SlideShare ist ein Scribd-Unternehmen logo
1 von 19
User ID Maintenance Project - Phase 1
Product Walkthrough



September 6, 2011
Agenda



    ●    Project Overview and Updates
    ●    Key Features
    ●    Demo
    ●    Next Steps
Project Overview and Updates



    User ID maintenance challenges:
    ●    Multiple channels for requests
    ●    Unsecured and time-consuming process for delivering passwords to users
    ●    No central view of the user for ITO-managed applications



    Project Objectives:
     ●   To streamline and standardize the end-to-end user ID maintenance process.
     ●   To provide a common channel for user ID related requests and follow-ups.
     ●   To incorporate standard and/or automated tools in the process
Project Overview and Updates



    Key decisions made:
     ●   Create a separate, simpler front-end for common users vs. authorized requestors
     ●   Remove ESS from the proposed application architecture
     ●
         Introduce verification of requester identity instead as 2nd authentication factor
     ●   Divide the project into phases, based on functionality to be delivered



    Project Phases & Scope:
     ●   Phase 1: Self-service requests (Reset and Unlock) and password delivery
     ●   Phase 2: Requests requiring approval (e.g. Creation, Deletion, Modification, etc.)
     ●   Phase 3: User ID database
Application Architecture Roadmap




                              3
                                                          ID                                5
             RT
                                       5a
                                                   Administrator           Password                 Business
                                                                           Generator               Application
                                               4



                                               BU         7
                                             Approver                          6
                                               DB




                                            User ID Maintenance Application

                                                                                          10
        1                                                                                                    8
                      2



                     BU                                            Windows
      User                        2a                    User ID                          User      9      Approver
                  Requestor                                         Active
                                                          DB
                                                                   Directory




                  Approver




             Demand                                 Process                            Deliver Password
Application Architecture Roadmap




                              3
                                                        ID                                  5
             RT
                                       5a
                                                   Administrator           Password                 Business
                                                                           Generator               Application

                                       rate
                                         4

                                    pa
                                  Se ject
                                   pro Approver
                                          BU            7                      6
                                              DB




                                            User ID Maintenance Application

                                                                                          10
        1                                                                                                    8
                       2
                                                     3
                                                a se
      User
                     BU           2a
                                              Ph User ID           Windows
                                                                                         User      9      Approver
                  Requestor                                         Active
                                                       DB

                   e   2                                           Directory


             Ph as
                  Approver




             Demand                                 Process                            Deliver Password
Product Overview



   The User ID Maintenance Application
    ●   is a web-based application
    ●   will be made accessible over the BDO intranet (https://userid.bdo.com.ph)
    ●   will serve as the default channel for requests and follow-ups from BDO users
    ●   will cover user IDs managed by ITO only
    ●   will interface with but not replace ITO's central ticketing system (RT)
    ●   will not be integrated with business applications (ex. ICBS, OPICS, etc.)
    ●   will have major releases corresponding to the 3 project phases
Key Product Features (Release 1)



    Works with Windows AD
        ●   Uses Windows AD authentication
        ●   Retrieves relevant employee information from AD (name, employee number,
            email address, etc.)



    Works with Request Tracker
        ●   Web front-end connects to Request Tracker
        ●   Creates RT ticket
        ●   Assigns ticket to RT Coordinator based on the business application
        ●   Closes ticket upon password delivery
Key Product Features (Release 1)



    Secures password delivery to user
        ●   Removes the need for administrators to remember / write down passwords
        ●   Requires 2-factor authentication for password retrieval:
                 Windows password + password key
                 OR 2 password keys
        ●   Deletes encrypted password in the database N days after resolution (N = 7 )


    Secures viewing of requests
        ●   Allows viewing of requests by the requestor or approvers only after log-in
        ●   Exception: requests for Windows IDs (log-in not required)
Key Product Features (Release 1)




    Guides the user
         ●       User chooses among limited options to get to desired page
         ●       Tool tips, hints and reminders

    Manages privileged users via roles
         ●       ID administrator
         ●       Website administrator

    Keeps an audit trail for critical actions:
             ●    Action: login, create/approve/view request, retrieve password
             ●    Information: IP address, session ID, Windows ID, timestamp

    Email notification capability
Demo
Demo



                    User   RT Coordinator   Servicing Personnel
                                             (ID Administrator)


   Request
   Tracker




 Application
 (ex. ICBS,Opics,
     Cadencie)




  User ID
  Website
Demo – Unlock ID



                            User       RT Coordinator    Servicing Personnel
                                                          (ID Administrator)

                                           Review &      Open
   Request                                  assign      assigned
   Tracker                                   ticket       ticket

                                                                     Set ticket
                                             Steal                   status to    End
                                             ticket                 “Resolved”



  Application
                                                        Unlock
 (ex. ICBS,Opics,                                         ID
     Cadencie)




                    Start
                             Submit
                             request




  User ID
  Website
Demo – Reset Password



                            User       Approver   RT Coordinator   Servicing Personnel
                                                                    (ID Administrator)

