SlideShare uma empresa Scribd logo
1 de 13
Baixar para ler offline
Reference Architecture for
Shared Services Hosting
for Payments Bank &
Small Finance Bank
Author: Sunil Babu
Date: 15-Feb-2016
Version: 1.0
Key Requirements
Business Requirements:
• Shared services hosting for Payment Banks & Small
Banks on a Shared Model & Shared Infra
• Fit for Purpose systems / Architecture
• Security compliant to mandates
• Lowest TCO
Technology Requirements:
• Scalable Architecture to handle rapid & quantified growth
• Architecture should logically partition bank data in an
optimal way
• Dynamic Infra Provisioning
• Lean Architecture
• High Performance and throughput at database and data
access layer
• Better User experience via low latency access response
• Effective Load distribution for optimum resource utilization
and better ROI
• Data security at rest and in transit
• Secure access to the environment for delivery team
• Ability to easily manage and replicate multiple environments
based on blueprint architecture.
High Level Architecture
Payments Bank & SFB - Shared Services
Infrastructure (DC, DR, Near-DR)
Networking (WAN, MPLS, SDN…)
Physical (Servers, SAN,Workstations..)
Virtualization (ESX, Hyper-V, Xen..)
Operating System
Compute Storage Network
Platform
Database Middleware ESB, MQ…
Core Application /TX
Processing Services
User Interface Services
Security
Management
Integration Services (API)
DevOps(Build,Test,Release)
ServiceMgmtPerf.MgmtEnterpriseMgmt
Bank
Users
Service
Provid
er
Team
• BankTeam
(Operation
s,
Managem
ent,
Business)
• Partners
• Merchants
• Customers
(Retail /
Corporate)
• Developm
ent
• Operations
• Infra
• Security
• Network
• Applicatio
ns
• Platform
• SOC, NOC,
TOC
Channels & Other
AncillaryApps
Design Principles & Assumptions
• Core Application (e.g. CBS),TX processingApplication (e.g. Cards), Functional Applications (e.g.AML) to be deployed
as separate instances
• Customer related Data to be stored in separate database
• There can be one instance of Non-Functional Apps such as APM, UIM, SOC etc.’
• Leverage on Multi-tenant database function to reduce DB license costs
• Leverage on running non-core functions such as Reporting, Backup from Near-DR & DR site to reduce load on DC
• Shared Applications such as APM, Infra Management, Asset Management should enable treating a bank as a logical
entity thus enabling monitoring/management/reporting for it separately
• Dynamic Infra Provisioning can achieved by leveraging Platform-as-a-Service (PaaS) technologies such as
Infrastructure-as-a-Service (IaaS), Database-as-a-Service (DBaaS) & Middleware-as-a-Service (MWaaS)
• When implementing PaaS, need to get assurance on version change and its impact on hosted applications.
Customer
Relationship
IT Governance
and
Compliance
Corporate
Administration
Products and
Transactions
ATM POS
Mobile/
Tablets
Internet
(Ret/Corp)
Branch KIOSKS
Phone
Banking
CRM
CRM
Analytics
Marketing
and
Campaigns
CRM Social
CRM Sales &
Service
Procurement HRMS GL
Fixed
Assets
Budgeting Projects Expense Management
Compliance BASEL
AML/KY
C
ALM/FT
P
Regulatory
RBI/ADF
Risk
Management
Governance Audit
Fraud
Management
Channels
Application Architecture
CASA
Microfina
nce
Term
Deposits
Personal
Finance
Wealth
Managem
ent
KYC
Gov
Business
Corporate
Banking
Payments Remittance Bills BC
Cash
management
Forex Treasury
DCMS
Asset
Manageme
nt
AML
Cards
Loyalty
Programs
INB
Mobile
Banking
Contact
Centre
Switch
ePG
Data Architecture
Encryption
Secure DB Instance for each Bank
Data Masking
Privileged
Access
Control
Replication for RTO, RPO &
Offloading of Non-Core
Functions
PR Near-DR / DR
Clustering for HA
(Active-Active or Active-Passive)
Compression
for Backup &
Archival
Columnar
Compression
Activity
