SlideShare uma empresa Scribd logo
1 de 17
Baixar para ler offline
<Insert Picture Here>




Smart Strategies for Reducing Risk and Improving
Compliance
Artur Alves
Solution Architect
Oracle Portugal
artur.alves@oracle.com
The following is intended to outline our general
product direction. It is intended for information
purposes only, and may not be incorporated into any
contract. It is not a commitment to deliver any
material, code, or functionality, and should not be
relied upon in making purchasing decisions.
The development, release, and timing of any
features or functionality described for Oracle’s
products remains at the sole discretion of Oracle.




                 Copyright © 2011, Oracle. Proprietary
Agenda

                                                           <Insert Picture Here>
●
    Factors increasing risk

●
    Strategies for reducing risk
●
    Demo

●
    Case Studies




                   Copyright © 2011, Oracle. Proprietary
Video – Too Much Information




           Copyright © 2011, Oracle. Proprietary
What Is Increasing Risk?




    Dynamic User                             Application                         Complex
     Population                              Explosion                          Regulatory
                                                                               Environment
 Corporate user                         IT spending on SaaS                   Regulations are increasing
  population is                           apps projected to                      world-wide
  increasingly mobile                     increase 5x in 2011*                  40% of IT budget is spent
 85% of all mobile                      25 billion app                         on addressing compliance
  devices are                             downloads projected                    mandates*
  unsecured by IT*                        for 2011*

*   Malicious Mobile Threats Report,    * IDC, Dec 2010                        * Forrester Consulting, 2010
    Juniper Networks 2011



                                       Copyright © 2011, Oracle. Proprietary
Strategies for Reducing Risk and
Improving Compliance


  Analyze Your Risks



  Prioritize Based on Economics and Impact



  Create a Sustainable Program




                 Copyright © 2011, Oracle. Proprietary
Risk Score Is Your Priority

                                                       Share        Last       Risk
User      Job Role     RACF        Siebel CRM
                                                       Point       Login      Score
                                     Manage
                        Excess                          Access      Sep 5
 John      Product                    Customer
                                                         Dev        2011 at      95
 Doe       Manager      Access       Manage
                                                         Specs     9am EST
                                      Opportunity


                                     Manage
                                                                   Jan 12,
                         SoD          Customer
  Jim                                                   Change    2000 at
           Sales Rep   Violation     Manage                                     97
 Harris                                                  Pricing    10am
                                      Opportunity
                                                                    PDT


                                     Manage
                                                                     Sep 5
                                      Customer
                        Excess                                      2011 at
 Steve                               Manage
          HR Manager                                                 10am        98
 Brown                  Access        Opportunity
                                                                   EST from
                                                                    Nigeria




                          Copyright © 2011, Oracle. Proprietary
Video – Audit Eye




            Copyright © 2011, Oracle. Proprietary
Prioritize based on economics and impact
Consolidate      Automate              Define                Assign Access Monitor & Enforce
& Correlate      Identity-based        Enterprise            via Roles     via Roles
Entitlements     Controls              Roles

                                                               Role-based
                                                               Provisioning
                                        Role
                                   Administration &
                                     Governance
                    Access
     Build        Certification
Idty Warehouse       & SoD


                                                                              Activity Monitoring
                                                                                       &
                                                                                Entitlements
                                                                                 Management




                                  Copyright © 2011, Oracle. Proprietary
Solution: Create a Sustainable Program


                                                        Share        Last       Risk
User      Job Role     RACF        Siebel CRM
                                                        Point       Login      Score
                                      Manage
                         Disable                         Access      Sep 5
 John      Product                     Customer
                                                          Dev        2011 at      95
 Doe       Manager       Access       Manage
                                                          Specs     9am EST
                                       Opportunity


                                      Manage
                                                                    Jan 12,
                     Closed Loop       Customer
  Jim                                                    Change    2000 at
           Sales Rep Remediation      Manage                                     97
 Harris                                                   Pricing    10am
                                       Opportunity
                                                                     PDT


