 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security Philosphy</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/security-philosphy/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/security-philosphy/</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 23:07:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: vnvrrw2c</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/security-philosphy/#comment-49871</link>
		<dc:creator>vnvrrw2c</dc:creator>
		<pubDate>Mon, 24 May 2004 13:02:37 +0000</pubDate>
		<guid isPermaLink="false">#comment-49871</guid>
		<description><![CDATA[It would also depend upon what model of security is used in the organization. The implementation of security around user and role based is different than the HR org based, which is generally position and personnel number driven. If your organization does not use HR module, the choice would be limited to user and role based security.
One critical factor to consider due to impending SOA requirements is the Segregation of duties, which requires much bigger framework to identify the users and user group assignments as well as rule building to avoid conflicting access assignment to users. The toughest part here is that SAP does not have a robust functionality around SOD. There are few good softwares in the market, which can help to manage roles, document them and control SOD conflicts / access to critical transactions etc.
I can provide more information if you need it.]]></description>
		<content:encoded><![CDATA[<p>It would also depend upon what model of security is used in the organization. The implementation of security around user and role based is different than the HR org based, which is generally position and personnel number driven. If your organization does not use HR module, the choice would be limited to user and role based security.<br />
One critical factor to consider due to impending SOA requirements is the Segregation of duties, which requires much bigger framework to identify the users and user group assignments as well as rule building to avoid conflicting access assignment to users. The toughest part here is that SAP does not have a robust functionality around SOD. There are few good softwares in the market, which can help to manage roles, document them and control SOD conflicts / access to critical transactions etc.<br />
I can provide more information if you need it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bigbob</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/security-philosphy/#comment-49872</link>
		<dc:creator>bigbob</dc:creator>
		<pubDate>Fri, 14 May 2004 11:37:14 +0000</pubDate>
		<guid isPermaLink="false">#comment-49872</guid>
		<description><![CDATA[Our VP of IT has laid out and implemented security policies. They are user based, so whether a user is in windows explorer, ms outlook or our document portal, the user is only allowed to view demeened items by their group, then user definitions. Each user is assigned to the appropriate group(s) and each group has been given their viewing rights. It does take time and meetings to create these groups and definitions, but it saves in the long run. Also, be sure to use the proper software to help you do this. Our document portal is currently on win2000 servers, but we are deploying a new version August 1st on .net/2003. This is what prompted us to do the definitions now, so we could easily define and migrate in August. We are also employing RSA&#039;s federate identity for customer and vendor relationships.]]></description>
		<content:encoded><![CDATA[<p>Our VP of IT has laid out and implemented security policies. They are user based, so whether a user is in windows explorer, ms outlook or our document portal, the user is only allowed to view demeened items by their group, then user definitions. Each user is assigned to the appropriate group(s) and each group has been given their viewing rights. It does take time and meetings to create these groups and definitions, but it saves in the long run. Also, be sure to use the proper software to help you do this. Our document portal is currently on win2000 servers, but we are deploying a new version August 1st on .net/2003. This is what prompted us to do the definitions now, so we could easily define and migrate in August. We are also employing RSA&#8217;s federate identity for customer and vendor relationships.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.034 seconds using memcached
Object Caching 281/287 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-24 23:40:17 -->