18

Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

  • Upload
    dinhbao

  • View
    214

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For
Page 2: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

2

Webinar Logistics

• Hide and unhide the Webinar control

panel by clicking on the arrow icon

on the top right of your screen

• The small window icon toggles

between a windowed and full screen

mode

• Ask questions throughout the

presentation using the question dialog

• Questions will be reviewed and

answered (time permitting) at the end

of the presentation

Page 3: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

3

Agenda

• Introduction

o Periodic Assignment Reviews

o Assignment Provisioning

• Introducing CS*Comply

• Demonstration

• Key Benefits/Value Proposition

• Q&A

Page 4: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

4

Introduction - Webinar Series

Page 5: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

5

Introduction – Feature Focused

• This is a feature focused webinar covering two process automation features of

CS*Comply…

o Periodic Assignment Reviews (PAR)

o Automated Assignment Provisioning (AAP)

Page 6: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

6

Introduction – Periodic Assignment Review

• A Periodic Assignment Review is a process whereby all responsibility

assignments are reviewed on a periodic basis; typically quarterly.

• The review process usually involves a “process owner” (or line manager or

similar) reviewing all of the responsibility assignments for the responsibilities

which they have authority over.

• Once all the assignments have been reviewed, any assignments that should be

removed would be end-dated by a security administrator.

Page 7: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

7

Introduction – Periodic Assignment Review

• This process is typically manual, from start to finish and for many organizations is

a major administrative overhead each time a review is required.

• The process owner would typically either “approve” or “reject” an assignment

using some manual process (spreadsheet, annotating a report…etc).

• The security administrator would then take the review results and action the

rejections by end-dating those rejected assignments.

• The information gathered during the review process is kept and likely used to help

satisfy auditors (internal and external) that a proper assignment review is taking

place.

Page 8: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

8

Introduction – Assignment Provisioning

• Assignment Provisioning is the process of granting or revoking users access to

one or more responsibilities

• For most organizations this is a manual process in that the security administrator

(or other suitably privileged user) will use the standard Oracle EBS Users screen

to assign responsibilities to users.

• The process is very time consuming and offers no means of automation to

streamline the process.

• There is no mechanism available that allows a user to request access to a given

responsibility and so some manual procedure of often used, such as filling in a

form to request access (either on a piece of paper or else using email or some

other method).

Page 9: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

9

Introduction – Assignment Provisioning

• Often supervisors, managers or similar will need to request access to one or more

responsibilities for one of their subordinates

• A given subordinate may have been created in the HR system but they may not

have an associated applications user; in these scenario’s a new application user will

need to be created by the security administrator

• In many scenarios, new application users are always granted access to one or more

“default responsibilities” as well as the responsibility their manager request access

for; the responsibilities would usually need to be manually assigned by the security

administrator

• All of the above typically a manual, cumbersome and time consuming process

Page 10: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

10

CS*Comply - Periodic Assignment Review

Review Assignments

Review Initiator

Initiate Review

Process Owners

Complete Review

Notification

Ap

pro

ve

Reject

Notifications

Process Review

Rejected Assignments

Automatically Removed

Review Initiator

Page 11: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

11

CS*Comply - Automated Assignment Provisioning

Initiate Approval Process & Invoke Scanning Engine

(if required)

End-User

Request Access & Removal

Provisioning Approvers

Responsibility Automatically Assigned or Removed

Notification

Approve

Re

jec

t

Notification Notification

Is this request for Access or Removal

Access

Do remove requests require

approval? R

em

ov

e

Yes

No

Automatically Approved

Page 12: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

12

CS*Comply – Supervisor Automated Assignment Provisioning

Initiate Approval Process & Invoke Scanning Engine

Supervisor

Request Access &

Removal for Subordinate

Provisioning Approvers

Responsibility Automatically Assigned or Removed

If new FND

User created then also

assign default responsibilities

Notification

Approve

Re

jec

t

Does FND User exist

Create new FND

User

No

Yes

Notification Notification

If new FND user has no

assignments, disable it

Is this request for Access or Removal

Do remove requests require

approval?

Re

mo

ve

Access

Automatically Approved

No

Yes

Page 13: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

13

CS*Comply - Automated User Termination

Is HR Record associated with Application User

Employee

HR Record Terminated

Notification

Ye

s

FND User & Assignments End-

Dated Automatically

Supervisor Notification

Group

Page 14: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

14

Demonstration

Page 15: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

15

CS*Comply - Key Benefits/Value Proposition

• CS*Comply brings many benefits... o Streamline review process

o Streamline user provisioning process

o Eliminate manual processes

o Satisfy auditors

o Reduce time and cost of audits

o Out of the Box Solution

o Substantial Time Savings

o Considerable Cost Savings

o Tightly Integrated

o Unique functionality

o Very easy to use

o Fully embedded into Oracle E-Business Suite

o Native look and feel, users feel at home

o Simple installation (the whole suite can be installed in less than 1 hour)

o Rapid implementation

o Rapid return on investment

Page 16: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

16

Multiple Capabilities

Page 17: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

17

CaoSys Solution Suite

• A comprehensive suite of solutions... o Improving efficiency with productivity solutions

o Delivering assurance through compliance

Page 18: Webinar Logistics - Risk Advisory Services for Oracle ... · • Assignment Provisioning is the process of granting or revoking users access to one or more responsibilities • For

Copyright © 1999-2012 CaoSys Limited. All rights reserved. Oracle and Oracle E-Business Suite are trademarks or registered trademarks of Oracle Corporation

18

Q & A