                                      Manage
                                                                      Sep 5
                                       Customer
                         Disable                                     2011 at
 Steve                                Manage
          HR Manager                                                  10am        98
 Brown                   Access        Opportunity
                                                                    EST from
                                                                     Nigeria




                           Copyright © 2011, Oracle. Proprietary
Oracle Identity Analytics 11g
 Rapid and Sustainable Compliance Automation

          Identity/Access                                               Role Governance
          Data Sources

          Oracle Identity              Identity                         IT Audit Policy Monitoring
          Manager                     Warehouse
                                                                        Access Certification
          Oracle Access
          Manager                                                       Compliance Command Console



• Compliance Command Console
    • Actionable Dashboards, Business Reports & Comprehensive Analytics

• Accelerated and Sustainable Compliance Automation
    • Access Certification, IT Audit Policy Monitoring, Closed-loop Remediation, SoD Engine

• Intelligent Role Governance
    • Change Management, Attestation, Consolidation & Audit, Role Mining, Identity Cleansing

• Rich Identity Warehouse
    • Optimized for Analysis, Mining, Correlation, Reporting on Identity, Access and Policy Data



                                Copyright © 2011, Oracle. Proprietary
Demo
Oracle Identity Analytics




       Copyright © 2011, Oracle. Proprietary
Access Certification Flow
     Oracle Identity Analytics


     Set Up                                                  Automated Action                  Report Built
1    Periodic
     Review
                 2   Reviewer Is Notified
                     Goes to Self Service             3      is taken based on
                                                             Periodic Review
                                                                                           4   And Results
                                                                                               Stored in DB
                     Reviewer Selections

                                                                        Email Result
 What Is                     Certify                                    to User
 Reviewed?

                                                                        Automatically
                             Reject                                     Terminate User



Who Reviews                 Decline                                     Notify the
It?                                                                     Process Owner

                                                                                           Archive (Audit)
                           Delegate                                     Notify Delegated   Attested Data
                                                                        Reviewer
                                                                                           Attestation Actions
Start When?                                                                                Delegation Paths
How Often?                Comments




                                Copyright © 2011, Oracle. Proprietary
Closed-Loop Provisioning
Oracle Identity Analytics + Oracle Identity Manager

              Identity       Oracle Identity
             Warehouse
                               Analytics
                         Roles                    SoD Checks
             Entitlement Rules                    Resource Data           Entitlements Data

                             Oracle Identity
                               Manager                          Enterprise
                                                              Applications
                                                                     Custom
                                                                       Apps
                                                 GRANT or
                                                 REVOKE            Databases
                                                                   and LDAP

                                                              Mainframes



              •   User provisioning and de-provisioning (after Certification)
              •   Password reset & self-service account requests
              •   Delegated administration
              •   Approval and request workflow
              •   Compliance reports


                           Copyright © 2011, Oracle. Proprietary
Case Study: Accelerating ROI
     Financial Services Example

COMPANY OVERVIEW                                                      RESULTS

• A global bank with HQ in Europe, presence in NA,                    • 3.8M actions reduced to 26K
  Asia and Emerging Markets
                                                                      • Annual cost reduction = Euro 3.7M
• Over 90K employees, > 1000 apps, 500 DBs, 6000
  servers, and 1.1 M user accounts                                    • 90% app SOX certification
                                                                       complete in 1 week, 100% in 2
CHALLENGES/OPPORTUNITIES                                               months. SOX compliant!
• SOX Compliance a challenge with over 3.8M actions
                                                                      • 3 month manual process now takes
• Complex feed from multiple platforms – UNIX, Wintel,                  <2 weeks
  DBs

SOLUTION
• Implemented Oracle Identity Analytics (formerly Sun
 Role Manager)




                                  Copyright © 2011, Oracle. Proprietary
Copyright © 2011, Oracle. Proprietary
18   |   © 2011 Oracle Corporation – Proprietary and Confidential

Mais conteúdo relacionado

Mais procurados

Agile labs 2011
Agile labs   2011Agile labs   2011
Agile labs 2011vpraghu
 
CSLLC corporate capabilities
CSLLC corporate capabilitiesCSLLC corporate capabilities
CSLLC corporate capabilitiesDoug Hitchcock
 
Simeio e-Brochure
Simeio e-BrochureSimeio e-Brochure
Simeio e-BrochureDirectAxs
 
Simulation Professional - What each module can do for me
Simulation Professional - What each module can do for meSimulation Professional - What each module can do for me
Simulation Professional - What each module can do for mePrism Engineering, Inc.
 