                                                    Review &             Open
   Request                                           assign             assigned
   Tracker                                            ticket              ticket


                                                      Steal
                                                      ticket


  Application                                                            Reset
 (ex. ICBS,Opics,                                                       password
     Cadencie)




                    Start
                             Submit    Approve                         Search for
                             request   request                         RT ticket #



                                                                        Send new
                            Retrieve
  User ID           End                                                 password
                            password
  Website                                                                to user
Demo – Reset Password (Windows)



                            User         Approver 1   Approver 2   RT Coordinator   Servicing Personnel
                                                                                     (ID Administrator)

                                                                       Review &             Open
  Request                                                               assign             assigned
  Tracker                                                                ticket              ticket


                                                                         Steal
                                                                         ticket



  Application                                                                               Reset
                                                                                           password
 (ex. ICBS,Opics,
     Cadencie)




                    Start
                              Submit      Approve       Approve                           Search for
                              Request     request       request                           RT ticket #



                                                                                           Send new
                              Retrieve
  User ID           End                                                                    password
                              password
  Website                                                                                   to user
Next Steps




    Key Dates:
             Dates                              Activities
     9/14 - 9/26     Product testing
                     Pilot deployment preparations
     10/6            Application deployment (bdoulx023)
     10/10 - 10/31   Pilot to selected business units
                     Technical support and fixes as needed
                     Performance testing and tuning parallel to pilot (bdoulx024)


    Bank-wide rollout and timeline will be decided after the pilot.
Q&A




      ?
Application Architecture Roadmap




      User ID
                          RT
                               3
                                         ID Administrator
                                                             Password      5
                                                                                    Business
      Website                                                Generator             Application
                                   8



                                                        7
                                          4
         1




       User                              BU
                                                   User ID                                            9
                                       Approver
                                                     DB                                                   Approver
                                         DB
                                                                               6     User ID
                                                                                     Website
        BU
                     2                                                                                      10
     Requestor
                                                                                                 11
                                                               Windows
                                                                Active
                                                               Directory
      Approver       2a
                                                                                                           User




                 Demand                    Process                                   Deliver Password
Application Architecture Roadmap




       User ID
                           RT
                                3
                                          ID Administrator
                                                              Password        5
                                                                                       Business
       Website                                                Generator               Application
                                    8



                                                         7
                                           4
         1




        User                              BU
                                                    User ID                                              9
                                        Approver
                                       te                     3
                                                       ase
                                                      DB
                                    ara
                                          DB                                                                 Approver
                                  p
                                Se ject             Ph
                                                                                  6     User ID
                                                                                        Website
         BU
      Requestor       2          pro                                                                           10

          2
       se
                                                                                                    11

      a                                                           Windows

   PhApprover
                                                                   Active
                                                                  Directory
                      2a
                                                                                                              User




                  Demand                    Process                                     Deliver Password

Weitere ähnliche Inhalte

Ähnlich wie Uidm deck unit heads 2011 09-06

Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...djmichael156
 
Updated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeUpdated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeSaket Mrinal
 
Software Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeSoftware Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeHari
 
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughAzure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughVinu Gunasekaran
 
SpotMe pitch
SpotMe pitchSpotMe pitch
SpotMe pitchjbusuito
 
OMGi application store
OMGi application storeOMGi application store
OMGi application storetothtamas
 
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...apidays
 
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...WSO2
 
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)Carles Farré
 
Saas webinar-dec6-01
Saas webinar-dec6-01Saas webinar-dec6-01
Saas webinar-dec6-01Paul Madsen
 

Ähnlich wie Uidm deck unit heads 2011 09-06 (20)

BI FirstBank
BI FirstBank BI FirstBank
BI FirstBank
 
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
 
Updated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeUpdated SAKET MRINAL Resume
Updated SAKET MRINAL Resume
 
Srs
SrsSrs
Srs
 
Software Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeSoftware Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet Cafe
 
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughAzure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
SpotMe pitch
SpotMe pitchSpotMe pitch
SpotMe pitch
 
OMGi application store
OMGi application storeOMGi application store
OMGi application store
 
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
 
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
CustomerCopy
CustomerCopyCustomerCopy
CustomerCopy
 
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
 
Saas webinar-dec6-01
Saas webinar-dec6-01Saas webinar-dec6-01
Saas webinar-dec6-01
 
ASP.NET Lecture 5
ASP.NET Lecture 5ASP.NET Lecture 5
ASP.NET Lecture 5
 
Resume
ResumeResume
Resume
 

Kürzlich hochgeladen

08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdfChristopherTHyatt
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 

Kürzlich hochgeladen (20)

