#OOW16 - Introduction to Advanced Access Controls

Dane Roberts
Dane RobertsProduct Mgr at Oracle um Oracle
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Introducing Oracle Fusion
Advanced Access Controls
to Strengthen Security
OpenWorld 2016
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Introducing Oracle Fusion
Advanced Access Controls
to Strengthen Security
This session provides a first look at this upcoming cloud service:
Continually detect and manage unwanted user access in ERP, HCM & SCM Clouds
Streamline role design, access policies
Improve access controls for SOX, other regulations
This session will help you:
Learn about this cloud service from industry experts and Oracle’s product developers
Determine whether this cloud service will be right for your organization
Get answers to your questions in live Q&A with our panelists
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Safe Harbor Statement
The following is intended to outline our general product direction. It is intended for
information purposes only, and may not be incorporated into any contract. It is not a
commitment to deliver any material, code, or functionality, and should not be relied upon
in making purchasing decisions. The development, release, and timing of any features or
functionality described for Oracle’s products remains at the sole discretion of Oracle.
3
4
© 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG
International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International.
Why Are Access Controls
Needed?
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
5
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Panelists
– Katrina Johnson
Chief Audit Executive
Service Corp International
– Nicholas Seeman
Director, Advisory Services
KPMG LLP
– Mark Stebelton
Director, Product Management
Oracle Product Development
Moderator
– Barry Greenhut
Director, Product Strategy
Oracle Product Development
6
Session Speakers
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
11
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Advanced Access Controls – Design Objectives
Find users in
Oracle
ERP/HCM/SCM
Cloud who…
• Can generate unwanted transactions – e.g., have
separation of duties (SoD) conflicts
• Have access to sensitive data
Let
organizations…
• Identify and minimize unnecessary financial and
operational risk
• Demonstrate compliance with SOX and similar obligations
12
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Why Are Access Controls Needed?
14
• Enforcement includes detecting users who can:
• Application owners must continually enforce those policies
Enter unwanted
transactions
Create invoices then pay them
Create purchase orders then record
receipts for them
Create/change critical setup
data and configurations
Spending authorization limits
Opening closed accounting periods
Create/change
master data
Supplier
Customer
Employee
Item
17
© 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG
International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International.
Access Control Maturity
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Create Supplier Invoice Create PaymentSupplier
Create Supplier Create Payment for
same supplier
+ Create Supplier Create Payment for
supplier
≠
Why Is Separation of Duties Needed?
18
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Advanced Access Controls – Design Objectives
Restrict Unauthorized Access & Automate SoD Analysis
Manage Exceptions & Simulate Changes
Link Results to Business Risks
Automate User Security Analysis
Deploy Pre-Built SoD Controls
Author New Access Rules & Policies
19
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Deep, Dynamic Analysis
• Generate unwanted transactions
E.g., Separation of Duties
• Access to sensitive data
ERP/HCM/SCM
user abilities
• Ready to grow as privileges are added
to ERP/HCM/SCM
6,000+
ERP/HCM/SCM
privileges
20
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
User: Janie Adams
Job Role: Accounts Payable Supervisor
Duty Role: Payables Payment Creation
Privilege: Create Payables Payments
Privilege: Create Purchase Order
Job Role: Buyer
SoD Conflict
Deep, Dynamic Analysis
Duty Role: Purchase Order Authoring
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Closed-loop, Compliant System
Enforce
control
objectives,
policies,
regulations
Maintain
as users
are added,
assigned
other roles
Evaluate
& enact
treatment
Detect users’
access
continually
Detect Evaluate
EnforceMaintain
24
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Preview
Panelist Q&A
More Resources
1
2
3
4
26
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Preview
InFusion Corp: Goals and Requirements
Requirements: We need an enterprise solution that:
• Automates detection of users with excessive access
• Provides an audit trail of remediation activities for access issues
• Secures what users see and do within the solution
• Provides data and reports that key stakeholders need to make good decisions
• Requires minimum resources to administer after go-live
27
Goal: We need to address user access risk by understanding excessive
user access, treating access issues, and documenting accordingly
Process Owner and
Auditor
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 28
Best Practice Process
Identify
Excessive
Access
Deploy
Controls
Address
Issues
Report
Results
28
Create Models and
assess results
Remediate excessive access
where feasible
Convert Models to
Controls
Run Control Analysis
periodically
Manage incidents - options:
Adjust ERP/HCM/SCM
security configuration
Add compensating
transaction controls
Report incident
management results to
managers, auditors
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 31
I import pre-built models, test and
refine them, and use the results to
guide improvements to role
definitions
Preview
Diane Analyst
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 32
Import Pre-built Models
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Import Pre-built Models
Procurement
• Create Payments &
• Create Suppliers
• Set Up Payment
• Create Purchase Orders &
• Approval Authorization
Control
• Approve Invoices
• Create Invoices
Financials
• Enter Journal Entry &
• Approve Invoices
• Assets Workbench
• Create Invoices
• Create Payments
• Create Purchase Orders
• Post Journal Entry &
• Approve Invoices
• Assets Workbench
• Create Invoices
• Create Payments
• Create Purchase Orders
• Physical Inventory
Supply Chain
• Create Items &
• Cycle Counting
• Inventory Transactions
• Inventory Transactions &
• Receive Goods and Services
• Item Costing &
• Create Items