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...Guidon Performance Solutions
 
For The Executive With Plant Productivity Problems Final
For The Executive With Plant Productivity Problems FinalFor The Executive With Plant Productivity Problems Final
For The Executive With Plant Productivity Problems FinalMark J Cundiff
 
Taking control of bring your own device byod with desktops as a service (daa ...
Taking control of bring your own device byod with desktops as a service (daa ...Taking control of bring your own device byod with desktops as a service (daa ...
Taking control of bring your own device byod with desktops as a service (daa ...Khazret Sapenov
 
Feb2008 Monthly Slides 1
Feb2008 Monthly Slides 1Feb2008 Monthly Slides 1
Feb2008 Monthly Slides 1Nadir Hussain
 
Maint overview sap
Maint overview sapMaint overview sap
Maint overview sapArghya Ray
 
Growing Up With Social
Growing Up With SocialGrowing Up With Social
Growing Up With SocialTed Sapountzis
 
We Don't Like our Service Management Tool
We Don't Like our Service Management ToolWe Don't Like our Service Management Tool
We Don't Like our Service Management ToolITSM Academy, Inc.
 
Tieto Manufacturing Operations Management – agility and support for manufactu...
Tieto Manufacturing Operations Management – agility and support for manufactu...Tieto Manufacturing Operations Management – agility and support for manufactu...
Tieto Manufacturing Operations Management – agility and support for manufactu...Tieto Corporation
 
Ibm pure flex overview cust pr
Ibm pure flex overview cust prIbm pure flex overview cust pr
Ibm pure flex overview cust prNatalija Pavic
 
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...IDS NEXT Business Solutions Pvt Ltd
 

Mais procurados (20)

Agile labs 2011
Agile labs   2011Agile labs   2011
Agile labs 2011
 
CSLLC corporate capabilities
CSLLC corporate capabilitiesCSLLC corporate capabilities
CSLLC corporate capabilities
 
Simeio e-Brochure
Simeio e-BrochureSimeio e-Brochure
Simeio e-Brochure
 
Simulation Professional - What each module can do for me
Simulation Professional - What each module can do for meSimulation Professional - What each module can do for me
Simulation Professional - What each module can do for me
 
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...
Leveraging Lean Thinking In Credit Unions: A Randolph-Brooks Federal Credit U...
 
For The Executive With Plant Productivity Problems Final
For The Executive With Plant Productivity Problems FinalFor The Executive With Plant Productivity Problems Final
For The Executive With Plant Productivity Problems Final
 
Taking control of bring your own device byod with desktops as a service (daa ...
Taking control of bring your own device byod with desktops as a service (daa ...Taking control of bring your own device byod with desktops as a service (daa ...
Taking control of bring your own device byod with desktops as a service (daa ...
 
JSoft Corporate presentation
JSoft Corporate presentationJSoft Corporate presentation
JSoft Corporate presentation
 
Feb2008 Monthly Slides 1
Feb2008 Monthly Slides 1Feb2008 Monthly Slides 1
Feb2008 Monthly Slides 1
 
IPM_E_10.2.12
IPM_E_10.2.12IPM_E_10.2.12
IPM_E_10.2.12
 
IPM_E_8.2.2012
IPM_E_8.2.2012IPM_E_8.2.2012
IPM_E_8.2.2012
 
IPM_E_8.2.2012
IPM_E_8.2.2012IPM_E_8.2.2012
IPM_E_8.2.2012
 
IPM_E_8.2.2012
IPM_E_8.2.2012IPM_E_8.2.2012
IPM_E_8.2.2012
 
Maint overview sap
Maint overview sapMaint overview sap
Maint overview sap
 
Growing Up With Social
Growing Up With SocialGrowing Up With Social
Growing Up With Social
 