Auditing Multitenant Container Database for Payments Bank / SFB Instance
Common DB Instance for all Banks
Multitenant Container Database
Information Architecture Information
Lifecycle
Management
Aggregations & SummariesUnstructured Data
Master & Reference Data, CIF
Operational DataStructured Data
External Ecosystem Service Provider DC – Bank “A” Application Instance
API Gateway
Channel / Wallet
App Services
CBS
Payment Gateway
2FA
Mobile Wallet App
TCP/IP
ISO8583
API Gateway
• Central Policy Enforcement on outgoing/
incoming traffic
• Threat Protection
• Non-Repudiation
• API Monitoring/ Mgmt.
• API Analytics
• ESB-Like Web Service Mediation
• Branded API Portal for Merchants & Developers
DMZ Corporate
Network
API based Integration Architecture
Risk Authentication
Merchants/Partners
Technology Operations Centre for all hosted banks - Architecture
Service Provider
Command Centre
DC & DR
Network
(MPLS/Leased
Line/WAN/LAN)
Applications
Servers
Workstations
Operating Systems
Transactions
Monitor
Manage
Administer
Proactive
Monitoring
(HW, SW, NW)
SLA
Management
Config/Patch
Management
App/Backup
Job
Management
RCA/ Rectify/
Restore
Server/Client
Automation
Asset Lifecycle
Management
Incident/Proble
m/Change
Management
Service
Management
Automation
Transaction
Management
(Online +
Mobile)
Database &
Middleware
Monitoring
TOC Solution Building Blocks
KPI(s)
• Business SLA
• Response Time
• RTO/RPO
• Throughput
• MTTR
• Time to Market/ Time to
Value
• TCO / RTO
Measured
Against
Technology Operations Centre - Integration
DC & DR
Applications
Servers
Workstations
Operating Systems
Transactions
Infra
Mgmt
Network
Mgmt
Automation
Application
Perf. Mgmt
Mobile
Application
Analytics
Service Desk
Alarms
Config Mgmt
Event Mgmt
Availability
Performance
“Metrics”
Agent +
Agentless
(SNMP)
“Metrics”
Agentless
(SNMP)
Workload Scheduling
& Management
Dashboard - Workload
Monitoring
& SLA Management
Dashboard/Reports/Alar
ms – Historical Reporting
Topology/Alarms – RCA
Reporting
Defects
Incident
Change Mgmt
Config Mgmt
KPI(s)/Trends/SLA
Reporting
Mobile/Web Customer Experience
& Business TX. Monitoring from
Mobile to backend
“Metrics”
Agent +
Web Traffic
“Metrics”
From Customer
Mobile Device
Events/Violations
Workload
(EOD, BOD, MIS..)
Security Architecture
Payments Bank & SFB - Shared Services
Infrastructure (DC, DR, Near-DR)
Networking (WAN, MPLS, SDN…)
Physical (Servers, SAN, Workstations..)
Virtualization (ESX, Hyper-V, Xen..)
Operating System
Compute Storage Network
Platform
Database Middleware ESB, MQ…
Core Application / TX
Processing Services
User Interface Services Integration Services (API)
Channels & Other
Ancillary Apps
WAFDDOS API
Management
IDS/IPS
PIM/PAM
2 Factor
Authentication
Fraud Risk
Management
IPsec APT
Security Operations Centre
Event Source
Points of Presence SOC Core SOC Output
Databases
Mainframe
Network
Collectors
SOC Analysis server
SOC DB server
SOC App server
Compliance Dashboard
Operational Dashboard
Logs,
Events,
Feeds
API
Management
2 Factor
Authentication
WAF
DDOS
IDS/IPS
IPsec
PIM/PAM
Fraud Risk
Management
APT
Deployment Architecture for a Bank
Bank “X” on Shared Services Hosting Model
Infrastructure (DC, DR, Near-DR)
Networking (WAN, MPLS, SDN…)
Physical (Servers, SAN,Workstations..)
Virtualization (ESX, Hyper-V, Xen..)
Operating System
Compute Storage Network
Platform
Database Middleware ESB, MQ…
Core Application /TX
Processing Services
User Interface Services
Management
Integration Services (API)
DevOps(Build,Test,Release)
ServiceMgmtPerf.MgmtEnterpriseMgmt
Channels & Other
AncillaryApps
Security
API
Management
2 Factor
Authentication
WAF
DDOS
IDS/IPS
IPsec
PIM/PAM
Fraud Risk
Management
APT
Created Specific
for Bank “X”
Shared Services
Reference Architecture for Shared Services Hosting_SunilBabu_V2.0

