systems:

•

SAP R3

• Microsoft Active Directory

•

RACF

• IBM Tivoli Directory Server

•

SharePoint

• openLDAP

•

INTERFLEX

• Novell eDirectory
• SUN one Directory Server

APIs available for the following platforms:

• ApacheDS

•

Java (SE & EE)

• RACF LDAP-Server

•

Windows / Unix (C)

• other systems

•

z/OS (Cobol, PL/1, C)

30.10.2013

ORG Product Presentation

22
Summary

• Single Point of Administration and Control
• Reduction of Time, Cost and Complexity
• History management / Revision proof
• Supports RBAC / ABAC
• Integration in company-wide environments is proven

• Integration of organizational structure information
• Distributed and delegated administration (configurable)
• Multi-client capable
• High performance & fail save
• Corporate Design applicable

30.10.2013

ORG Product Presentation

23
Agenda

Company Overview
Product Presentation
Access Governance Suite
Live Demo
Discussion

30.10.2013

ORG Product Presentation

24
Access Governance Suite

30.10.2013

ORG Product Presentation

25
Agenda

Company Overview
Product Presentation
Access Governance Suite
Live Demo
Discussion

30.10.2013

ORG Product Presentation

26
Live Demo

FSP GmbH
Consulting & IT-Services
Albin-Köbis Straße 8
D-51147 Cologne
Tel.: +49 (0) 2203 / 371 000 – 0

www.fsp-org.com
30.10.2013

ORG Product Presentation

27

Más contenido relacionado

Similar a ORG Access Management: Technical Details

Community vs. Commercial Open Source
Community vs. Commercial Open SourceCommunity vs. Commercial Open Source
Community vs. Commercial Open SourceJustin Reock
 
Emerging standards and support organizations within engineering simulation
Emerging standards and support organizations within engineering simulation Emerging standards and support organizations within engineering simulation
Emerging standards and support organizations within engineering simulation Modelon
 
Software variability management - 2017
Software variability management - 2017Software variability management - 2017
Software variability management - 2017XavierDevroey
 
The Real Scoop on Migrating from Oracle Databases
The Real Scoop on Migrating from Oracle DatabasesThe Real Scoop on Migrating from Oracle Databases
The Real Scoop on Migrating from Oracle DatabasesEDB
 
Introduction to basics of drupal
Introduction to basics of drupalIntroduction to basics of drupal
Introduction to basics of drupallrtraining05
 
Reducing the Risks of Migrating Off Oracle
Reducing the Risks of Migrating Off OracleReducing the Risks of Migrating Off Oracle
Reducing the Risks of Migrating Off OracleEDB
 
Software Product Lines by Dr. Indika Kumara
Software Product Lines by Dr. Indika KumaraSoftware Product Lines by Dr. Indika Kumara
Software Product Lines by Dr. Indika KumaraThejan Wijesinghe
 
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3Marco Gralike
 
SpagoBI - the Business Intelligence Free Platform
SpagoBI - the Business Intelligence Free PlatformSpagoBI - the Business Intelligence Free Platform
SpagoBI - the Business Intelligence Free Platformdavide.zerbetto
 
The Race To 50 Million Page Views
The Race To 50 Million Page ViewsThe Race To 50 Million Page Views
The Race To 50 Million Page ViewsLogicworksNY
 
QA team transition to agile testing at Alcatel Lucent
QA team transition to agile testing at Alcatel LucentQA team transition to agile testing at Alcatel Lucent
QA team transition to agile testing at Alcatel LucentAgileSparks
 
Analyti x mapping manager product overview presentation
Analyti x mapping manager product overview presentationAnalyti x mapping manager product overview presentation
Analyti x mapping manager product overview presentationAnalytixDataServices
 
Oslc case study (poc results) v1.1
Oslc case study (poc results) v1.1Oslc case study (poc results) v1.1
Oslc case study (poc results) v1.1Joseph Lopez, M.ISM
 
DS, BP, EJB, CDI, WTF!? - Graham Charters
DS, BP, EJB, CDI, WTF!? - Graham ChartersDS, BP, EJB, CDI, WTF!? - Graham Charters
DS, BP, EJB, CDI, WTF!? - Graham Chartersmfrancis
 
SYSTEMS PRESENTATION to help you in design
SYSTEMS PRESENTATION to help you  in designSYSTEMS PRESENTATION to help you  in design
SYSTEMS PRESENTATION to help you in designrhesusfactor848
 
Service Lifecycle Management with Fuse Service Works
Service Lifecycle Management with Fuse Service WorksService Lifecycle Management with Fuse Service Works
Service Lifecycle Management with Fuse Service WorksKenneth Peeples
 
Winning performance challenges in oracle standard editions
Winning performance challenges in oracle standard editionsWinning performance challenges in oracle standard editions
Winning performance challenges in oracle standard editionsPini Dibask
 
F17_Unified Governance for Power Automate, Power Apps, Power BI
F17_Unified Governance for Power Automate, Power Apps,  Power BIF17_Unified Governance for Power Automate, Power Apps,  Power BI
F17_Unified Governance for Power Automate, Power Apps, Power BIserge luca
 
Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager OracleIDM
 
Streamline it management
Streamline it managementStreamline it management
Streamline it managementDLT Solutions
 

Similar a ORG Access Management: Technical Details (20)

Community vs. Commercial Open Source
Community vs. Commercial Open SourceCommunity vs. Commercial Open Source
Community vs. Commercial Open Source
 
Emerging standards and support organizations within engineering simulation
Emerging standards and support organizations within engineering simulation Emerging standards and support organizations within engineering simulation
Emerging standards and support organizations within engineering simulation
 
Software variability management - 2017
Software variability management - 2017Software variability management - 2017
Software variability management - 2017
 
The Real Scoop on Migrating from Oracle Databases
The Real Scoop on Migrating from Oracle DatabasesThe Real Scoop on Migrating from Oracle Databases
The Real Scoop on Migrating from Oracle Databases
 
Introduction to basics of drupal
Introduction to basics of drupalIntroduction to basics of drupal
Introduction to basics of drupal
 
Reducing the Risks of Migrating Off Oracle
Reducing the Risks of Migrating Off OracleReducing the Risks of Migrating Off Oracle
Reducing the Risks of Migrating Off Oracle
 
Software Product Lines by Dr. Indika Kumara
Software Product Lines by Dr. Indika KumaraSoftware Product Lines by Dr. Indika Kumara
Software Product Lines by Dr. Indika Kumara
 
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3
An introduction into Oracle Enterprise Manager Cloud Control 12c Release 3
 
SpagoBI - the Business Intelligence Free Platform
SpagoBI - the Business Intelligence Free PlatformSpagoBI - the Business Intelligence Free Platform
SpagoBI - the Business Intelligence Free Platform
 
The Race To 50 Million Page Views
The Race To 50 Million Page ViewsThe Race To 50 Million Page Views
The Race To 50 Million Page Views
 
QA team transition to agile testing at Alcatel Lucent
QA team transition to agile testing at Alcatel LucentQA team transition to agile testing at Alcatel Lucent
QA team transition to agile testing at Alcatel Lucent
 
Analyti x mapping manager product overview presentation
Analyti x mapping manager product overview presentationAnalyti x mapping manager product overview presentation
Analyti x mapping manager product overview presentation
 
Oslc case study (poc results) v1.1
Oslc case study (poc results) v1.1Oslc case study (poc results) v1.1
Oslc case study (poc results) v1.1
 
DS, BP, EJB, CDI, WTF!? - Graham Charters
DS, BP, EJB, CDI, WTF!? - Graham ChartersDS, BP, EJB, CDI, WTF!? - Graham Charters
DS, BP, EJB, CDI, WTF!? - Graham Charters
 
SYSTEMS PRESENTATION to help you in design
SYSTEMS PRESENTATION to help you  in designSYSTEMS PRESENTATION to help you  in design
SYSTEMS PRESENTATION to help you in design
 
Service Lifecycle Management with Fuse Service Works
Service Lifecycle Management with Fuse Service WorksService Lifecycle Management with Fuse Service Works
Service Lifecycle Management with Fuse Service Works
 
Winning performance challenges in oracle standard editions
Winning performance challenges in oracle standard editionsWinning performance challenges in oracle standard editions
Winning performance challenges in oracle standard editions
 
F17_Unified Governance for Power Automate, Power Apps, Power BI
F17_Unified Governance for Power Automate, Power Apps,  Power BIF17_Unified Governance for Power Automate, Power Apps,  Power BI
F17_Unified Governance for Power Automate, Power Apps, Power BI
 
Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager
 
Streamline it management
Streamline it managementStreamline it management
Streamline it management
 

Último

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Angeliki Cooney
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 

