SlideShare a Scribd company logo
1 of 48
Download to read offline
Automate Robust User Access
and Security Controls for
PeopleSoft
David Maberry
Chief Risk Officer
American Fidelity Assurance Company
Madeline Osit
Chief Operating Officer
Beacon Application Services Corporation
Stephanie Golly
Sr. Product Manager, Oracle
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal2
Agenda
 Introduction to AFA and David Maberry
– Glimpse into the unfolding events leading up to PeopleSoft and GRC Advanced Controls implementation
 Introduction to Beacon Application Services
– Glimpse into implementation approach
 Introduction to Advanced Controls and a demonstration
 Lessons learned
 Q&A
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
3
About American Fidelity Assurance (AFA)
American Fidelity provides supplemental health insurance
benefits and financial services to education employees, auto
dealerships, health care providers and municipal workers across
the United States. American Fidelity was also named one of
FORTUNE magazine’s “100 Best Companies to Work For” in
America for nine years. American Fidelity serves more than 1
million Customers in 49 states and in 23 countries worldwide.
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
4
Your Speaker from AFA
David Maberry, Chief Risk Officer
• Responsible for developing and maintaining a comprehensive process for identifying,
assessing, mitigating, monitoring, and reporting key operational, financial, strategic,
technology and regulatory related risks that could potentially impact the organization’s
operations.
• Prior to coming to American Fidelity, worked for 10 years as a Principal & Director in
Deloitte and Touche’s Audit and Enterprise Risk Services practice in Los Angeles.
• Presented at numerous events hosted by the Institute of Internal Auditors (IIA) and the
Information Systems Audit and Control Association (ISACA).
• Frequent guest speaker at Texas A&M University, the University of Southern California and
California State - Los Angeles on topics including enterprise risk management, internal
control rationalization, and information technology risk.
• Graduate of Baylor University and the University of Wisconsin in Madison.
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
5
Timeline for selection process
March 2011
Investigation and Demo
August 2011
Demonstration
Contract July 2012
July 2011
Implementation Scoping
June
Justification
Due
Diligence
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
6
AFA pre-Oracle/PeopleSoft ERP
GL/AP – multiple systems, both home grown and via
acquisition
Assets – FAS and CLAS
Cash Management - manual
AR/Billing – manually for internal charges
Purchasing – manual, excel/access based system
Hyperion for budget and planning
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
7
AFA pre-Oracle/PeopleSoft ERP
Risks & Vulnerabilities
Outdated systems – some without support, many unrecognizable
Lack of visibility and transparency to financial data
No analytics – no drilldown to detail – no info on separate accounts
Hard coded integration with insurance admin systems, no flexibility
Lack of controls – worries about audit
Costs out of line with benefits
Quality compromises
Internal customer satisfaction low
Consolidations, Allocations (other) outside ledger – lack of transparency and manual intervention
Usability issues
Finance viewed as reporters of data not information
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Key AFA Business Issues Addressed
Antiquated/non-
integrated Financial
Systems required
significant manual
intervention
Complex and Manually
Intensive Reporting
processes
Manual governance
processes
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Reasons for Selecting PeopleSoft and
Advanced Controls
Benefits
Enhanced user experience and reduction in manual tasks
Increased automation – straight through Processing
Higher efficiency, accuracy and timeliness of
approvals and tighter controls
Shift from manual to automated controls
Single source of the truth for statutory, regulatory, tax, GAAP
and management reporting
Eliminate disparate systems offering partial solutions that are
difficult to maintain and reconcile
Transition away from legacy systems to support future growth through
enabling technology
Reduction in audit costs and increased accountability to management
Automation
Efficiency
Cost
Reduction
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Solution
New Financial Platform
• PeopleSoft Financial
• PeopleSoft Cash Management
• Supply Chain Procurement Applications
New Financial Reporting Platform
• PeopleSoft Financials
• Oracle Business Intelligence Analytic Applications
New Governance Framework
• Oracle Advanced Controls for select PeopleSoft processes
• Implemented in the initial go-live
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Why Advanced Controls
Bringing high value product to
• Document, manage, remediate
• Enforce user access policies and procedures
• Control introduction of new systems to the organization
Strong audit capabilities to reduce external costs
Tight integration with PeopleSoft security
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Project Approach
Installation
•Installation of new Financial ERP Platform
•Installation of Delivered OBIAA solutions with roadmap for future capabilities
Implementation
•Implement Advanced Controls foundation, targeting high-value controls with roadmap
for future expansion
•Rapid implementation with low impact (time and budget) to overall implementation
Partner
•Select a partner who could achieve these objectives as a co-owner of the implementation
with expertise to pull it off.
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Project Implementation Approach
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
14
About Beacon Application Services
Beacon is an Oracle Platinum Partner exclusively focused on the delivery of
services and software for PeopleSoft customers. Since 1993, Beacon has
been providing implementation, upgrade, enhancement and integration
services for Human Capital Management, Financials, and Supply Chain. To
meet our PeopleSoft customers’ increasing regulatory requirements and
complex information needs, Beacon also offers services for Advanced
Controls for PeopleSoft and Oracle Business Intelligence. We also offer our
Oracle Validated BEAM suite of software to manage your PeopleSoft
environment.