08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 

Uidm deck unit heads 2011 09-06

  • 1. User ID Maintenance Project - Phase 1 Product Walkthrough September 6, 2011
  • 2. Agenda ● Project Overview and Updates ● Key Features ● Demo ● Next Steps
  • 3. Project Overview and Updates User ID maintenance challenges: ● Multiple channels for requests ● Unsecured and time-consuming process for delivering passwords to users ● No central view of the user for ITO-managed applications Project Objectives: ● To streamline and standardize the end-to-end user ID maintenance process. ● To provide a common channel for user ID related requests and follow-ups. ● To incorporate standard and/or automated tools in the process
  • 4. Project Overview and Updates Key decisions made: ● Create a separate, simpler front-end for common users vs. authorized requestors ● Remove ESS from the proposed application architecture ● Introduce verification of requester identity instead as 2nd authentication factor ● Divide the project into phases, based on functionality to be delivered Project Phases & Scope: ● Phase 1: Self-service requests (Reset and Unlock) and password delivery ● Phase 2: Requests requiring approval (e.g. Creation, Deletion, Modification, etc.) ● Phase 3: User ID database
  • 5. Application Architecture Roadmap 3 ID 5 RT 5a Administrator Password Business Generator Application 4 BU 7 Approver 6 DB User ID Maintenance Application 10 1 8 2 BU Windows User 2a User ID User 9 Approver Requestor Active DB Directory Approver Demand Process Deliver Password
  • 6. Application Architecture Roadmap 3 ID 5 RT 5a Administrator Password Business Generator Application rate 4 pa Se ject pro Approver BU 7 6 DB User ID Maintenance Application 10 1 8 2 3 a se User BU 2a Ph User ID Windows User 9 Approver Requestor Active DB e 2 Directory Ph as Approver Demand Process Deliver Password
  • 7. Product Overview The User ID Maintenance Application ● is a web-based application ● will be made accessible over the BDO intranet (https://userid.bdo.com.ph) ● will serve as the default channel for requests and follow-ups from BDO users ● will cover user IDs managed by ITO only ● will interface with but not replace ITO's central ticketing system (RT) ● will not be integrated with business applications (ex. ICBS, OPICS, etc.) ● will have major releases corresponding to the 3 project phases
  • 8. Key Product Features (Release 1) Works with Windows AD ● Uses Windows AD authentication ● Retrieves relevant employee information from AD (name, employee number, email address, etc.) Works with Request Tracker ● Web front-end connects to Request Tracker ● Creates RT ticket ● Assigns ticket to RT Coordinator based on the business application ● Closes ticket upon password delivery
  • 9. Key Product Features (Release 1) Secures password delivery to user ● Removes the need for administrators to remember / write down passwords ● Requires 2-factor authentication for password retrieval: Windows password + password key OR 2 password keys ● Deletes encrypted password in the database N days after resolution (N = 7 ) Secures viewing of requests ● Allows viewing of requests by the requestor or approvers only after log-in ● Exception: requests for Windows IDs (log-in not required)
  • 10. Key Product Features (Release 1) Guides the user ● User chooses among limited options to get to desired page ● Tool tips, hints and reminders Manages privileged users via roles ● ID administrator ● Website administrator Keeps an audit trail for critical actions: ● Action: login, create/approve/view request, retrieve password ● Information: IP address, session ID, Windows ID, timestamp Email notification capability
  • 11. Demo
  • 12. Demo User RT Coordinator Servicing Personnel (ID Administrator) Request Tracker Application (ex. ICBS,Opics, Cadencie) User ID Website
  • 13. Demo – Unlock ID User RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Set ticket Steal status to End ticket “Resolved” Application Unlock (ex. ICBS,Opics, ID Cadencie) Start Submit request User ID Website
  • 14. Demo – Reset Password User Approver RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Steal ticket Application Reset (ex. ICBS,Opics, password Cadencie) Start Submit Approve Search for request request RT ticket # Send new Retrieve User ID End password password Website to user
  • 15. Demo – Reset Password (Windows) User Approver 1 Approver 2 RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Steal ticket Application Reset password (ex. ICBS,Opics, Cadencie) Start Submit Approve Approve Search for Request request request RT ticket # Send new Retrieve User ID End password password Website to user
  • 16. Next Steps Key Dates: Dates Activities 9/14 - 9/26 Product testing Pilot deployment preparations 10/6 Application deployment (bdoulx023) 10/10 - 10/31 Pilot to selected business units Technical support and fixes as needed Performance testing and tuning parallel to pilot (bdoulx024) Bank-wide rollout and timeline will be decided after the pilot.
  • 17. Q&A ?
  • 18. Application Architecture Roadmap User ID RT 3 ID Administrator Password 5 Business Website Generator Application 8 7 4 1 User BU User ID 9 Approver DB Approver DB 6 User ID Website BU 2 10 Requestor 11 Windows Active Directory Approver 2a User Demand Process Deliver Password
  • 19. Application Architecture Roadmap User ID RT 3 ID Administrator Password 5 Business Website Generator Application 8 7 4 1 User BU User ID 9 Approver te 3 ase DB ara DB Approver p Se ject Ph 6 User ID Website BU Requestor 2 pro 10 2 se 11 a Windows PhApprover Active Directory 2a User Demand Process Deliver Password

Hinweis der Redaktion

  1. -