Mais conteúdo relacionado

Mais procurados

IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
Rob Akershoek
 
Enterprise Architecture Toolkit Overview
Enterprise Architecture Toolkit OverviewEnterprise Architecture Toolkit Overview
Enterprise Architecture Toolkit Overview
Mike Walker
 
Review of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability ModelsReview of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability Models
Alan McSweeney
 
Gartner's IT Score Wallchart
Gartner's IT Score WallchartGartner's IT Score Wallchart
Gartner's IT Score Wallchart
Paul Sullivan
 

Mais procurados (20)

Enterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful BusinessEnterprise Architecture Governance: A Framework for Successful Business
Enterprise Architecture Governance: A Framework for Successful Business
 
IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022 IT4IT / DevOps Tooling Landscape 2022
IT4IT / DevOps Tooling Landscape 2022
 
ValueFlowIT: A new IT Operating Model Emerges
ValueFlowIT: A new IT Operating Model EmergesValueFlowIT: A new IT Operating Model Emerges
ValueFlowIT: A new IT Operating Model Emerges
 
EA maturity models
EA maturity modelsEA maturity models
EA maturity models
 
Effective Security Operation Center - present by Reza Adineh
Effective Security Operation Center - present by Reza AdinehEffective Security Operation Center - present by Reza Adineh
Effective Security Operation Center - present by Reza Adineh
 
ITIL v3 vs v4
ITIL v3 vs v4ITIL v3 vs v4
ITIL v3 vs v4
 
What is a secure enterprise architecture roadmap?
What is a secure enterprise architecture roadmap?What is a secure enterprise architecture roadmap?
What is a secure enterprise architecture roadmap?
 
Introduction to ITIL 4 and IT service management
Introduction to ITIL 4 and IT service managementIntroduction to ITIL 4 and IT service management
Introduction to ITIL 4 and IT service management
 
Enterprise Architecture Toolkit Overview
Enterprise Architecture Toolkit OverviewEnterprise Architecture Toolkit Overview
Enterprise Architecture Toolkit Overview
 
Digital Operating Model & IT4IT
Digital Operating Model & IT4ITDigital Operating Model & IT4IT
Digital Operating Model & IT4IT
 
Architecting ITSM for IT Self-Service Success
Architecting ITSM for IT Self-Service Success Architecting ITSM for IT Self-Service Success
Architecting ITSM for IT Self-Service Success
 
How to Hire and Compensate Your Customer Success Management Team
How to Hire and Compensate Your Customer Success Management TeamHow to Hire and Compensate Your Customer Success Management Team
How to Hire and Compensate Your Customer Success Management Team
 
US DOC ACMM Wallchart
US DOC ACMM WallchartUS DOC ACMM Wallchart
US DOC ACMM Wallchart
 
TOGAF Complete Slide Deck
TOGAF Complete Slide DeckTOGAF Complete Slide Deck
TOGAF Complete Slide Deck
 
Integrated IT Service Management: From Strategy to Implementing to User Adoption
Integrated IT Service Management: From Strategy to Implementing to User AdoptionIntegrated IT Service Management: From Strategy to Implementing to User Adoption
Integrated IT Service Management: From Strategy to Implementing to User Adoption
 
Guidewire values and_practices
Guidewire values and_practicesGuidewire values and_practices
Guidewire values and_practices
 
IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1IT4IT - The Full Story for Digital Transformation - Part 1
IT4IT - The Full Story for Digital Transformation - Part 1
 
Review of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability ModelsReview of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability Models
 
IT Service Management Overview
IT Service Management OverviewIT Service Management Overview
IT Service Management Overview
 
