Citi Managed Identity Services Case Studies on Identity Assurance



Similar documents
Briefly describe the #1 problem you have encountered with implementing Multi-Factor Authentication.

Meeting the FDA s Requirements for Electronic Records and Electronic Signatures (21 CFR Part 11)

POLICY ISSUES IN E-COMMERCE APPLICATIONS: ELECTRONIC RECORD AND SIGNATURE COMPLIANCE FDA 21 CFR 11 ALPHATRUST PRONTO ENTERPRISE PLATFORM

How much do you pay for your PKI solution?

Class 3 Registration Authority Charter

Clinical Data Management BPaaS Approach HCL Technologies

Concept of Electronic Approvals

white paper 5 Steps to Secure Internet SSO Overview

Finance Effectiveness Efficiency

Certificate Policies and Certification Practice Statements

Demystifying Digital Signature Usage for Global Business

White paper. Implications of digital certificates on trusted e-business.

Oracle WebCenter Content

Revenue Recognition Engine

Intelligent Security Design, Development and Acquisition

SolidWorks Enterprise PDM and FDA 21CFR Part 11

Department of Veterans Affairs VA DIRECTIVE 6510 VA IDENTITY AND ACCESS MANAGEMENT

Ericsson Group Certificate Value Statement

SUNGARD B2B PAYMENTS AND BANK CONNECTIVITY STUDY INNOVATIONS TO OVERCOME COMPLEXITY-DRIVEN FRAUD EXPOSURE AND COST INCREASES

Identity Management & Digital Signatures in the BioPharmaceutical Industry John Hendrix; Program Director CTST 2009

Adobe PDF for electronic records

Arkansas Department of Information Systems Arkansas Department of Finance and Administration

Clinical Platform Compliance in the Cloud

The Paperless QMS March 2012

Identity & access management solution IDM365 for the Pharma & Life Science

Eskom Registration Authority Charter

The PNC Financial Services Group, Inc. Business Continuity Program

Business Issues in the implementation of Digital signatures

5 FAM 140 ACCEPTABILITY AND USE OF ELECTRONIC SIGNATURES

A unique biometrics based identifier, such as a fingerprint, voice print, or a retinal scan; or

How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration Procedures associated with Board Policy 5.22

Role Based Identity and Access Management Basic Infrastructure for New Citizen Services and Lean Internal Administration

InfoCenter Suite and the FDA s 21 CFR part 11 Electronic Records; Electronic Signatures

Digital Signatures The Law and Best Practices for Compliance. January 2014

Management Excellence Framework: Record to Report

Provisioning and Deprovisioning 1 Provisioning/De-provisiong replacement 1

FILEHOLD DOCUMENT MANAGEMENT SYSTEM 21 CFR PART 11 COMPLIANCE WHITE PAPER

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

Why Use Electronic Transactions Instead of Paper? Electronic Signatures, Identity Credentialing, Digital Timestamps and Content Authentication

CA Federation Manager

Pharmaceutical, Biotech and Medical Device Manufacturers. Be Compliant and Audit Ready - Implement an LMS!

SRI LANKA AUDITING PRACTICE STATEMENT 1013 ELECTRONIC COMMERCE EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

Security in Fax: Minimizing Breaches and Compliance Risks

Glossary of Key Terms

Gatekeeper PKI Framework. Archived. February Gatekeeper Public Key Infrastructure Framework. Gatekeeper PKI Framework.

INTERNATIONAL AUDITING PRACTICE STATEMENT 1013 ELECTRONIC COMMERCE EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

How Accenture is taking SAP NetWeaver Identity Management to the next level. Kristian Lehment, SAP AG Matthew Pecorelli, Accenture

A Model for Training/Qualification Record Validation within the Talent Management System

Establishing A Multi-Factor Authentication Solution. Report to the Joint Legislative Oversight Committee on Information Technology

BPM Perspectives Positioning and Fitment drivers

The CFO s motivation...

SAP Solution Brief SAP ERP SAP Invoice Management by OpenText. Take Control with Invoice Management Software

The IdenTrust Rule Set: Providing Secure Identities While Protecting Privacy

Full Compliance Contents

Drug Pooling in Clinical Trial Supply Chain

Signicat white paper. Signicat Solutions. This document introduces the Signicat solutions for digital identities and electronic signatures

PRACTICE NOTE 1013 ELECTRONIC COMMERCE - EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

Our Business Knowledge, Your Winning Edge. Consulting & Thought Partnership

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

SUPERVISION GUIDELINE NO. 9 ISSUED UNDER THE AUTHORITY OF THE FINANCIAL INSTITUTIONS ACT 1995 (NO. 1 OF 1995) RISK MANAGEMENT

Can We Reconstruct How Identity is Managed on the Internet?

