SlideShare una empresa de Scribd logo
1 de 21
Session ID:
Prepared by:
Build Fine-Grained Authorization
for WebCenter Using Oracle
Entitlements Server (OES)
1351
Shyam Kumar – AST Corporation
Zeeshan Baig – AST Corporation
Introduction
Shyam Kumar is the Vice President of Middleware Practice at AST
Corporation, Naperville (Chicago), IL & responsible for all aspects of
the middleware business including strategic account management
and solution architecture.
Speaker at following industry forums/conferences –
– Airport E-Business Users’ Roundtable
– 5th International SOA, Cloud + Service Technology Symposium, London
– APTA - 2013 Fare Collect-TransITech - Phoenix, AZ
– North Central Oracle Apps User Group(NCOAUG) - Chicago
– Oracle HCM Users Group (OHUG)
– Collaborate (OAUG/IOUG)
– Oracle Open World (OOW)
Zeeshan Baig is an Oracle ACE and works as Solution Architect at
Middleware Practice at AST Corporation, Naperville (Chicago), IL &
responsible for enterprise architecture for large Cloud, Mobile, Security and
Integration Projects..
Speaker at following industry forums/conferences –
– North Central Oracle Apps User Group(NCOAUG)
– RMOUG
– Collaborate (OAUG/IOUG)
– KSCOPE
Our Brands Our Services Oracle Specialized
 Enterprise Resource Planning
 Business Intelligence
 EPM-Hyperion
 Middleware
 CRM/CX
 MDM-EDQ
 Configure/Price/Quote
 Managed Services
 Education / Oracle University
 Project Advisory Services
 EBS Financial Management
 EBS Human Capital Management
 EBS Supply Chain Management
 Database
 BI Applications
 BI Foundation Suite
 Hyperion Planning & Financial Management
 Essbase
 Oracle Data Integration
 Application Development Framework
 Service Oriented Architecture
 WebCenter Content
 Access Management Suite Plus
 Identity Governance Suite
 WebLogic Server
2015, 2013, 2011, 2009
Oracle Excellence
Award Winner
2015, 2014
Chicago Tribune Top 100
Workplaces Award Winner
2014, 2013, 2012
Inc. 5000 Fastest Growing
Companies Award Winner
2014, 2012
Best & Brightest Companies to
Work For Award Winner
Specialized. Recognized. Preferred.
3
Agenda
• Authorization Overview
• Understanding Oracle Entitlement Server
• Oracle Entitlement Server Demo
• WCC – OES Implementation Approach
• Implementation Case Study
• Q & A.
4
Insider Threat
5
“Does our organization have a way to detect
unauthorized access to our data?”
“…less than 10 percent of companies actually have proactive monitoring
of security controls - Authorization?”
58% Information Security Incidents Attributed to Insider Threat
93 % of U.S. Organizations Are Vulnerable to Insider
Authorization Concepts
6
Grant “trade” privileges for the Account resource when user is in Account Trader Role:
Fine-Grained & Coarse-Grained Authorization
•Role Based (RBAC)
•Less Restrictive
Coarse-
Grained
•Attribute Based
(ABAC)
•More Restrictive
Fine-
Grained
7
Authorization Policy Definition
Application Security Requirements are defined by ‘Business Experts’
 OES provides an implementation of fine-
grained authorization
 Use policies to protect application resources
Oracle Entitlement Server (OES)
 The PAP is the OES Admin Server manages the policies
and artifacts related to security
 SM Engine are the process referred as OES client
High-Level Architecture
WebCenter – Security Overview
WebCenter Content Security
Security Groups
• Similar to Roles
• Non-Hierarchical
• Performance
overhead
Accounts with SG
• User level
• Could be Hierarchical
• Could become
Complex and out of
control
OES
• Policy Based approach
• Attribute Level control
• Custom Functions
• Integration with DB or
LDAP
WebCenter – Supported Operations
WebCenter Content Document
Operation Description
Oracle Entitlements Server
Controls
Check-in Creating new revision of the
document
Who can perform document check-
in operation
New Check-in Uploading new document Who can perform a new document
check-in operation
Check-in similar Similar to New Check-in. Inherits
properties set during previous new
document upload
Who can perform check-in similar
document operation
Checkout Checkout existing document for
modifications
Who can perform document
checkout operation
Undo Checkout Discard checked-out document Who can perform discard
document checkout operation
Delete Delete revision of the document Who can perform document delete
operation
Update Update metadata or attributes of
the document
Who can perform document
update operation
Search Perform document search
operation
What user can see in the
document search results
Read Read content of the document Who can perform document read
operation
Download Download the document Who can perform document
download operation
 The OES client(Security Module (SM), is embedded
inside the Content Management; this SM provides
both
• Policy Decision Point (PDP)
• Policy Enforcement Point (PEP)
WebCenter – OES Integration
WebCenter – Integration Roadmap
Migrate WC
Policy Store
to OES
Install UCM
Connector
for OES
Create
Policies in
OES
WebCenter – Demo Outline
 OES Policy Overview
 Policies for WebCenter
 Create Check In Policy for Directors
 Attribute Based Policy Scenario
CUSTOMER CASE STUDY
Entitlement Server Implementation
CASESTUDY.
College Of American
Pathologist
Northfield, Illinois
World’s largest association
composed exclusively of board
certified pathologists and is the
worldwide leader in laboratory
quality assurance. More than
7,000 laboratories are accredited
by the CAP, and approximately
23,000 laboratories.
Build an Enterprise Security Platform, a strategic initiative for CAP’s future growth
and expansion to the international market, requiring a highly‐secured
infrastructure for its customers.
BUSINESS
NEEDS
• Create foundation for Enterprise Security
• Consolidation of identity data, creating a centralized identity store using Oracle Internet
Directory & Oracle Virtual Directory
• Implementations of policy‐driven automated provisioning, enhancing security and compliance
by leveraging Oracle Identity Manager
• Self‐service user registration and profile management
• Single Sign‐On (SSO) using Oracle Access Manager
• Federated identity management and cross‐domain SSO using Oracle Identity Federation
• Fine‐grained portal entitlement and delegated administration using Oracle Entitlement
Server
• Integration with over 25 legacy systems
• Identity governance, and IT audit monitoring and reporting
SOLUTION & BENEFITS
 250,000 Users and 40,000 members
 250 Policies
 Dynamic Policies
OES Implementation Overview
Sun Lab Inc
3M Lab
Enterprise OES Platform
OID
Authentication
Store
Database
Policy
Store
CAP Staff
John– the
Lab Admin
John – the
Pathologist
 OES Replacement to CrossLogix
 Integration with Enterprise OIAM Systems
 WebService Based Integration
Implementation Technical Architecture
Question & Answers
Contact Information
Shyam Kumar/Zeeshan Baig
skumar@astcorporation.com
630-347-0833
Build Fine-Grained Authorization for WebCenter Using Oracle Entitlements Server (OES)