• Create Purchase Orders
• Ship Confirm Goods
33
Some of the planned pre-built models (100+ planned)
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 34
Review Model
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 35
Configure Model – Business Objects
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 36
Configure Model- Filter Logic
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 37
Configure Model- Access Conditions
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 38
Review Model Results
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 39
Visualize Incidents
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 40
Convert Models to Controls
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 41
I review and remediate incidents in
my business area
Review and Remediate Incidents
Chris Owner
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 42
Review and Remediate Incidents
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 43
Simulate Role Redesign
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 44
I review incident reports and re-
evaluate our existing access controls
Review Incident Reports
Alan Auditor
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 45
Review Incident Reports
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Advanced Access Controls – Design Objectives
Restrict Unauthorized Access & Automate SoD Analysis
Manage Exceptions & Simulate Changes
Link Results to Business Risks
Automate User Security Analysis
Deploy Pre-Built SoD Controls
Author New Access Rules & Policies
46
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
Katrina Johnson Service Corp International
Nicholas Seeman KPMG LLP
Mark Stebelton Oracle Product Development
More Resources
1
2
3
4
51
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
52
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
DEMOgrounds
Moscone West Level 3 Lobby (M,T,W) ERP Showcase
Workstation
WEP-020
53
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Wednesday
CUSTOMER CASE STUDY
Sep 21, 11:00 AM – 11:45 AM| Moscone West 3005
Securing ERP: Application Compliance
and Controls Implementation
[CAS7689]
Gautham Ramkumar: Director, Advisory Services, KMPG LLP
Chuck Devore, Director, Finance Transformation, ADM
Kenneth Kobia, Risk & Controls Lead, Archer Daniels Midland
Organizations have successfully transformed their business
operations by leveraging Oracle ERP technologies. Yet they
continue to struggle to balance the two divergent needs of
empowering ERP business users, while protecting sensitive
data and transactions. In this session KPMG and Archer
Daniels Midland detail how they took advantage of Oracle’s
ERP security and controls capabilities, to support ADM’s
initiative to deploy Oracle ERP .
PANEL SEESION
Sep 21, 1:30 PM – 2:15PM | Moscone West 3005
Introducing Oracle Fusion Advanced
Access Controls to Strengthen Security
[CON7290]
Katrina Johnson, VP Risk Assurance, Service Corp
International
Nicholas Seeman, Director, Advisory Services, KMPG LLP
Barry Greenhut, Director, Product Strategy, Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides an overview of Oracle Fusion Advanced
Access Controls to continuously detect segregation of duties
violations, manage exceptions, and fix unauthorized access to
sensitive functions and data. Compliance managers and
auditors can use Oracle Fusion Advanced Access Controls to
ensure strong access controls across ERP, HCM and SCM
cloud applications.
PANEL SESSION
Sep 21, 4:15 PM – 5:00 PM | Moscone West 3005
Implement the Best Practice for Oracle
Financial Reporting Compliance Cloud
[CON7291]
Swarnali Bag, Governance, Risk & Compliance Practice Lead,
Oracle
Barry Greenhut, Director, Product Strategy , Oracle
Lakshmi Rajamohan, Principal Product Strategy Mgr., Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides a more detailed walkthrough of Oracle
Financial Reporting Compliance from an end user’s
perspective, and highlights how the product can be
configured to automate the best practice process. Based on
learning from a decade of customer experience, it showcases
the shortest and most cost-effective path to go live and
streamline operations.
54
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Thursday
PANEL SESSION
Sep 22, 9:30 AM – 10:15 AM| Moscone West 3005
Implement the Best Practice for Oracle Fusion Advanced Financial
Controls Cloud Service
[CAS7286]
Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle
Barry Greenhut, Director, Product Strategy, Oracle
Christine Doxey, President, Doxey, Inc.
Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides a detailed walkthrough of Oracle Fusion Financial Controls Cloud Service
from an end user’s perspective, and highlights how the product can be configured to automate
best practice controls. Oracle Fusion Advanced Financial Controls Cloud Service is designed to
meet the common needs of Oracle Financials Cloud subscribers. Based on learning from a decade
of customer experience, this session showcases Oracle’s best practice business process for
maximum ROI with minimum cost of ongoing operation.
PANEL SESSION
Sep 22, 12:00 PM – 12:45 PM | Moscone West 3005
Get Started with Financial Reporting Compliance and Advanced
Financial Controls
[CON7284]
Barry Greenhut, Director, Product Strategy, Oracle
Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle
Joel Alvarado, Customer Success Manager, Oracle
This session provides you with the most effective project plan to implement Oracle Financial
Reporting Compliance or Oracle Fusion Advanced Financial Controls Cloud Service. Participants
will learn the shortest and most cost-effective path to success using Oracle’s customer and
partner-tested “get started” process. Learn how to plan and adopt these cloud services, and then
sustain your use through growth and change. Learn how to get the experience and expertise
needed to succeed.
55
Arturo Martínez del
Campo Saucedo
Corporate Chief Financial Officer
Grupo Posadas S.A.B. de C.V. .
LEADERSHIP IN FINANCE
LATIN AMERICA - CLOUD
2016
Best
Practice
Adopter
First
Adopter
of Risk
Cloud
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
 For subscribers and partners
To Learn More
Cloud Portal Release Readiness User Documentation Modern Best Practice
Oracle University Success Managers  Get Started  Customer Connect 
57
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | 5959
Join our LinkedIn Group
For the latest Updates and Presentations .
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 60
| Confidential – Oracle Internal/Restricted/Highly Restricted61
1 von 44