The Impact of 21 CFR Part 11 on Product Development

Enterprise Information Management for the Food and Beverage Industry

Streamlining the drug development lifecycle with Adobe LiveCycle enterprise solutions

FileNet and SharePoint Better Together. Tom Moen Channel Development Manager

SMART PAYMENTS - BETTER DECISIONS BANK ACCOUNT MANAGEMENT E BANK ACCOUNT MANAGEMENT BEST PRACTICES IN BANK ACCOUNT MANAGEMENT.

Identity and Access Management

<Insert Picture Here> Oracle Database Vault

White paper. Four Best Practices for Secure Web Access

Compliance in the Corporate World

Enterprise Identity Management Reference Architecture

Centralized Secure Vault with Serena Dimensions CM

#KPMG Ignite. Join the conversation

Cloud Computing Security Considerations

CoSign Digital Signatures and Alfresco at ERT. VP, EMEA Sales CoSign by ARX

How Global Data Management (GDM) within J&J Pharma is SAVE'ing its Data. Craig Pusczko & Chris Henderson

Location for Trials- Global Considerations A Pharma Perspective. Carlo Maccarrone Assoc. Director, Clinical Research GSK Australia 7 May 2014

An Oracle White Paper November Financial Crime and Compliance Management: Convergence of Compliance Risk and Financial Crime

Gain a New Level of Trust with Extended Validation SSL Certificates

Best Practices in Contract Migration

Transcription:

Citi Managed Identity Services Case Studies on Identity Assurance Frank Villavicencio May 28, 2008

Identity as a Business Increasing number of high-value transactions migrating to electronic Need to confidently know who is transacting Complex regulatory landscape demands tighter controls and visibility Focus on process optimization, efficiency, cost and environmental footprint reduction Blurry organizational and geographical boundaries Hard to distinguish internal vs. external, local vs. global Majority processes involving multitude of parties (B2B, B2C, B2G, G2C, etc.) Digital Signatures Reputation Authentication Digital Identity Non- Repudiation Authorization Proof of Source Data Integrity

Why Now? Regulatory landscape has propitiated the right conditions Maturity and cost of technology Acceptance and critical mass around assurance standards

Business Opportunity Need for trusted providers to help organizations mitigate identity risks this goes well beyond technology Sense of urgency needs to be addressed today Maturity and viability of technology and standards Why Banks? Banks embody key elements needed to mitigate risks Establishing trust in transactions is a heritage to banks 1 2 3 POLICY LEGAL OPERATIONS Consistent KYC (PATRIOT Act) Globally regulated Bank-centric policies and procedures Contract-based structure Common liability model Complete legally binding nonrepudiation Bank-grade global performance standards Strong operational model Consistent audit processes 4 TECHNOLOGY Multi-factor authentication Anti-pharming (no man in the middle) Anti-phishing Public Key Infrastructure

Citi Managed Identity Services Traditional Digital Cash Management Secure Payment Authorization Citi CFS (file) or CitiDirect Digital Account Management Integrated Solutions ERP integrations (SAP, Oracle) Financial systems (WSS) Non-traditional Non-Banking Services Enabling various industry verticals services Examples: pharma, government Vertical Partner Solution Collaboration and document management IdM platform integration & automation Secure electronic correspondence Horizontal Services Common Foundation to Vertical Solutions Electronic Vault (evault) Secure and regulatory-compliant electronic records management Searchable and indexed audit repository Granular access control via entitlements Issuance Services Managed RA and CA services. Delegated administration models IdenTrust and SAFE digital credentials Turnkey solution with an online interface Also accessible via Web Services

Citi s Approach to Digital Identity Digital Identities are enablers real value comes from applications We believe that co-opetition is required Identities should be globally interoperable Hence should adhere to an accepted global standard Drive adoption through innovation and broad collaboration Financial supply-chain Other segments

Citi s Experience in the Pharma Sector Business Case: Drug R&D process Highly regulated and paper-intensive process Competitive landscape demands streamlining Drivers Cost savings, shorten timeframes FDA acceptance of digital signatures Other government entities also adopting SAFE Biopharma a common standard for the industry Citi s Perspective SAFE issuer since 2005 currently providing services to two global pharmaceutical Issuance services complies with EU advanced digital signatures guidelines

Electronic Bank Account Management Authorized signers on bank accounts paper-based process Changes should be as simple as a search-and-replace but needs the rigor of a contractual process

Digital Signatures in the Payments Process Downstream Payments JDE Digitally Sign and Approve Citi evault Finance Kit Digitally Sign and Approve Entitlement Check SWIFTNet Digitally Sign and Approve Digitally Sign and Approve SWIFTNet interface SAP Digitally Sign and Approve Entitlement Check Entitlement Check Citi Signer Management Downstream Payments

so why the need for a common standard?

QUESTIONS?