Gartner's IT Score Wallchart
Gartner's IT Score WallchartGartner's IT Score Wallchart
Gartner's IT Score Wallchart
 

Destaque

Tss Reference Architecture Reduced
Tss Reference Architecture   ReducedTss Reference Architecture   Reduced
Tss Reference Architecture Reduced
aadly
 
Fs tech-journal-cost-management
Fs tech-journal-cost-managementFs tech-journal-cost-management
Fs tech-journal-cost-management
Karthik Arumugham
 
Disaster Recovery Deep Dive
Disaster Recovery Deep DiveDisaster Recovery Deep Dive
Disaster Recovery Deep Dive
Liberteks
 
Disaster recovery and the cloud
Disaster recovery and the cloudDisaster recovery and the cloud
Disaster recovery and the cloud
Jason Dea
 
Service Oriented Architecture Luqman
Service Oriented Architecture LuqmanService Oriented Architecture Luqman
Service Oriented Architecture Luqman
Luqman Shareef
 

Destaque (16)

Soa best practice
Soa best practiceSoa best practice
Soa best practice
 
Tss Reference Architecture Reduced
Tss Reference Architecture   ReducedTss Reference Architecture   Reduced
Tss Reference Architecture Reduced
 
Fs tech-journal-cost-management
Fs tech-journal-cost-managementFs tech-journal-cost-management
Fs tech-journal-cost-management
 
Disaster Recovery Deep Dive
Disaster Recovery Deep DiveDisaster Recovery Deep Dive
Disaster Recovery Deep Dive
 
disaster-recovery-online
disaster-recovery-onlinedisaster-recovery-online
disaster-recovery-online
 
Disaster Recovery- A Case Study
Disaster Recovery- A Case StudyDisaster Recovery- A Case Study
Disaster Recovery- A Case Study
 
SOA @ T-Mobile: Automatic Service Provisioning to the ESB
SOA @ T-Mobile: Automatic Service Provisioning to the ESBSOA @ T-Mobile: Automatic Service Provisioning to the ESB
SOA @ T-Mobile: Automatic Service Provisioning to the ESB
 
Technology Management In Banks Abbr
Technology Management In Banks AbbrTechnology Management In Banks Abbr
Technology Management In Banks Abbr
 
Enterprise-Grade Disaster Recovery Without Breaking the Bank
Enterprise-Grade Disaster Recovery Without Breaking the BankEnterprise-Grade Disaster Recovery Without Breaking the Bank
Enterprise-Grade Disaster Recovery Without Breaking the Bank
 
Designing a Modern Disaster Recovery Environment
Designing a Modern Disaster Recovery EnvironmentDesigning a Modern Disaster Recovery Environment
Designing a Modern Disaster Recovery Environment
 
Pros and Cons of Moving to Cloud and Managed Services
Pros and Cons of Moving to Cloud and Managed ServicesPros and Cons of Moving to Cloud and Managed Services
Pros and Cons of Moving to Cloud and Managed Services
 
Business Continuity & Disaster Recovery with Microsoft Azure
Business Continuity & Disaster Recovery with Microsoft AzureBusiness Continuity & Disaster Recovery with Microsoft Azure
Business Continuity & Disaster Recovery with Microsoft Azure
 
Deep-Dive: Secure API Management
Deep-Dive: Secure API ManagementDeep-Dive: Secure API Management
Deep-Dive: Secure API Management
 
Disaster recovery and the cloud
Disaster recovery and the cloudDisaster recovery and the cloud
Disaster recovery and the cloud
 
Enterprise grade disaster recovery without breaking the bank
Enterprise grade disaster recovery without breaking the bankEnterprise grade disaster recovery without breaking the bank
Enterprise grade disaster recovery without breaking the bank
 
Service Oriented Architecture Luqman
Service Oriented Architecture LuqmanService Oriented Architecture Luqman
Service Oriented Architecture Luqman
 

Semelhante a Reference Architecture for Shared Services Hosting_SunilBabu_V2.0

Ibm cloud forum managing heterogenousclouds_final
Ibm cloud forum managing heterogenousclouds_finalIbm cloud forum managing heterogenousclouds_final
Ibm cloud forum managing heterogenousclouds_final
Mauricio Godoy
 