Recomendados

Introducing Oracle Advanced Financial Controls Cloud Service von
Introducing Oracle Advanced Financial Controls Cloud ServiceIntroducing Oracle Advanced Financial Controls Cloud Service
Introducing Oracle Advanced Financial Controls Cloud ServiceDane Roberts
1.5K views56 Folien
#OOW16 - Risk Management Cloud / GRC General Session von
#OOW16 - Risk Management Cloud / GRC General Session#OOW16 - Risk Management Cloud / GRC General Session
#OOW16 - Risk Management Cloud / GRC General SessionDane Roberts
1.1K views38 Folien
Fusion Financial Reporting and Analysis Proof of Concept von
Fusion Financial Reporting and Analysis Proof of ConceptFusion Financial Reporting and Analysis Proof of Concept
Fusion Financial Reporting and Analysis Proof of ConceptKhalil Rehman NLP (MPrac) MCIPS, PMP,OCP
2.4K views43 Folien
#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud Service von
#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud Service#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud Service
#OOW16 - Introducing Oracle Financial Reporting Compliance Cloud ServiceDane Roberts
3.5K views46 Folien
Rapid implementation Spreadsheets in Oracle ERP Cloud von
Rapid implementation Spreadsheets in Oracle ERP CloudRapid implementation Spreadsheets in Oracle ERP Cloud
Rapid implementation Spreadsheets in Oracle ERP CloudPrithis Das, PMP, OCS ☁️
5.5K views115 Folien
Oracle Fusion Financials Overview von
Oracle Fusion Financials OverviewOracle Fusion Financials Overview
Oracle Fusion Financials OverviewBerry Clemens
16.6K views49 Folien

Más contenido relacionado

Was ist angesagt?

Demystifying Oracle Cloud ERP Financials von
Demystifying Oracle Cloud ERP FinancialsDemystifying Oracle Cloud ERP Financials
Demystifying Oracle Cloud ERP FinancialsPerficient, Inc.
2.2K views72 Folien
One time payment requests in Oracle ERP Cloud von
One time payment requests in Oracle ERP CloudOne time payment requests in Oracle ERP Cloud
One time payment requests in Oracle ERP CloudPrithis Das, PMP, OCS ☁️
7.6K views28 Folien
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C... von
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...Prithis Das, PMP, OCS ☁️
10.5K views42 Folien
Simplify Complex Consolidations and Close Processes with Oracle Financial Con... von
Simplify Complex Consolidations and Close Processes with Oracle Financial Con...Simplify Complex Consolidations and Close Processes with Oracle Financial Con...
Simplify Complex Consolidations and Close Processes with Oracle Financial Con...Alithya
424 views38 Folien
Oracle Fusion Financial Report Centre Reporting Beginner course von
Oracle Fusion Financial Report Centre Reporting Beginner courseOracle Fusion Financial Report Centre Reporting Beginner course
Oracle Fusion Financial Report Centre Reporting Beginner courseKhalil Rehman NLP (MPrac) MCIPS, PMP,OCP
4.2K views22 Folien
Oracle Fusion Payments von
Oracle Fusion Payments Oracle Fusion Payments
Oracle Fusion Payments Berry Clemens
8.6K views43 Folien

Was ist angesagt?(20)