Guidon And RBFCU Lean For Credit Unions Webinar
Guidon And RBFCU Lean For Credit Unions WebinarGuidon And RBFCU Lean For Credit Unions Webinar
Guidon And RBFCU Lean For Credit Unions Webinar
 
We Don't Like our Service Management Tool
We Don't Like our Service Management ToolWe Don't Like our Service Management Tool
We Don't Like our Service Management Tool
 
Tieto Manufacturing Operations Management – agility and support for manufactu...
Tieto Manufacturing Operations Management – agility and support for manufactu...Tieto Manufacturing Operations Management – agility and support for manufactu...
Tieto Manufacturing Operations Management – agility and support for manufactu...
 
Ibm pure flex overview cust pr
Ibm pure flex overview cust prIbm pure flex overview cust pr
Ibm pure flex overview cust pr
 
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...
IDS FortuneNext Enterprise: Helping Hotels Smile Their Way To Profitability, ...
 

Semelhante a Strategies for Reducing Access Controls Risk

Oracle Advance Controls
Oracle Advance ControlsOracle Advance Controls
Oracle Advance ControlsZeeshan Khan
 
Fusion app func_con8722_pdf_8722_0001
Fusion app func_con8722_pdf_8722_0001Fusion app func_con8722_pdf_8722_0001
Fusion app func_con8722_pdf_8722_0001jucaab
 
Talk IT_ Oracle_정봉기_111025
Talk IT_ Oracle_정봉기_111025Talk IT_ Oracle_정봉기_111025
Talk IT_ Oracle_정봉기_111025Cana Ko
 
Optimized Business Processes in the Age of Cloud Computing
Optimized Business Processes in the Age of Cloud ComputingOptimized Business Processes in the Age of Cloud Computing
Optimized Business Processes in the Age of Cloud ComputingOracle Day
 
Oracle Bi Foundation Sales V5.8
Oracle Bi Foundation Sales V5.8Oracle Bi Foundation Sales V5.8
Oracle Bi Foundation Sales V5.8Oracle
 
Oracle Bi Foundation
Oracle Bi FoundationOracle Bi Foundation
Oracle Bi Foundationjamesgj2004
 
2012 year Siebel CRM Strategy and Roadmap (outdated)
2012 year Siebel CRM Strategy and Roadmap (outdated)2012 year Siebel CRM Strategy and Roadmap (outdated)
2012 year Siebel CRM Strategy and Roadmap (outdated)Ilya Milshtein
 
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfReporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfInSync2011
 
Identity management11gr2launch finalv2
Identity management11gr2launch finalv2Identity management11gr2launch finalv2
Identity management11gr2launch finalv2OracleIDM
 
Analytics for procurement health care
Analytics for procurement health careAnalytics for procurement health care
Analytics for procurement health careHenner Schliebs
 
Ebs em con9053_pdf_9053_0001
Ebs em con9053_pdf_9053_0001Ebs em con9053_pdf_9053_0001
Ebs em con9053_pdf_9053_0001jucaab
 
Integrating oracle cloud and existing applications final sg
Integrating oracle cloud and existing applications  final sgIntegrating oracle cloud and existing applications  final sg
Integrating oracle cloud and existing applications final sgKen Ng
 
The Road to Agility Starts with BI
The Road to Agility Starts with BIThe Road to Agility Starts with BI
The Road to Agility Starts with BIKalido
 
Analytics For Procurement Health Care
Analytics For Procurement Health CareAnalytics For Procurement Health Care
Analytics For Procurement Health CareHenner Schliebs
 
Customer MDM Is Key To Strategic Business Success
Customer MDM Is Key To Strategic Business SuccessCustomer MDM Is Key To Strategic Business Success
Customer MDM Is Key To Strategic Business SuccessJerome Leonard
 
Increasing the ROI of SAP post-implementation
Increasing the ROI of SAP post-implementationIncreasing the ROI of SAP post-implementation
Increasing the ROI of SAP post-implementationRaul Morales
 