Introduction to PaaS
Introduction to PaaSIntroduction to PaaS
Introduction to PaaS
Chris Haddad
 
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
EuroCloud
 
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
Liviu Claudiu Cismaru
 
Azure Overview Csco
Azure Overview CscoAzure Overview Csco
Azure Overview Csco
rajramab
 
Application Portfolio Migration v1
Application Portfolio Migration v1Application Portfolio Migration v1
Application Portfolio Migration v1
Arthur Ching
 
Talk IT_Oracle AP_이진호 부장_111102
Talk IT_Oracle AP_이진호 부장_111102 Talk IT_Oracle AP_이진호 부장_111102
Talk IT_Oracle AP_이진호 부장_111102
Cana Ko
 
Cloud Capacity Management
Cloud Capacity ManagementCloud Capacity Management
Cloud Capacity Management
Precisely
 
IBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
IBM Technology Day 2013 Smarter Computing P Perdaems Salle RomeIBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
IBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
IBM Switzerland
 
adopt_soa.94145841
adopt_soa.94145841adopt_soa.94145841
adopt_soa.94145841
ypai
 

Semelhante a Reference Architecture for Shared Services Hosting_SunilBabu_V2.0 (20)

Architecting SaaS
Architecting SaaSArchitecting SaaS
Architecting SaaS
 
Centerity Solution overview
Centerity Solution overviewCenterity Solution overview
Centerity Solution overview
 
Ibm cloud forum managing heterogenousclouds_final
Ibm cloud forum managing heterogenousclouds_finalIbm cloud forum managing heterogenousclouds_final
Ibm cloud forum managing heterogenousclouds_final
 
Introduction to PaaS
Introduction to PaaSIntroduction to PaaS
Introduction to PaaS
 
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
Virgílio Vargas Presentations / CloudViews.Org - Cloud Computing Conference 2...
 
Making Sense Of Cloud Computing - by Mark Rivington
Making Sense Of Cloud Computing - by Mark RivingtonMaking Sense Of Cloud Computing - by Mark Rivington
Making Sense Of Cloud Computing - by Mark Rivington
 
Cloud Computing 2010 - IBM Italia - Mariano Ammirabile
Cloud Computing 2010 - IBM Italia - Mariano AmmirabileCloud Computing 2010 - IBM Italia - Mariano Ammirabile
Cloud Computing 2010 - IBM Italia - Mariano Ammirabile
 
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
 
Azure Overview Csco
Azure Overview CscoAzure Overview Csco
Azure Overview Csco
 
Application Portfolio Migration v1
Application Portfolio Migration v1Application Portfolio Migration v1
Application Portfolio Migration v1
 
Talk IT_Oracle AP_이진호 부장_111102
Talk IT_Oracle AP_이진호 부장_111102 Talk IT_Oracle AP_이진호 부장_111102
Talk IT_Oracle AP_이진호 부장_111102
 
Cloud Capacity Management
Cloud Capacity ManagementCloud Capacity Management
Cloud Capacity Management
 
IBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
IBM Technology Day 2013 Smarter Computing P Perdaems Salle RomeIBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
IBM Technology Day 2013 Smarter Computing P Perdaems Salle Rome
 
Augmenting IT strategy with Enterprise architecture assessment
Augmenting IT strategy with Enterprise architecture assessmentAugmenting IT strategy with Enterprise architecture assessment
Augmenting IT strategy with Enterprise architecture assessment
 
(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS
 
Icinga Camp Bangalore - Enterprise exceptions
Icinga Camp Bangalore - Enterprise exceptions Icinga Camp Bangalore - Enterprise exceptions
Icinga Camp Bangalore - Enterprise exceptions
 
adopt_soa.94145841
adopt_soa.94145841adopt_soa.94145841
adopt_soa.94145841
 
Where to Begin? Application Portfolio Migration
Where to Begin? Application Portfolio MigrationWhere to Begin? Application Portfolio Migration
Where to Begin? Application Portfolio Migration
 
Virtualization and Automation: How Dynamic is Your Data Center
Virtualization and Automation: How Dynamic is Your Data CenterVirtualization and Automation: How Dynamic is Your Data Center
Virtualization and Automation: How Dynamic is Your Data Center
 
MT125 Virtustream Enterprise Cloud: Purpose Built to Run Mission Critical App...
MT125 Virtustream Enterprise Cloud: Purpose Built to Run Mission Critical App...MT125 Virtustream Enterprise Cloud: Purpose Built to Run Mission Critical App...
MT125 Virtustream Enterprise Cloud: Purpose Built to Run Mission Critical App...
 