Demystifying Oracle Cloud ERP Financials von Perficient, Inc.
Demystifying Oracle Cloud ERP FinancialsDemystifying Oracle Cloud ERP Financials
Demystifying Oracle Cloud ERP Financials
Perficient, Inc.2.2K views
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C... von Prithis Das, PMP, OCS ☁️
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...
Simplify Complex Consolidations and Close Processes with Oracle Financial Con... von Alithya
Simplify Complex Consolidations and Close Processes with Oracle Financial Con...Simplify Complex Consolidations and Close Processes with Oracle Financial Con...
Simplify Complex Consolidations and Close Processes with Oracle Financial Con...
Alithya424 views
Oracle Fusion Payments von Berry Clemens
Oracle Fusion Payments Oracle Fusion Payments
Oracle Fusion Payments
Berry Clemens8.6K views
Oracle Fusion Architecture von Vinay Kumar
Oracle Fusion ArchitectureOracle Fusion Architecture
Oracle Fusion Architecture
Vinay Kumar10.4K views
Oracle Fusion Applications Accounts Payables von Berry Clemens
Oracle Fusion Applications Accounts PayablesOracle Fusion Applications Accounts Payables
Oracle Fusion Applications Accounts Payables
Berry Clemens32.4K views
Oracle ERP Implementation_Genpact_V7.pptx von AshokKumar705948
Oracle ERP Implementation_Genpact_V7.pptxOracle ERP Implementation_Genpact_V7.pptx
Oracle ERP Implementation_Genpact_V7.pptx
AshokKumar705948453 views
New features in oracle fusion financial accounts receivables and account paya... von Jade Global
New features in oracle fusion financial accounts receivables and account paya...New features in oracle fusion financial accounts receivables and account paya...
New features in oracle fusion financial accounts receivables and account paya...
Jade Global9.7K views
Oracle EPM Cloud for Midsize Customers von Alithya
Oracle EPM Cloud for Midsize CustomersOracle EPM Cloud for Midsize Customers
Oracle EPM Cloud for Midsize Customers
Alithya390 views
Implementing Cloud Financials von NERUG
Implementing Cloud FinancialsImplementing Cloud Financials
Implementing Cloud Financials
NERUG8.2K views
IMPLEMENTATION BEST PRACTICES Sep 22.pdf von udayabhaskar42
IMPLEMENTATION BEST PRACTICES Sep 22.pdfIMPLEMENTATION BEST PRACTICES Sep 22.pdf
IMPLEMENTATION BEST PRACTICES Sep 22.pdf
udayabhaskar42204 views
Migration to Oracle ERP Cloud: A must read winning recipe for all von Jim Pang
Migration to Oracle ERP Cloud: A must read winning recipe for allMigration to Oracle ERP Cloud: A must read winning recipe for all
Migration to Oracle ERP Cloud: A must read winning recipe for all
Jim Pang522 views
Case study: Managing a Fusion Financials Cloud Implementation with Oracle Uni... von Jade Global
Case study: Managing a Fusion Financials Cloud Implementation with Oracle Uni...Case study: Managing a Fusion Financials Cloud Implementation with Oracle Uni...
Case study: Managing a Fusion Financials Cloud Implementation with Oracle Uni...
Jade Global2.8K views
Oracle Fusion & Cloud Applications Overview von Ahmed El-Demasy
Oracle Fusion & Cloud Applications OverviewOracle Fusion & Cloud Applications Overview
Oracle Fusion & Cloud Applications Overview
Ahmed El-Demasy6.8K views
OOW16 - Oracle E-Business Suite: What’s New in Release 12.2 Beyond Online Pat... von vasuballa
OOW16 - Oracle E-Business Suite: What’s New in Release 12.2 Beyond Online Pat...OOW16 - Oracle E-Business Suite: What’s New in Release 12.2 Beyond Online Pat...
OOW16 - Oracle E-Business Suite: What’s New in Release 12.2 Beyond Online Pat...
vasuballa4K views

Similar a #OOW16 - Introduction to Advanced Access Controls

#OOW16 - • Implement the Best Practice for Oracle Fusion Advanced Financial C... von
#OOW16 - •	Implement the Best Practice for Oracle Fusion Advanced Financial C...#OOW16 - •	Implement the Best Practice for Oracle Fusion Advanced Financial C...
#OOW16 - • Implement the Best Practice for Oracle Fusion Advanced Financial C...Dane Roberts
745 views43 Folien
#OOW16 - • Get Started with Financial Reporting Compliance and Advanced Finan... von
#OOW16 - •	Get Started with Financial Reporting Compliance and Advanced Finan...#OOW16 - •	Get Started with Financial Reporting Compliance and Advanced Finan...
#OOW16 - • Get Started with Financial Reporting Compliance and Advanced Finan...Dane Roberts
761 views42 Folien
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc... von
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...Dane Roberts
888 views50 Folien
Advanced Controls access and user security for superusers con8824 von
Advanced Controls access and user security for superusers con8824Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824Oracle
2.5K views61 Folien
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016 von
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016Ron Corbisier
1.2K views30 Folien
Enterprise manager 13c von
Enterprise manager 13cEnterprise manager 13c
Enterprise manager 13cMarketingArrowECS_CZ
2.9K views113 Folien