Más contenido relacionado

Último

Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 

Último (20)

Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 

Destacado

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Destacado (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Build Fine-Grained Authorization for WebCenter Using Oracle Entitlements Server (OES)

  • 1. Session ID: Prepared by: Build Fine-Grained Authorization for WebCenter Using Oracle Entitlements Server (OES) 1351 Shyam Kumar – AST Corporation Zeeshan Baig – AST Corporation
  • 2. Introduction Shyam Kumar is the Vice President of Middleware Practice at AST Corporation, Naperville (Chicago), IL & responsible for all aspects of the middleware business including strategic account management and solution architecture. Speaker at following industry forums/conferences – – Airport E-Business Users’ Roundtable – 5th International SOA, Cloud + Service Technology Symposium, London – APTA - 2013 Fare Collect-TransITech - Phoenix, AZ – North Central Oracle Apps User Group(NCOAUG) - Chicago – Oracle HCM Users Group (OHUG) – Collaborate (OAUG/IOUG) – Oracle Open World (OOW) Zeeshan Baig is an Oracle ACE and works as Solution Architect at Middleware Practice at AST Corporation, Naperville (Chicago), IL & responsible for enterprise architecture for large Cloud, Mobile, Security and Integration Projects.. Speaker at following industry forums/conferences – – North Central Oracle Apps User Group(NCOAUG) – RMOUG – Collaborate (OAUG/IOUG) – KSCOPE
  • 3. Our Brands Our Services Oracle Specialized  Enterprise Resource Planning  Business Intelligence  EPM-Hyperion  Middleware  CRM/CX  MDM-EDQ  Configure/Price/Quote  Managed Services  Education / Oracle University  Project Advisory Services  EBS Financial Management  EBS Human Capital Management  EBS Supply Chain Management  Database  BI Applications  BI Foundation Suite  Hyperion Planning & Financial Management  Essbase  Oracle Data Integration  Application Development Framework  Service Oriented Architecture  WebCenter Content  Access Management Suite Plus  Identity Governance Suite  WebLogic Server 2015, 2013, 2011, 2009 Oracle Excellence Award Winner 2015, 2014 Chicago Tribune Top 100 Workplaces Award Winner 2014, 2013, 2012 Inc. 5000 Fastest Growing Companies Award Winner 2014, 2012 Best & Brightest Companies to Work For Award Winner Specialized. Recognized. Preferred. 3
  • 4. Agenda • Authorization Overview • Understanding Oracle Entitlement Server • Oracle Entitlement Server Demo • WCC – OES Implementation Approach • Implementation Case Study • Q & A. 4
  • 5. Insider Threat 5 “Does our organization have a way to detect unauthorized access to our data?” “…less than 10 percent of companies actually have proactive monitoring of security controls - Authorization?” 58% Information Security Incidents Attributed to Insider Threat 93 % of U.S. Organizations Are Vulnerable to Insider
  • 6. Authorization Concepts 6 Grant “trade” privileges for the Account resource when user is in Account Trader Role:
  • 7. Fine-Grained & Coarse-Grained Authorization •Role Based (RBAC) •Less Restrictive Coarse- Grained •Attribute Based (ABAC) •More Restrictive Fine- Grained 7
  • 8. Authorization Policy Definition Application Security Requirements are defined by ‘Business Experts’
  • 9.  OES provides an implementation of fine- grained authorization  Use policies to protect application resources Oracle Entitlement Server (OES)
  • 10.  The PAP is the OES Admin Server manages the policies and artifacts related to security  SM Engine are the process referred as OES client High-Level Architecture
  • 11. WebCenter – Security Overview WebCenter Content Security Security Groups • Similar to Roles • Non-Hierarchical • Performance overhead Accounts with SG • User level • Could be Hierarchical • Could become Complex and out of control OES • Policy Based approach • Attribute Level control • Custom Functions • Integration with DB or LDAP