Reference Architecture for Shared Services Hosting_SunilBabu_V2.0

  • 1. Reference Architecture for Shared Services Hosting for Payments Bank & Small Finance Bank Author: Sunil Babu Date: 15-Feb-2016 Version: 1.0
  • 2. Key Requirements Business Requirements: • Shared services hosting for Payment Banks & Small Banks on a Shared Model & Shared Infra • Fit for Purpose systems / Architecture • Security compliant to mandates • Lowest TCO Technology Requirements: • Scalable Architecture to handle rapid & quantified growth • Architecture should logically partition bank data in an optimal way • Dynamic Infra Provisioning • Lean Architecture • High Performance and throughput at database and data access layer • Better User experience via low latency access response • Effective Load distribution for optimum resource utilization and better ROI • Data security at rest and in transit • Secure access to the environment for delivery team • Ability to easily manage and replicate multiple environments based on blueprint architecture.
  • 3. High Level Architecture Payments Bank & SFB - Shared Services Infrastructure (DC, DR, Near-DR) Networking (WAN, MPLS, SDN…) Physical (Servers, SAN,Workstations..) Virtualization (ESX, Hyper-V, Xen..) Operating System Compute Storage Network Platform Database Middleware ESB, MQ… Core Application /TX Processing Services User Interface Services Security Management Integration Services (API) DevOps(Build,Test,Release) ServiceMgmtPerf.MgmtEnterpriseMgmt Bank Users Service Provid er Team • BankTeam (Operation s, Managem ent, Business) • Partners • Merchants • Customers (Retail / Corporate) • Developm ent • Operations • Infra • Security • Network • Applicatio ns • Platform • SOC, NOC, TOC Channels & Other AncillaryApps
  • 4. Design Principles & Assumptions • Core Application (e.g. CBS),TX processingApplication (e.g. Cards), Functional Applications (e.g.AML) to be deployed as separate instances • Customer related Data to be stored in separate database • There can be one instance of Non-Functional Apps such as APM, UIM, SOC etc.’ • Leverage on Multi-tenant database function to reduce DB license costs • Leverage on running non-core functions such as Reporting, Backup from Near-DR & DR site to reduce load on DC • Shared Applications such as APM, Infra Management, Asset Management should enable treating a bank as a logical entity thus enabling monitoring/management/reporting for it separately • Dynamic Infra Provisioning can achieved by leveraging Platform-as-a-Service (PaaS) technologies such as Infrastructure-as-a-Service (IaaS), Database-as-a-Service (DBaaS) & Middleware-as-a-Service (MWaaS) • When implementing PaaS, need to get assurance on version change and its impact on hosted applications.
  • 5. Customer Relationship IT Governance and Compliance Corporate Administration Products and Transactions ATM POS Mobile/ Tablets Internet (Ret/Corp) Branch KIOSKS Phone Banking CRM CRM Analytics Marketing and Campaigns CRM Social CRM Sales & Service Procurement HRMS GL Fixed Assets Budgeting Projects Expense Management Compliance BASEL AML/KY C ALM/FT P Regulatory RBI/ADF Risk Management Governance Audit Fraud Management Channels Application Architecture CASA Microfina nce Term Deposits Personal Finance Wealth Managem ent KYC Gov Business Corporate Banking Payments Remittance Bills BC Cash management Forex Treasury DCMS Asset Manageme nt AML Cards Loyalty Programs INB Mobile Banking Contact Centre Switch ePG