Último (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 

ORG Access Management: Technical Details

  • 1. 30.10.2013 FSP GmbH | Product Presentation
  • 2. Agenda Company Overview Product Presentation Access Governance Suite Live Demo Discussion 30.10.2013 ORG Product Presentation 2
  • 3. Company Overview Founded in 2002 Headquarters: Cologne Represented throughout Germany 40 employees 30.10.2013 ORG Product Presentation 3
  • 4. Company Overview: Software & Consulting Software Business Consulting • Access Governance Concepts • Process Optimization • Project- / Test Management IT Consulting & Development • Software Development • IT Security • IT-Project- / Test Management 30.10.2013 ORG Product Presentation 4
  • 6. Agenda Company Overview Product Presentation Access Governance Suite Live Demo Discussion 30.10.2013 ORG Product Presentation 6
  • 7. Access Management: Conventional method RACF Group SAP HR SAP-Role Indiv. Applications Groups / Individual Rights P&C Administration Individual Rights Partner System Individual Rights Notes/Outlook Group LDAP e.g. Group Membership Databases Employee Several System-Administrators Indiv. / Role Individual Systems often use Individual Rights New Entry, Fluctuation, Departmental Change 30.10.2013 ORG Product Presentation 7
  • 8. Solution: ORG Central administration of user rights Interfaces: SPML-Systems: - Novell Identity Manager - IBM Tivoli Directory Integrator - openSPML Directory Systems ‐ ‐ ‐ - Employee New Entry Fluctuation Departmental Change Central, lean Administration User Rights based on: - Roles/Rights model - Attributes Other systems ‐ SAP R3 ‐ RACF ‐ INTERFLEX APIs - External Known customer Prospect … Microsoft AD IBM Tivoli Directory Server openLDAP Novell eDirectory SUN one Directory Server … Java (SE & EE) Windows / Unix (C) z/OS (Cobol, PL/1, C) automated provisioning 30.10.2013 ORG Product Presentation 8
  • 9. ORG Architecture: Basis for USPs 30.10.2013 ORG Product Presentation 9
  • 10. Model: Entities OrganizationalUnit Position User Organizational Structure Client Location Role Role group Competence scheme Role model Permissions Competence Role conflict 30.10.2013 ORG Product Presentation 10
  • 11. Model: Historicizing, life cycle Time Status: future Create Status: current Edit or delete No physical deletion: The database entry is marked as „deleted“ Status: historicized Expired or deleted Historicizing of all changes of an object or a relation between objects including the initiator and the time 30.10.2013 ORG Product Presentation 11
  • 12. SPML Webservice: Architecture Interface to approval workflow: • ORG Approve • Lotus Notes • SharePoint • etc. • Interface to higher-level systems: • HR-Systems (z.B. SAP HR, …) • IDM-Systems (z.B. IBM TIM, Novell IDM, …) • etc. 30.10.2013 ORG Product Presentation 12
  • 13. Approval Workflow (with ORG Approve) • Self Service • Appliable permission requests depend on the owners role (e.g. a normal employee is not permitted to request an executive‘s role) • 4-eyes principle supported (parallel and sequentially) • MaRisk AT 7.2 conform 30.10.2013 ORG Product Presentation 13
  • 15. Model: Standard software Modeling • User and Role are always available. • Position, Role group and Organization Unit are optional. External system User Organization - unit Typical use Position • Storage systems with their own detailled permissions. • E. g. the system has to enable roles or groups to carry authorizations. Role group Role Examples • LDAP-Directory (z.B. Active Directory) • SAP • RACF 30.10.2013 User Role or group Indiv. rights ORG Product Presentation 15
  • 17. ORG Connector: Attribute mapping Attribute mappings are free configurable Source in ORG can be: Attribute of the user Values of a users competence to a random Competence Scheme Composite values via formation rule 30.10.2013 ORG Product Presentation 17
  • 18. USP: Fine Grained Attribute based, more than role based 30.10.2013 ORG Product Presentation 18
  • 19. Model: Homegrown software Modeling User • Users and competency scheme are always available • Position, role group, role and OU are optional. • Competencies can be defined for users, roles or positions. Typical use • House developments • Systems in which an exit is provided for the procurement of allowances. 30.10.2013 Position Organization - unit Role group Role Competence Competence scheme ORG Product Presentation 19
  • 20. ORG APIs: Access to runtime db 30.10.2013 ORG Product Presentation 20
  • 21. Process logic: Runtime DB access Application life Functional Authorization capsule ORG API Verify the payout isPayoutPermitted(userid,value) hasCompetence(userid,“PayoutContract“,“Life“,value ) Database-consultation Result (Yes or No) Result (Yes or No) • • The Process-logic is basically at all APIs the same. It makes sense to summarize all functional authorizations of a application to one specific Functional Authorization capsule. 30.10.2013 ORG Product Presentation 21
  • 22. Interfaces SPML systems: • Novell Identity Manager • IBM Tivoli Directory Integrator • openSPML Other connectors available for: Directory systems: • SAP R3 • Microsoft Active Directory • RACF • IBM Tivoli Directory Server • SharePoint • openLDAP • INTERFLEX • Novell eDirectory • SUN one Directory Server APIs available for the following platforms: • ApacheDS • Java (SE & EE) • RACF LDAP-Server • Windows / Unix (C) • other systems • z/OS (Cobol, PL/1, C) 30.10.2013 ORG Product Presentation 22
  • 23. Summary • Single Point of Administration and Control • Reduction of Time, Cost and Complexity • History management / Revision proof • Supports RBAC / ABAC • Integration in company-wide environments is proven • Integration of organizational structure information • Distributed and delegated administration (configurable) • Multi-client capable • High performance & fail save • Corporate Design applicable 30.10.2013 ORG Product Presentation 23
  • 24. Agenda Company Overview Product Presentation Access Governance Suite Live Demo Discussion 30.10.2013 ORG Product Presentation 24
  • 25. Access Governance Suite 30.10.2013 ORG Product Presentation 25
  • 26. Agenda Company Overview Product Presentation Access Governance Suite Live Demo Discussion 30.10.2013 ORG Product Presentation 26
  • 27. Live Demo FSP GmbH Consulting & IT-Services Albin-Köbis Straße 8 D-51147 Cologne Tel.: +49 (0) 2203 / 371 000 – 0 www.fsp-org.com 30.10.2013 ORG Product Presentation 27