Asug Minnesota Using Six Sigma To Reduce Costs
Asug Minnesota   Using Six Sigma To Reduce CostsAsug Minnesota   Using Six Sigma To Reduce Costs
Asug Minnesota Using Six Sigma To Reduce CostsFabio Brancati
 

Semelhante a Strategies for Reducing Access Controls Risk (20)

Oracle Advance Controls
Oracle Advance ControlsOracle Advance Controls
Oracle Advance Controls
 
Fusion app func_con8722_pdf_8722_0001
Fusion app func_con8722_pdf_8722_0001Fusion app func_con8722_pdf_8722_0001
Fusion app func_con8722_pdf_8722_0001
 
Talk IT_ Oracle_정봉기_111025
Talk IT_ Oracle_정봉기_111025Talk IT_ Oracle_정봉기_111025
Talk IT_ Oracle_정봉기_111025
 
Optimized Business Processes in the Age of Cloud Computing
Optimized Business Processes in the Age of Cloud ComputingOptimized Business Processes in the Age of Cloud Computing
Optimized Business Processes in the Age of Cloud Computing
 
Oracle Bi Foundation Sales V5.8
Oracle Bi Foundation Sales V5.8Oracle Bi Foundation Sales V5.8
Oracle Bi Foundation Sales V5.8
 
Oracle Bi Foundation
Oracle Bi FoundationOracle Bi Foundation
Oracle Bi Foundation
 
Lean Enterprise Initiative
Lean Enterprise InitiativeLean Enterprise Initiative
Lean Enterprise Initiative
 
2012 year Siebel CRM Strategy and Roadmap (outdated)
2012 year Siebel CRM Strategy and Roadmap (outdated)2012 year Siebel CRM Strategy and Roadmap (outdated)
2012 year Siebel CRM Strategy and Roadmap (outdated)
 
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfReporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
 
Identity management11gr2launch finalv2
Identity management11gr2launch finalv2Identity management11gr2launch finalv2
Identity management11gr2launch finalv2
 
Analytics for procurement health care
Analytics for procurement health careAnalytics for procurement health care
Analytics for procurement health care
 
Ebs em con9053_pdf_9053_0001
Ebs em con9053_pdf_9053_0001Ebs em con9053_pdf_9053_0001
Ebs em con9053_pdf_9053_0001
 
Integrating oracle cloud and existing applications final sg
Integrating oracle cloud and existing applications  final sgIntegrating oracle cloud and existing applications  final sg
Integrating oracle cloud and existing applications final sg
 
The Road to Agility Starts with BI
The Road to Agility Starts with BIThe Road to Agility Starts with BI
The Road to Agility Starts with BI
 
Analytics For Procurement Health Care
Analytics For Procurement Health CareAnalytics For Procurement Health Care
Analytics For Procurement Health Care
 
Customer MDM Is Key To Strategic Business Success
Customer MDM Is Key To Strategic Business SuccessCustomer MDM Is Key To Strategic Business Success
Customer MDM Is Key To Strategic Business Success
 
Increasing the ROI of SAP post-implementation
Increasing the ROI of SAP post-implementationIncreasing the ROI of SAP post-implementation
Increasing the ROI of SAP post-implementation
 
Asug Minnesota Using Six Sigma To Reduce Costs
Asug Minnesota   Using Six Sigma To Reduce CostsAsug Minnesota   Using Six Sigma To Reduce Costs
Asug Minnesota Using Six Sigma To Reduce Costs
 
101 ab 1630-1700
101 ab 1630-1700101 ab 1630-1700
101 ab 1630-1700
 
101 ab 1630-1700
101 ab 1630-1700101 ab 1630-1700
101 ab 1630-1700
 

Mais de Artur Alves

Securing your Applications for the Cloud Age
Securing your Applications for the Cloud AgeSecuring your Applications for the Cloud Age
Securing your Applications for the Cloud AgeArtur Alves
 
Securing Corporate Applications and Data on Personal Devices
Securing Corporate Applications and Data on Personal DevicesSecuring Corporate Applications and Data on Personal Devices
Securing Corporate Applications and Data on Personal DevicesArtur Alves
 