  • 6. Data Architecture Encryption Secure DB Instance for each Bank Data Masking Privileged Access Control Replication for RTO, RPO & Offloading of Non-Core Functions PR Near-DR / DR Clustering for HA (Active-Active or Active-Passive) Compression for Backup & Archival Columnar Compression Activity Auditing Multitenant Container Database for Payments Bank / SFB Instance Common DB Instance for all Banks Multitenant Container Database Information Architecture Information Lifecycle Management Aggregations & SummariesUnstructured Data Master & Reference Data, CIF Operational DataStructured Data
  • 7. External Ecosystem Service Provider DC – Bank “A” Application Instance API Gateway Channel / Wallet App Services CBS Payment Gateway 2FA Mobile Wallet App TCP/IP ISO8583 API Gateway • Central Policy Enforcement on outgoing/ incoming traffic • Threat Protection • Non-Repudiation • API Monitoring/ Mgmt. • API Analytics • ESB-Like Web Service Mediation • Branded API Portal for Merchants & Developers DMZ Corporate Network API based Integration Architecture Risk Authentication Merchants/Partners
  • 8. Technology Operations Centre for all hosted banks - Architecture Service Provider Command Centre DC & DR Network (MPLS/Leased Line/WAN/LAN) Applications Servers Workstations Operating Systems Transactions Monitor Manage Administer Proactive Monitoring (HW, SW, NW) SLA Management Config/Patch Management App/Backup Job Management RCA/ Rectify/ Restore Server/Client Automation Asset Lifecycle Management Incident/Proble m/Change Management Service Management Automation Transaction Management (Online + Mobile) Database & Middleware Monitoring TOC Solution Building Blocks KPI(s) • Business SLA • Response Time • RTO/RPO • Throughput • MTTR • Time to Market/ Time to Value • TCO / RTO Measured Against
  • 9. Technology Operations Centre - Integration DC & DR Applications Servers Workstations Operating Systems Transactions Infra Mgmt Network Mgmt Automation Application Perf. Mgmt Mobile Application Analytics Service Desk Alarms Config Mgmt Event Mgmt Availability Performance “Metrics” Agent + Agentless (SNMP) “Metrics” Agentless (SNMP) Workload Scheduling & Management Dashboard - Workload Monitoring & SLA Management Dashboard/Reports/Alar ms – Historical Reporting Topology/Alarms – RCA Reporting Defects Incident Change Mgmt Config Mgmt KPI(s)/Trends/SLA Reporting Mobile/Web Customer Experience & Business TX. Monitoring from Mobile to backend “Metrics” Agent + Web Traffic “Metrics” From Customer Mobile Device Events/Violations Workload (EOD, BOD, MIS..)
  • 10. Security Architecture Payments Bank & SFB - Shared Services Infrastructure (DC, DR, Near-DR) Networking (WAN, MPLS, SDN…) Physical (Servers, SAN, Workstations..) Virtualization (ESX, Hyper-V, Xen..) Operating System Compute Storage Network Platform Database Middleware ESB, MQ… Core Application / TX Processing Services User Interface Services Integration Services (API) Channels & Other Ancillary Apps WAFDDOS API Management IDS/IPS PIM/PAM 2 Factor Authentication Fraud Risk Management IPsec APT
  • 11. Security Operations Centre Event Source Points of Presence SOC Core SOC Output Databases Mainframe Network Collectors SOC Analysis server SOC DB server SOC App server Compliance Dashboard Operational Dashboard Logs, Events, Feeds API Management 2 Factor Authentication WAF DDOS IDS/IPS IPsec PIM/PAM Fraud Risk Management APT
  • 12. Deployment Architecture for a Bank Bank “X” on Shared Services Hosting Model Infrastructure (DC, DR, Near-DR) Networking (WAN, MPLS, SDN…) Physical (Servers, SAN,Workstations..) Virtualization (ESX, Hyper-V, Xen..) Operating System Compute Storage Network Platform Database Middleware ESB, MQ… Core Application /TX Processing Services User Interface Services Management Integration Services (API) DevOps(Build,Test,Release) ServiceMgmtPerf.MgmtEnterpriseMgmt Channels & Other AncillaryApps Security API Management 2 Factor Authentication WAF DDOS IDS/IPS IPsec PIM/PAM Fraud Risk Management APT Created Specific for Bank “X” Shared Services