Key New Capabilities Complete, Open, Integrated. Oracle Identity Analytics 11g: Identity Intelligence and Governance



Similar documents
<Insert Picture Here> Oracle Identity And Access Management

Sun and Oracle: Joining Forces in Identity Management

Identity Governance Evolution

Oracle Role Manager. An Oracle White Paper Updated June 2009

Oracle Privileged Account Manager 11gR2. Karsten Müller-Corbach

Enterprise Identity Management Reference Architecture

Trust but Verify: Best Practices for Monitoring Privileged Users

How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions

Oracle Identity Management Securing The New Digital Experience

RSA Identity Management & Governance (Aveksa)

with Managing RSA the Lifecycle of Key Manager RSA Streamlining Security Operations Data Loss Prevention Solutions RSA Solution Brief

B2C, B2B and B2E:! Leveraging IAM to Achieve Real Business Value

IDENTITY MANAGEMENT AND WEB SECURITY. A Customer s Pragmatic Approach

Governance, Risk & Compliance for Public Sector

A Smarter Way to Manage Identity

RSA envision. Platform. Real-time Actionable Security Information, Streamlined Incident Handling, Effective Security Measures. RSA Solution Brief

Oracle Identity Manager (OIM) as Enterprise Security Platform - A Real World Implementation Approach for Success

Attestation of Identity Information. An Oracle White Paper May 2006

Management Packs for Database

Vermont Enterprise Architecture Framework (VEAF) Identity & Access Management (IAM) Abridged Strategy Level 0

Identity and Access Management Integration with PowerBroker. Providing Complete Visibility and Auditing of Identities

An Oracle White Paper January Access Certification: Addressing & Building on a Critical Security Control

Identity Management: Securing Information in the HIPAA Environment

Business and Process Requirements Business Requirements mapped to downstream Process Requirements. IAM UC Davis

Monitoring, Managing and Supporting Enterprise Clouds with Oracle Enterprise Manager 12c Name, Title Oracle

Oracle Fusion Middleware 11g Release 1 IDM Suite

Introductions. KPMG Presenters: Jay Schulman - Managing Director, Advisory - KPMG National Leader Identity and Access Management

IBM InfoSphere Discovery: The Power of Smarter Data Discovery

Security management White paper. Develop effective user management to demonstrate compliance efforts and achieve business value.

Automated User Provisioning

Pentaho Enterprise and Community Editions Feature Comparison

Select the right solution for identity and access governance

Quest One Identity Solution. Simplifying Identity and Access Management

Delivering value to the business with IAM

<Insert Picture Here> Move to Oracle Database with Oracle SQL Developer Migrations

Identity Management Overview. Bill Nelson Vice President of Professional Services

RSA enables rapid transformation of Identity and Access Governance processes

It s 2014 Do you Know where Your digital Identity is? Rapid Compliance with Governance Driven IAM. Toby Emden Vice President Strategy and Practices

ORACLE HYPERION DATA RELATIONSHIP MANAGEMENT

Corralling Data for Business Insights. The difference data relationship management can make. Part of the Rolta Managed Services Series

The Unique Alternative to the Big Four. Identity and Access Management

How To Ensure Financial Compliance

ADAPTABLE IDENTITY GOVERNANCE AND MANAGEMENT

Metrics that Matter Security Risk Analytics

<Insert Picture Here> Application Testing Suite Overview

RSA Via Lifecycle and Governance 101. Getting Started with a Solid Foundation

Data Security: Strategy and Tactics for Success

Complete Database Security. Thomas Kyte

How To Secure A Database From A Leaky, Unsecured, And Unpatched Server

An Oracle White Paper Dec Identity and Access Management: Comparing Oracle and NetIQ/Novell

SOLUTION BRIEF CA ERwin Modeling. How can I understand, manage and govern complex data assets and improve business agility?

Security management solutions White paper. IBM Tivoli and Consul: Facilitating security audit and compliance for heterogeneous environments.

ORACLE IT SERVICE MANAGEMENT SUITE

Oracle E-Business Suite Single Sign On Using Oracle Access Manager

White Paper: The Seven Elements of an Effective Compliance and Ethics Program

Developing an Identity Management Strategy

Service Orchestration

ORACLE ENTERPRISE MANAGER 10 g CONFIGURATION MANAGEMENT PACK FOR ORACLE DATABASE

ARIS 9ARIS 9.6 map and Future Directions Die nächste Generation des Geschäftsprozessmanagements

Role Based Access Control: How-to Tips and Lessons Learned from IT Peers

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Minimize Access Risk and Prevent Fraud With SAP Access Control

Enabling ITIL Best Practices Through Oracle Enterprise Manager, Session # Ana Mccollum Enterprise Management, Product Management