Securing Mobile Device Access
Securing Mobile Device AccessSecuring Mobile Device Access
Securing Mobile Device AccessArtur Alves
 
GlassFish OSGi Server
GlassFish OSGi ServerGlassFish OSGi Server
GlassFish OSGi ServerArtur Alves
 
Java keynote preso
Java keynote presoJava keynote preso
Java keynote presoArtur Alves
 
A.Alves Sun GlassFish Portfolio preso - JavaPT '09
A.Alves Sun GlassFish Portfolio preso - JavaPT '09A.Alves Sun GlassFish Portfolio preso - JavaPT '09
A.Alves Sun GlassFish Portfolio preso - JavaPT '09Artur Alves
 
MySQL June/2009 FDTI - Portuguese Version
MySQL June/2009 FDTI - Portuguese VersionMySQL June/2009 FDTI - Portuguese Version
MySQL June/2009 FDTI - Portuguese VersionArtur Alves
 

Mais de Artur Alves (7)

Securing your Applications for the Cloud Age
Securing your Applications for the Cloud AgeSecuring your Applications for the Cloud Age
Securing your Applications for the Cloud Age
 
Securing Corporate Applications and Data on Personal Devices
Securing Corporate Applications and Data on Personal DevicesSecuring Corporate Applications and Data on Personal Devices
Securing Corporate Applications and Data on Personal Devices
 
Securing Mobile Device Access
Securing Mobile Device AccessSecuring Mobile Device Access
Securing Mobile Device Access
 
GlassFish OSGi Server
GlassFish OSGi ServerGlassFish OSGi Server
GlassFish OSGi Server
 
Java keynote preso
Java keynote presoJava keynote preso
Java keynote preso
 
A.Alves Sun GlassFish Portfolio preso - JavaPT '09
A.Alves Sun GlassFish Portfolio preso - JavaPT '09A.Alves Sun GlassFish Portfolio preso - JavaPT '09
A.Alves Sun GlassFish Portfolio preso - JavaPT '09
 
MySQL June/2009 FDTI - Portuguese Version
MySQL June/2009 FDTI - Portuguese VersionMySQL June/2009 FDTI - Portuguese Version
MySQL June/2009 FDTI - Portuguese Version
 