Similar a #OOW16 - Introduction to Advanced Access Controls(20)

#OOW16 - • Implement the Best Practice for Oracle Fusion Advanced Financial C... von Dane Roberts
#OOW16 - •	Implement the Best Practice for Oracle Fusion Advanced Financial C...#OOW16 - •	Implement the Best Practice for Oracle Fusion Advanced Financial C...
#OOW16 - • Implement the Best Practice for Oracle Fusion Advanced Financial C...
Dane Roberts745 views
#OOW16 - • Get Started with Financial Reporting Compliance and Advanced Finan... von Dane Roberts
#OOW16 - •	Get Started with Financial Reporting Compliance and Advanced Finan...#OOW16 - •	Get Started with Financial Reporting Compliance and Advanced Finan...
#OOW16 - • Get Started with Financial Reporting Compliance and Advanced Finan...
Dane Roberts761 views
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc... von Dane Roberts
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...
Dane Roberts888 views
Advanced Controls access and user security for superusers con8824 von Oracle
Advanced Controls access and user security for superusers con8824Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824
Oracle2.5K views
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016 von Ron Corbisier
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016
Oracle Eloqua Roadmap SoCal Marketing Cloud User Group February 2016
Ron Corbisier1.2K views
Unified ERP HCM Presentation-23Feb16 von Ahmed Sayed
Unified ERP HCM Presentation-23Feb16Unified ERP HCM Presentation-23Feb16
Unified ERP HCM Presentation-23Feb16
Ahmed Sayed249 views
B6 improve operational_efficiency_through_process_and_document_collaboration von Dr. Wilfred Lin (Ph.D.)
B6 improve operational_efficiency_through_process_and_document_collaborationB6 improve operational_efficiency_through_process_and_document_collaboration
B6 improve operational_efficiency_through_process_and_document_collaboration
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations von Oracle
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Oracle1.4K views
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni... von Oracle
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Oracle1.1K views
How will you create a supplier management software.pptx von ssuser50762b
How will you create a supplier management software.pptxHow will you create a supplier management software.pptx
How will you create a supplier management software.pptx
ssuser50762b25 views
Control Spend and Deliver Savings_CWFY16-DC_PROCUREMENT-1 von Micky Agyeman
Control Spend and Deliver Savings_CWFY16-DC_PROCUREMENT-1Control Spend and Deliver Savings_CWFY16-DC_PROCUREMENT-1
Control Spend and Deliver Savings_CWFY16-DC_PROCUREMENT-1
Micky Agyeman92 views
Rapid process automation with oracle process cloud service von Heba Fouad
Rapid process automation with oracle process cloud serviceRapid process automation with oracle process cloud service
Rapid process automation with oracle process cloud service
Heba Fouad1.3K views
Oracle Management Cloud - HybridCloud Café - May 2016 von Bastien Leblanc
Oracle Management Cloud - HybridCloud Café - May 2016Oracle Management Cloud - HybridCloud Café - May 2016
Oracle Management Cloud - HybridCloud Café - May 2016
Bastien Leblanc4K views
Accelerate commercialization with cloud based product master data management von KPIT
Accelerate commercialization with cloud based product master data managementAccelerate commercialization with cloud based product master data management
Accelerate commercialization with cloud based product master data management
KPIT 1K views
Con8813 securing privileged accounts with an integrated idm solution - final von OracleIDM
Con8813 securing privileged accounts with an integrated idm solution - finalCon8813 securing privileged accounts with an integrated idm solution - final
Con8813 securing privileged accounts with an integrated idm solution - final
OracleIDM1.6K views
Optimizing order to-cash (e-business suite) with GRC Advanced Controls von Oracle
Optimizing order to-cash (e-business suite) with GRC Advanced ControlsOptimizing order to-cash (e-business suite) with GRC Advanced Controls
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
Oracle3.2K views
Theresa Rogers - Content Strategy to the Rescue! von LavaConConference
Theresa Rogers - Content Strategy to the Rescue!Theresa Rogers - Content Strategy to the Rescue!
Theresa Rogers - Content Strategy to the Rescue!
7. Andy Campbell - Make the Most of the Cloud von Cedar Consulting
7. Andy Campbell -  Make the Most of the Cloud7. Andy Campbell -  Make the Most of the Cloud
7. Andy Campbell - Make the Most of the Cloud
Cedar Consulting112 views