1 Building an Identity Management Business Case. 2 Agenda. 3 Business Challenges

IDENTITY AND ACCESS GOVERNANCE. Buyer s Guide

Consolidate by Migrating Your Databases to Oracle Database 11g. Fred Louis Enterprise Architect

TECHNOLOGY BRIEF: INTEGRATED IDENTITY AND ACCESS MANAGEMENT (IAM) An Integrated Architecture for Identity and Access Management

Axway API Portal. Putting APIs first for your developer ecosystem

10 Things IT Should be Doing (But Isn t)

The CMDB: The Brain Behind IT Business Value

CLOUDFORMS Open Hybrid Cloud

Oracle Reference Architecture and Oracle Cloud

Oracle Identity Governance - Complete Identity Lifecycle Management

Enterprise Business Service Management

<Insert Picture Here> Oracle SQL Developer 3.0: Overview and New Features

The Impact of PaaS on Business Transformation

Best Practices in Identity and Access Management (I&AM) for Regulatory Compliance. RSA Security and Accenture February 26, :00 AM

SailPoint IdentityIQ Managing the Business of Identity

How to best protect Active Directory in your organization. Alistair Holmes. Senior Systems Consultant

RSA ARCHER OPERATIONAL RISK MANAGEMENT

IBM Unstructured Data Identification and Management

BROCHURE ECOSYS EPC. Full Lifecycle Project Cost Controls

Managing Application Performance with JBoss Operations Network and OC Systems RTI

What s New Guide: Version 5.6

Oracle BI Applications. Can we make it worth the Purchase?

OracleAS Identity Management Solving Real World Problems

Oracle Audit Vault and Database Firewall. Morana Kobal Butković Principal Sales Consultant Oracle Hrvatska

CMTRAC. Application Overview APPLICATION DATASHEET

CA point of view: Content-Aware Identity & Access Management

APPLICATION MANAGEMENT SUITE FOR SIEBEL APPLICATIONS

SailPoint IdentityIQ Managing the Business of Identity

Kelvin Wee CISA, CISM, CISSP Principal Consultant (DLP Specialist) Asia Pacific and Japan

ORACLE FUSION MIDDLEWARE PROFILE

OpenMake Dynamic DevOps Suite 7.5 Road Map. Feature review for Mojo, Meister, CloudBuilder and Deploy+

Transcription:

<Insert Picture Here> Key New Capabilities Complete, Open, Integrated Oracle Analytics 11g: Intelligence and Governance Paola Marino Principal Sales Consultant, Management

Agenda Drivers Oracle Analytics overview and demo: Attestation Process Audit Policy Role Governance Compliance Dashboard Oracle Differentiators Phased approach Customers profiles

Business Requirements for IT Security Managing Security & Risk Increasing Business Value Sustaining Compliance

Oracle Management Comprehensive and Best-of-Breed Administration Manager Access Management * Access Manager Adaptive Access Manager Enterprise Single Sign-On Entitlements Server Federation Information Rights Management Web Services Manager & Access Governance Analytics Oracle Platform Security Services Directory Services Directory Server EE Internet Directory Virtual Directory Operational Manageability Management Pack For Management *Access Management includes Oracle OpenSSO STS and Oracle OpenSSO Fedlet

What Are We Hearing? IT Ops & Security Business Managers Compliance Manage access control across the enterprise Assess and control security risk Understand and attest to user access IT Risk and Business Productivity goals don t align Without automation, compliance is complex, error-prone, inconsistent Need to enforce and demonstrate compliance rapidly Control IT, Security, Compliance Costs

Achieving Compliance A common theme behind compliance involves identification and management of user access rights What resource(s) does a user have an account on? Does the user require an account on that system? What are the user's capabilities on that resource? Who authorized or created the user's account? Does the user's presence violate any business or security policies? How do companies determine this information today?

Oracle Analytics 11g Data Sources Oracle Manager Oracle Access Manager Compliance Command Console Access Certification IT Audit Policy Monitoring Role Governance Compliance Command Console Actionable Dashboards, Business Reports & Comprehensive Analytics Accelerated and Sustainable Compliance Automation Access Certification, IT Audit Policy Monitoring, Closed-loop Remediation Intelligent Role Governance Change Management, Attestation, Consolidation & Audit, Role Mining Rich Optimized for Analysis, Mining, Correlation, Reporting on, Access and Policy Data

Central Repository Users, Roles, Orgs, Entitlements Business glossaries, Classifications Data ownership, Entitlement hierarchies Applications Entitlements, Account types/status Policies Attestation Approvals Optimized for complex analyses & simulations Historical & audit snapshots Support for direct imports from applications, OOB integration for Manager