  • 12. WebCenter – Supported Operations WebCenter Content Document Operation Description Oracle Entitlements Server Controls Check-in Creating new revision of the document Who can perform document check- in operation New Check-in Uploading new document Who can perform a new document check-in operation Check-in similar Similar to New Check-in. Inherits properties set during previous new document upload Who can perform check-in similar document operation Checkout Checkout existing document for modifications Who can perform document checkout operation Undo Checkout Discard checked-out document Who can perform discard document checkout operation Delete Delete revision of the document Who can perform document delete operation Update Update metadata or attributes of the document Who can perform document update operation Search Perform document search operation What user can see in the document search results Read Read content of the document Who can perform document read operation Download Download the document Who can perform document download operation
  • 13.  The OES client(Security Module (SM), is embedded inside the Content Management; this SM provides both • Policy Decision Point (PDP) • Policy Enforcement Point (PEP) WebCenter – OES Integration
  • 14. WebCenter – Integration Roadmap Migrate WC Policy Store to OES Install UCM Connector for OES Create Policies in OES
  • 15. WebCenter – Demo Outline  OES Policy Overview  Policies for WebCenter  Create Check In Policy for Directors  Attribute Based Policy Scenario
  • 16. CUSTOMER CASE STUDY Entitlement Server Implementation
  • 17. CASESTUDY. College Of American Pathologist Northfield, Illinois World’s largest association composed exclusively of board certified pathologists and is the worldwide leader in laboratory quality assurance. More than 7,000 laboratories are accredited by the CAP, and approximately 23,000 laboratories. Build an Enterprise Security Platform, a strategic initiative for CAP’s future growth and expansion to the international market, requiring a highly‐secured infrastructure for its customers. BUSINESS NEEDS • Create foundation for Enterprise Security • Consolidation of identity data, creating a centralized identity store using Oracle Internet Directory & Oracle Virtual Directory • Implementations of policy‐driven automated provisioning, enhancing security and compliance by leveraging Oracle Identity Manager • Self‐service user registration and profile management • Single Sign‐On (SSO) using Oracle Access Manager • Federated identity management and cross‐domain SSO using Oracle Identity Federation • Fine‐grained portal entitlement and delegated administration using Oracle Entitlement Server • Integration with over 25 legacy systems • Identity governance, and IT audit monitoring and reporting SOLUTION & BENEFITS
  • 18.  250,000 Users and 40,000 members  250 Policies  Dynamic Policies OES Implementation Overview Sun Lab Inc 3M Lab Enterprise OES Platform OID Authentication Store Database Policy Store CAP Staff John– the Lab Admin John – the Pathologist  OES Replacement to CrossLogix  Integration with Enterprise OIAM Systems  WebService Based Integration
  • 20. Question & Answers Contact Information Shyam Kumar/Zeeshan Baig skumar@astcorporation.com 630-347-0833

Notas del editor

  1. Oracle Entitlements Server (OES) is a standards-based, policy-driven security solution that provides real time fine-grained authorization in Application, Service-Oriented Architecture (SOA) and Database environments…. Oracle Entitlements Server can serve as the authorization engine for all the content managed by Oracle WebCenter Content using RBAC and ABAC policies