Último

The Talent Management Navigator Performance Management von
The Talent Management Navigator Performance ManagementThe Talent Management Navigator Performance Management
The Talent Management Navigator Performance ManagementSeta Wicaksana
35 views36 Folien
Super Solar Mounting Solutions 20230509(1).pdf von
Super Solar Mounting Solutions 20230509(1).pdfSuper Solar Mounting Solutions 20230509(1).pdf
Super Solar Mounting Solutions 20230509(1).pdfcarrie55bradshaw
12 views25 Folien
port23_2023121_resize2.pdf von
port23_2023121_resize2.pdfport23_2023121_resize2.pdf
port23_2023121_resize2.pdfSivaphan Wuttingam
32 views64 Folien
Imports Next Level.pdf von
Imports Next Level.pdfImports Next Level.pdf
Imports Next Level.pdfBloomerang
150 views32 Folien
sample.potx von
sample.potxsample.potx
sample.potxMaryna Yurchenko
20 views3 Folien

Último(20)

The Talent Management Navigator Performance Management von Seta Wicaksana
The Talent Management Navigator Performance ManagementThe Talent Management Navigator Performance Management
The Talent Management Navigator Performance Management
Seta Wicaksana35 views
Super Solar Mounting Solutions 20230509(1).pdf von carrie55bradshaw
Super Solar Mounting Solutions 20230509(1).pdfSuper Solar Mounting Solutions 20230509(1).pdf
Super Solar Mounting Solutions 20230509(1).pdf
carrie55bradshaw12 views
Imports Next Level.pdf von Bloomerang
Imports Next Level.pdfImports Next Level.pdf
Imports Next Level.pdf
Bloomerang150 views
Bloomerang Thank Yous Dec 2023.pdf von Bloomerang
Bloomerang Thank Yous Dec 2023.pdfBloomerang Thank Yous Dec 2023.pdf
Bloomerang Thank Yous Dec 2023.pdf
Bloomerang140 views
voice logger software aegis.pdf von Nirmal Sharma
voice logger software aegis.pdfvoice logger software aegis.pdf
voice logger software aegis.pdf
Nirmal Sharma47 views
Why are KPIs(key performance indicators) important? von Epixel MLM Software
Why are KPIs(key performance indicators) important? Why are KPIs(key performance indicators) important?
Why are KPIs(key performance indicators) important?
Engaging Senior Leaders to Accelerate Your Continuous Improvement Program von KaiNexus
Engaging Senior Leaders to Accelerate Your Continuous Improvement ProgramEngaging Senior Leaders to Accelerate Your Continuous Improvement Program
Engaging Senior Leaders to Accelerate Your Continuous Improvement Program
KaiNexus12 views
Navigating EUDR Compliance within the Coffee Industry von Peter Horsten
Navigating EUDR Compliance within the Coffee IndustryNavigating EUDR Compliance within the Coffee Industry
Navigating EUDR Compliance within the Coffee Industry
Peter Horsten46 views
PMU Launch - Guaranteed Slides von pmulaunch
PMU Launch - Guaranteed SlidesPMU Launch - Guaranteed Slides
PMU Launch - Guaranteed Slides
pmulaunch18 views
How UiPath’s European Founder Kept Control and Built an Expert Board of Direc... von Christian Dahlen
How UiPath’s European Founder Kept Control and Built an Expert Board of Direc...How UiPath’s European Founder Kept Control and Built an Expert Board of Direc...
How UiPath’s European Founder Kept Control and Built an Expert Board of Direc...
Christian Dahlen55 views
Better Appeals and Solicitations - Bloomerang.pdf von Bloomerang
Better Appeals and Solicitations - Bloomerang.pdfBetter Appeals and Solicitations - Bloomerang.pdf
Better Appeals and Solicitations - Bloomerang.pdf
Bloomerang81 views
Nevigating Sucess.pdf von TEWMAGAZINE
Nevigating Sucess.pdfNevigating Sucess.pdf
Nevigating Sucess.pdf
TEWMAGAZINE26 views
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf von Bloomerang
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdfBloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf
Bloomerang167 views