Strategies for Reducing Access Controls Risk

  • 1. <Insert Picture Here> Smart Strategies for Reducing Risk and Improving Compliance Artur Alves Solution Architect Oracle Portugal artur.alves@oracle.com
  • 2. The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle. Copyright © 2011, Oracle. Proprietary
  • 3. Agenda <Insert Picture Here> ● Factors increasing risk ● Strategies for reducing risk ● Demo ● Case Studies Copyright © 2011, Oracle. Proprietary
  • 4. Video – Too Much Information Copyright © 2011, Oracle. Proprietary
  • 5. What Is Increasing Risk? Dynamic User Application Complex Population Explosion Regulatory Environment  Corporate user  IT spending on SaaS  Regulations are increasing population is apps projected to world-wide increasingly mobile increase 5x in 2011*  40% of IT budget is spent  85% of all mobile  25 billion app on addressing compliance devices are downloads projected mandates* unsecured by IT* for 2011* * Malicious Mobile Threats Report, * IDC, Dec 2010 * Forrester Consulting, 2010 Juniper Networks 2011 Copyright © 2011, Oracle. Proprietary
  • 6. Strategies for Reducing Risk and Improving Compliance Analyze Your Risks Prioritize Based on Economics and Impact Create a Sustainable Program Copyright © 2011, Oracle. Proprietary
  • 7. Risk Score Is Your Priority Share Last Risk User Job Role RACF Siebel CRM Point Login Score  Manage Excess  Access Sep 5 John Product Customer Dev 2011 at 95 Doe Manager Access  Manage Specs 9am EST Opportunity  Manage Jan 12, SoD Customer Jim  Change 2000 at Sales Rep Violation  Manage 97 Harris Pricing 10am Opportunity PDT  Manage Sep 5 Customer Excess 2011 at Steve  Manage HR Manager 10am 98 Brown Access Opportunity EST from Nigeria Copyright © 2011, Oracle. Proprietary
  • 8. Video – Audit Eye Copyright © 2011, Oracle. Proprietary
  • 9. Prioritize based on economics and impact Consolidate Automate Define Assign Access Monitor & Enforce & Correlate Identity-based Enterprise via Roles via Roles Entitlements Controls Roles Role-based Provisioning Role Administration & Governance Access Build Certification Idty Warehouse & SoD Activity Monitoring & Entitlements Management Copyright © 2011, Oracle. Proprietary
  • 10. Solution: Create a Sustainable Program Share Last Risk User Job Role RACF Siebel CRM Point Login Score  Manage Disable  Access Sep 5 John Product Customer Dev 2011 at 95 Doe Manager Access  Manage Specs 9am EST Opportunity  Manage Jan 12, Closed Loop Customer Jim  Change 2000 at Sales Rep Remediation  Manage 97 Harris Pricing 10am Opportunity PDT  Manage Sep 5 Customer Disable 2011 at Steve  Manage HR Manager 10am 98 Brown Access Opportunity EST from Nigeria Copyright © 2011, Oracle. Proprietary
  • 11. Oracle Identity Analytics 11g Rapid and Sustainable Compliance Automation Identity/Access Role Governance Data Sources Oracle Identity Identity IT Audit Policy Monitoring Manager Warehouse Access Certification Oracle Access Manager Compliance Command Console • Compliance Command Console • Actionable Dashboards, Business Reports & Comprehensive Analytics • Accelerated and Sustainable Compliance Automation • Access Certification, IT Audit Policy Monitoring, Closed-loop Remediation, SoD Engine • Intelligent Role Governance • Change Management, Attestation, Consolidation & Audit, Role Mining, Identity Cleansing • Rich Identity Warehouse • Optimized for Analysis, Mining, Correlation, Reporting on Identity, Access and Policy Data Copyright © 2011, Oracle. Proprietary
  • 12. Demo Oracle Identity Analytics Copyright © 2011, Oracle. Proprietary
  • 13. Access Certification Flow Oracle Identity Analytics Set Up Automated Action Report Built 1 Periodic Review 2 Reviewer Is Notified Goes to Self Service 3 is taken based on Periodic Review 4 And Results Stored in DB Reviewer Selections Email Result What Is Certify to User Reviewed? Automatically Reject Terminate User Who Reviews Decline Notify the It? Process Owner Archive (Audit) Delegate Notify Delegated Attested Data Reviewer Attestation Actions Start When? Delegation Paths How Often? Comments Copyright © 2011, Oracle. Proprietary
  • 14. Closed-Loop Provisioning Oracle Identity Analytics + Oracle Identity Manager Identity Oracle Identity Warehouse Analytics Roles SoD Checks Entitlement Rules Resource Data Entitlements Data Oracle Identity Manager Enterprise Applications Custom Apps GRANT or REVOKE Databases and LDAP Mainframes • User provisioning and de-provisioning (after Certification) • Password reset & self-service account requests • Delegated administration • Approval and request workflow • Compliance reports Copyright © 2011, Oracle. Proprietary
  • 15. Case Study: Accelerating ROI Financial Services Example COMPANY OVERVIEW RESULTS • A global bank with HQ in Europe, presence in NA, • 3.8M actions reduced to 26K Asia and Emerging Markets • Annual cost reduction = Euro 3.7M • Over 90K employees, > 1000 apps, 500 DBs, 6000 servers, and 1.1 M user accounts • 90% app SOX certification complete in 1 week, 100% in 2 CHALLENGES/OPPORTUNITIES months. SOX compliant! • SOX Compliance a challenge with over 3.8M actions • 3 month manual process now takes • Complex feed from multiple platforms – UNIX, Wintel, <2 weeks DBs SOLUTION • Implemented Oracle Identity Analytics (formerly Sun Role Manager) Copyright © 2011, Oracle. Proprietary
  • 16. Copyright © 2011, Oracle. Proprietary
  • 17. 18 | © 2011 Oracle Corporation – Proprietary and Confidential