Data Architecture Optimized for Complex Analyses & Simulations Historical & Audit Snapshots Business Organization Hierarchies Entitlement Hierarchies Business & IT Roles Data Elements Users, Roles, Entitlements, Applications & Policy Violations Business Friendly Entitlement Glossaries Risk Based Data Classification Privileged Entitlement Monitoring Data Ownership Data Population Out of Box ETL from Oracle Manager & Oracle Waveset Support for Direct Imports from Applications Consistent Schema for all Import Types

Demo: Data Browsing (Organizations and Users Data) Hierarchical Business Structures Accounts with nth level attributes

Access Certification Certification Data User Attributes Role Memberships Role Based Entitlement Grants Exception Entitlement Grants Role Definition Role Entitlement Mapping Scheduling Periodic Scheduling Event Based Attestation for On-Boarding, Transfers & Termination Reminders & Escalations Spreadsheet Exports 360 Degree View Business Glossary Audit Exceptions Historical Data Approval Data Attestation Dashboards for Compliance Officers Closed Loop Remediation with OIM Integration

Access Certification Flow 1 Set Up Periodic Review 2 Reviewer Is Notified Goes to Self Service 3 Automated Action is taken based on Periodic Review 4 Report Built And Results Stored in DB Reviewer Selections What Is Reviewed? Certify Email Result to User Reject Automatically Terminate User Who Reviews It? Decline Notify the Process Owner Archive Delegate Notify Delegated Reviewer Attested Data Attestation Actions Start When? How Often? Comments Delegation Paths

Demo: Access Certification (Employment verification, Roles and Entitlements Attestation, Certify / Revoke) 360 Degree View Of User Access Certify/Revoke Options

IT Audit Policy Monitoring Violation Detection and Alert Event Analysis Audit Trail Assign Remediation IT Audit Policies Across Entitlements & Roles Within Application or Cross- Applications Preventative & Detective Remediation for SoD conflicts Role and Audit Exceptions

Demo: Audit Policy Definition Complex Audit Rule Conditions Enterprise wide Rule Objects

Demo: Audit Policy Violations Comprehensive Audit Violation Information Policy Violation Remedation Actions

IT Audit Policy Monitoring Closed-Loop Remediation Oracle Analytics Oracle Manager Attestation Remediation Configuration Roles, Accounts & Resource Entitlements Exported to OIM for De-Provisioning Provisioning/ De-Provisioning Workflow Revocation Tracking (closing the loop) Account & Resource Entitlement Data Imported to OIA Revocation of Resources & Roles (automated and/or manual) Complete De-Provisioning Audit Trail Comprehensive Audit Trail

Role Lifecycle Management Role Definition Role Modeling Role Mining Top-Down Approach Bottom-Up Approach Role Governance Role Audit, Analytics Change Mgmt Role Audit Analytics Role Change Approvals Role Versioning & Offline Copies Rollbacks Role Change Impact Analysis Role Entitlement Mapping History Role Membership History Approvals History Role Ownership History Role Definition Attestation Role Membership Attestation Role Consolidation Role Mining

Role Engineering Intelligent Role Discovery Engine Comprehensive Role Discovery using Hybrid Approach: Bottom Up (User Entitlements) Top Down (User HR Attributes) Flexible User Population Selection Review Mining Results in a centralized Dashboard with mining statistics, intelligent Analytics and graphical Representations Role Entitlement Discovery to mine new applications based on existing roles Role Mining Mining Data Resources Identities Entitlements Existing Roles Discover Patterns Suggested Roles

Demo: Role Mining, Versioning, History Role Versioning Complete Role History & Audit Trail

Compliance Command Console Presentation of Data in Business-Friendly Format Actionable Dashboards Reliable risk analysis Compliance Metrics Monitoring Reports like Top N-lists Comprehensive crossreferenced presentable data Enable complete identity Governance Advanced analytics Historical Trend Analysis Remediation Tracking 50+ out of box reports

Oracle Differentiators Product Leadership Scalable Architecture Part of industry-leading IAM Solution Set Executive Commitment, Strong Vision, Tremendous R&D and Global Support

Phased approach to Oracle Analytics Consolidate & Correlate Entitlements Automate -based Controls Define Enterprise Roles Assign Access via Roles Support Business Decisions Access Certification & Audit Policy Role Mgmt & Governance Integration with Provisioning Reports, Dashboards & Analytics Phase 1 Phase 2 Phase 3 Phase 4 Phase 5

Oracle Analytics Customers

Deployment Profiles Citi 200k Users, 2M Entitlements Capital One 55K attestations AMEX 250K Users, 24M Entitlements, 5M Accounts, 6.5M Glossary Definitions United Airlines 100 K Users Thrivent Financial Integrated with OIM for application management DirectTV M+ Entitlements Blue Cross Blue Shield of Louisiana SoD across AD & Mainframe

Oracle IdM Customer Advisory Board (July 13-15, 2010) Confidential