#OOW16 - Introduction to Advanced Access Controls

  • 1. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Introducing Oracle Fusion Advanced Access Controls to Strengthen Security OpenWorld 2016
  • 2. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Introducing Oracle Fusion Advanced Access Controls to Strengthen Security This session provides a first look at this upcoming cloud service: Continually detect and manage unwanted user access in ERP, HCM & SCM Clouds Streamline role design, access policies Improve access controls for SOX, other regulations This session will help you: Learn about this cloud service from industry experts and Oracle’s product developers Determine whether this cloud service will be right for your organization Get answers to your questions in live Q&A with our panelists
  • 3. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Safe Harbor Statement The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle. 3
  • 4. 4 © 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International. Why Are Access Controls Needed?
  • 5. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 5
  • 6. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Panelists – Katrina Johnson Chief Audit Executive Service Corp International – Nicholas Seeman Director, Advisory Services KPMG LLP – Mark Stebelton Director, Product Management Oracle Product Development Moderator – Barry Greenhut Director, Product Strategy Oracle Product Development 6 Session Speakers
  • 7. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 11
  • 8. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Advanced Access Controls – Design Objectives Find users in Oracle ERP/HCM/SCM Cloud who… • Can generate unwanted transactions – e.g., have separation of duties (SoD) conflicts • Have access to sensitive data Let organizations… • Identify and minimize unnecessary financial and operational risk • Demonstrate compliance with SOX and similar obligations 12
  • 9. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Why Are Access Controls Needed? 14 • Enforcement includes detecting users who can: • Application owners must continually enforce those policies Enter unwanted transactions Create invoices then pay them Create purchase orders then record receipts for them Create/change critical setup data and configurations Spending authorization limits Opening closed accounting periods Create/change master data Supplier Customer Employee Item
  • 10. 17 © 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International. Access Control Maturity
  • 11. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Create Supplier Invoice Create PaymentSupplier Create Supplier Create Payment for same supplier + Create Supplier Create Payment for supplier ≠ Why Is Separation of Duties Needed? 18
  • 12. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Advanced Access Controls – Design Objectives Restrict Unauthorized Access & Automate SoD Analysis Manage Exceptions & Simulate Changes Link Results to Business Risks Automate User Security Analysis Deploy Pre-Built SoD Controls Author New Access Rules & Policies 19
  • 13. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Deep, Dynamic Analysis • Generate unwanted transactions E.g., Separation of Duties • Access to sensitive data ERP/HCM/SCM user abilities • Ready to grow as privileges are added to ERP/HCM/SCM 6,000+ ERP/HCM/SCM privileges 20
  • 14. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. User: Janie Adams Job Role: Accounts Payable Supervisor Duty Role: Payables Payment Creation Privilege: Create Payables Payments Privilege: Create Purchase Order Job Role: Buyer SoD Conflict Deep, Dynamic Analysis Duty Role: Purchase Order Authoring
  • 15. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Closed-loop, Compliant System Enforce control objectives, policies, regulations Maintain as users are added, assigned other roles Evaluate & enact treatment Detect users’ access continually Detect Evaluate EnforceMaintain 24
  • 16. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Preview Panelist Q&A More Resources 1 2 3 4 26
  • 17. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Preview InFusion Corp: Goals and Requirements Requirements: We need an enterprise solution that: • Automates detection of users with excessive access • Provides an audit trail of remediation activities for access issues • Secures what users see and do within the solution • Provides data and reports that key stakeholders need to make good decisions • Requires minimum resources to administer after go-live 27 Goal: We need to address user access risk by understanding excessive user access, treating access issues, and documenting accordingly Process Owner and Auditor
  • 18. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 28 Best Practice Process Identify Excessive Access Deploy Controls Address Issues Report Results 28 Create Models and assess results Remediate excessive access where feasible Convert Models to Controls Run Control Analysis periodically Manage incidents - options: Adjust ERP/HCM/SCM security configuration Add compensating transaction controls Report incident management results to managers, auditors
  • 19. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 31 I import pre-built models, test and refine them, and use the results to guide improvements to role definitions Preview Diane Analyst
  • 20. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 32 Import Pre-built Models
  • 21. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Import Pre-built Models Procurement • Create Payments & • Create Suppliers • Set Up Payment • Create Purchase Orders & • Approval Authorization Control • Approve Invoices • Create Invoices Financials • Enter Journal Entry & • Approve Invoices • Assets Workbench • Create Invoices • Create Payments • Create Purchase Orders • Post Journal Entry & • Approve Invoices • Assets Workbench • Create Invoices • Create Payments • Create Purchase Orders • Physical Inventory Supply Chain • Create Items & • Cycle Counting • Inventory Transactions • Inventory Transactions & • Receive Goods and Services • Item Costing & • Create Items • Create Purchase Orders • Ship Confirm Goods 33 Some of the planned pre-built models (100+ planned)
  • 22. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 34 Review Model
  • 23. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 35 Configure Model – Business Objects
  • 24. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 36 Configure Model- Filter Logic
