Deploying Mobile HR applications for Oracle EBS products@applaudsolutions.com @ApplaudSolution 1
Independent Software Vendor About Applaud Formed in 2008 Offices in UK and India Software vendor dedicated to Oracle EBS 50 Oracle EBS customers across UK, US, Middle East & Australia Oracle Gold Partner Sample of clients 2
Current demand for mobile HR UK
Mobile HCM F.U.D. Fear Uncertainty Doubt
The biggest blocker to Mobile HCM....no business case!
350 Properties 742 miles of Coastline 247,000 hectares of land 60,000 volunteers 12,000 employees
Sample project National Trust Time Entry Oracle Directory Payslip Personal Info Changes Dashboards Approvals Absence Bank Details Cost Centre Update Request Position Qualifications Emergency Contacts Recruitment Candidate Recruitment Management
Review HR Solutions Available, Budget & Time Oracle 3 rd Party DIY Time Entry Approvals Directory (*) + other non-hr apps available (*) Not on appstore at time of writing (**) Free for licensed Oracle customers. Internal Implementation Cost. ~6 weeks duration Software License External Implementation Cost. ~8-12 weeks duration Platform license Technical Dev cost 24+ weeks duration (**) Easier on 12.2.4 with Weblogic middle tier
5 minute demo
Getting Started
Review your Infrastructure Which Oracle EBS Version are you on? 11i Upgrade! 12.0 3 rd Parties ok; Oracle Upgrade 12.1 3 rd Parties ok; Oracle Patching needed 12.2 All ok Do you have any part of EBS external in a DMZ, for example, isupplier or irecruitment? Yes good to go No Review DMZ setup cost / time Do you have Single Sign On (SSO)? No good to go Yes Check vendor support for Mobile SSO
Connecting Devices: Demilitarized Zone (DMZ) for Oracle EBS
Connecting Devices: VPN / 2FA Warning: Using VPN/2FA kills user adoption!
Things Security Teams ask #1 Left phone in pub -style concerns Is data stored locally on device? Security teams hate local caching Check with vendor Offline capability indicates local storage Does the app timeout after non-use? Check capability with vendor How does password reset work? Usually standard Oracle consider removing ability to reset password from phone app; desktop only or helpdesk What controls can we have in place if the phone is compromised? Mobile Device Management Mobile Application Management
Introduction to MAMs and MDMs Over the air updates Remote configuration Remote Lock and Wipe Security Backup / Restore Software installation Device tracking Network support MDM App Delivery App Security App Updating User Authentication User Authorization Version Checking Push Services Reporting and tracking MAM
Common MAMs and MDMs Note: Not all apps are compatible with all MAMs. Check with vendor over compatibility. Around 33% of our customers use a MDM or MAM
Things Security Teams ask #2 How are we protected from malicious users?
Penetration Testing https://oracle.nationaltrust.com:8000/oa_html/ getpersonsalary&ppersonid=1234 Pen testing checks that malicious users can t read or change data using a simulated HTTP request Pen Testing is usually a simulated set of HTTP calls. Use SOAPUI (http://www.soapui.org/). Free open source tool to use for testing. Check Vendor s Web Services respect Oracle security. Don t ask the Vendor to perform Penetration testing! Sample vendors can also do this (for a fee!) https://www.nettitude.co.uk/contact-us/ https://www.hedgehogsecurity.co.uk/contact http://www.jumpsec.com/contact/ Only 25% of our customers bother!
Deployment and Rollout
Deploying Options #1 Use Public Apps Users download direct from public AppStore. No additional cost to project.
Deployment Options #2 - Branded apps Check with vendor if this is an option. Not all vendors will allow rebranding their apps like this.
Option 3 MAMs and MDMs Rebrand and circulate to internal Enterprise AppStore using an MDM or MAM. Check with vendor this is supported.
Miscellaneous Considerations Consider mobile access after termination Review your off-boarding processes (ex-emps now have access outside the office) Consider if some processes should be actively prohibited on mobile Return to work questionnaires Sickness Consider the service desk and support offered Support the app not the device! Provide a clear list of devices the vendor supports Don t assume vendor supports the latest device. Factors that break apps include: Higher resolution Front facing cameras Different form factors (iphone 6+) Testing can be a challenge if you don t have a test DMZ Discuss with network team connecting a test device to your internal network and do it early!
Questions? Ivan.harding@applaudsolutions.com 24 24