  • 25. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 37 Configure Model- Access Conditions
  • 26. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 38 Review Model Results
  • 27. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 39 Visualize Incidents
  • 28. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 40 Convert Models to Controls
  • 29. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 41 I review and remediate incidents in my business area Review and Remediate Incidents Chris Owner
  • 30. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 42 Review and Remediate Incidents
  • 31. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 43 Simulate Role Redesign
  • 32. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 44 I review incident reports and re- evaluate our existing access controls Review Incident Reports Alan Auditor
  • 33. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 45 Review Incident Reports
  • 34. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Advanced Access Controls – Design Objectives Restrict Unauthorized Access & Automate SoD Analysis Manage Exceptions & Simulate Changes Link Results to Business Risks Automate User Security Analysis Deploy Pre-Built SoD Controls Author New Access Rules & Policies 46
  • 35. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A Katrina Johnson Service Corp International Nicholas Seeman KPMG LLP Mark Stebelton Oracle Product Development More Resources 1 2 3 4 51
  • 36. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 52
  • 37. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | DEMOgrounds Moscone West Level 3 Lobby (M,T,W) ERP Showcase Workstation WEP-020 53
  • 38. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Wednesday CUSTOMER CASE STUDY Sep 21, 11:00 AM – 11:45 AM| Moscone West 3005 Securing ERP: Application Compliance and Controls Implementation [CAS7689] Gautham Ramkumar: Director, Advisory Services, KMPG LLP Chuck Devore, Director, Finance Transformation, ADM Kenneth Kobia, Risk & Controls Lead, Archer Daniels Midland Organizations have successfully transformed their business operations by leveraging Oracle ERP technologies. Yet they continue to struggle to balance the two divergent needs of empowering ERP business users, while protecting sensitive data and transactions. In this session KPMG and Archer Daniels Midland detail how they took advantage of Oracle’s ERP security and controls capabilities, to support ADM’s initiative to deploy Oracle ERP . PANEL SEESION Sep 21, 1:30 PM – 2:15PM | Moscone West 3005 Introducing Oracle Fusion Advanced Access Controls to Strengthen Security [CON7290] Katrina Johnson, VP Risk Assurance, Service Corp International Nicholas Seeman, Director, Advisory Services, KMPG LLP Barry Greenhut, Director, Product Strategy, Oracle Mark Stebelton, Director, Product Management, Oracle This session provides an overview of Oracle Fusion Advanced Access Controls to continuously detect segregation of duties violations, manage exceptions, and fix unauthorized access to sensitive functions and data. Compliance managers and auditors can use Oracle Fusion Advanced Access Controls to ensure strong access controls across ERP, HCM and SCM cloud applications. PANEL SESSION Sep 21, 4:15 PM – 5:00 PM | Moscone West 3005 Implement the Best Practice for Oracle Financial Reporting Compliance Cloud [CON7291] Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle Barry Greenhut, Director, Product Strategy , Oracle Lakshmi Rajamohan, Principal Product Strategy Mgr., Oracle Mark Stebelton, Director, Product Management, Oracle This session provides a more detailed walkthrough of Oracle Financial Reporting Compliance from an end user’s perspective, and highlights how the product can be configured to automate the best practice process. Based on learning from a decade of customer experience, it showcases the shortest and most cost-effective path to go live and streamline operations. 54
  • 39. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Thursday PANEL SESSION Sep 22, 9:30 AM – 10:15 AM| Moscone West 3005 Implement the Best Practice for Oracle Fusion Advanced Financial Controls Cloud Service [CAS7286] Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle Barry Greenhut, Director, Product Strategy, Oracle Christine Doxey, President, Doxey, Inc. Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle Mark Stebelton, Director, Product Management, Oracle This session provides a detailed walkthrough of Oracle Fusion Financial Controls Cloud Service from an end user’s perspective, and highlights how the product can be configured to automate best practice controls. Oracle Fusion Advanced Financial Controls Cloud Service is designed to meet the common needs of Oracle Financials Cloud subscribers. Based on learning from a decade of customer experience, this session showcases Oracle’s best practice business process for maximum ROI with minimum cost of ongoing operation. PANEL SESSION Sep 22, 12:00 PM – 12:45 PM | Moscone West 3005 Get Started with Financial Reporting Compliance and Advanced Financial Controls [CON7284] Barry Greenhut, Director, Product Strategy, Oracle Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle Joel Alvarado, Customer Success Manager, Oracle This session provides you with the most effective project plan to implement Oracle Financial Reporting Compliance or Oracle Fusion Advanced Financial Controls Cloud Service. Participants will learn the shortest and most cost-effective path to success using Oracle’s customer and partner-tested “get started” process. Learn how to plan and adopt these cloud services, and then sustain your use through growth and change. Learn how to get the experience and expertise needed to succeed. 55
  • 40. Arturo Martínez del Campo Saucedo Corporate Chief Financial Officer Grupo Posadas S.A.B. de C.V. . LEADERSHIP IN FINANCE LATIN AMERICA - CLOUD 2016 Best Practice Adopter First Adopter of Risk Cloud
  • 41. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |  For subscribers and partners To Learn More Cloud Portal Release Readiness User Documentation Modern Best Practice Oracle University Success Managers  Get Started  Customer Connect  57
  • 42. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | 5959 Join our LinkedIn Group For the latest Updates and Presentations .
  • 43. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 60
  • 44. | Confidential – Oracle Internal/Restricted/Highly Restricted61