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
15
Timeline for Project Activities
January 2012
Chartfield design Workshop
Requirements
Thru Jan 2013
Go Live
January
2014
July 2012 - Implementation
Construct
August 2013
Test
Creating a timeline that achieved the
objectives at a pace comfortable to AFA
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Project Approach for PeopleSoft
Simplify, Automate, Consolidate, Standardize
• Identify areas of pain with current business processes
• Conduct Business Process Review sessions to document manual, off-line or
redundant activities and high audit risk process areas
• Create a future “to be” state to remediate the above either through process
redesign in delivered PeopleSoft applications or through adoption of AC
• Implement Advanced Controls foundation, targeting high-value controls with
roadmap for future expansion rather than “biting off more than we could chew”
• Embrace audit requirements as a fundamental part of the implementation rather
than an afterthought
• Target a specific area of concern to serve as a model for approaching all other
target areas
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Advanced Controls Business Drivers and
Requirements
• Eliminate cumbersome and costly manual auditing of system
controls – Reduction in Time, increase in transparency
• Reduce External Audit Cost and Effort – Reduction in Cost
• Enforce Separation of Duties – Eliminate possibility of Fraud
• Minimize Risk of Financial Loss – Reduction in Cost
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Advanced Controls –
Implementing our focus area
Initial focus on Procure-to-Pay process where highest risk was
identified
• Separation of duties for adding and paying vendors - Advanced Controls
identifies violations of the controls (entitlements) and flags them allowing
for correction
• Paying unapproved invoices – implementing workflow processes
• Identifying potentially fraudulent payments – AC was to be used in
support of ensuring that multiple payments are not unknowingly
processed to bypass certain threshold levels established in the application
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Advanced Controls – Approach
Key to success was narrowing scope from all available and non-
material or appropriate to AFA
255
Delivered Controls
57
Procure to Pay
Identify
Pertinent
11
GOAL
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
20
Controls Implemented
No. Control Names Entitlement
1 Add Vendors & Create Vouchers 1. Add Vendors
2. Create Vouchers
2 Create Control Groups & Approve Control Groups 1. Create Control Group
2. Approve Control Groups
3 Create Payments & Create Vouchers 1. Create Vouchers
2. Create Payments
4 Create Self Service Invoice & Create Urgent
Payment
1. Create Self-Service Invoice
2. Create Urgent Payment
5 Create Suppliers & Create Vouchers 1. Create Vouchers
2. Create Suppliers
6 Create Voucher & Selective Payment Update 1. Create Vouchers
2. Selective Urgent Payment
7 Create Voucher & Vendor Maintenance 1. Create Vouchers
2. Vendor Maintenance
8 Create Voucher & Voucher Maintenance 1. Create Vouchers
2. Voucher Maintenance
9 Create Vouchers & Approve Vouchers 1. Create Vouchers
2. Approve Vouchers
10 Create Vouchers & Create Express Checks 1. Create Vouchers
2. Create Express Checks
11 Create Vouchers & Print Checks 1. Print Checks
2. Create Vouchers
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
21
Tactical Steps
Install and activate integration with Financials
Select Targeted
business process
(procure to pay)
Identify
delivered
entitlements –
Pare down list
Execute
delivered
controls against
configured
security
Produce
delivered reports
to identify
conflicts
Adjust Roles and
Rules as
identified
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Demonstration of how it’s done!
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal24
The following is intended to outline our general product
direction. It is intended for information purposes only,
and may not be incorporated into any contract.
It is not a commitment to deliver any material, code, or
functionality, and should not be relied upon in making
purchasing decisions. The development, release, and
timing of any features or functionality described for
Oracle’s products remains at the sole discretion of
Oracle.
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal25
Create Supplier Invoice Create PaymentSupplier
Create Supplier Create Payment
for same supplier
+ Create Supplier Create Payment
for supplier≠
Prevent user from creating and paying the same
supplier
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal26
Prevent user from creating and paying the same
supplier
 AACG : Find users who could create and pay fictitious suppliers
– Users with both “Create Supplier” and “Create Payment” privileges
– Remove privileges when possible
 TCG: Monitor users who have created and paid the same supplier
– For users who must have both privileges
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal27 Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal27
Advanced Controls Foundation
Custom or Legacy
Applications
Fusion Platform with Dashboards,
Alerts & Drilldowns
Sophisticated Controls Monitoring
and Enforcement Engine
Many Types of Controls against
Various Business Applications
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal28
• Move away from silo’d information
• Multiple ERPs monitored from a single application.
• Control totals and exposure areas in self-serve capacity.
Advanced Controls – Embedded Dashboards
Copyright © 2013 Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal29
Application Access Controls Governor (AACG)
 Document, assess and certify
Application Security/SOD policies
 Library of pre-built automated SOD
controls for EBS, PSFT
 Author new controls, extend to any
business application
Advanced SOD and Security Controls
Compensating
Policies
Preventive
Provisioning
Remediation
(Clean-up)
Access
Analysis
Define Access
Controls
Detection Prevention
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal30
AACG – Finding Conflicts
User: Janie Adams
Responsibility: Payables Super User (Process Operations)
Menu: AP_Navigate_GUI12
Submenu: AZN_AP_Invoices_Entry
Function: Payments
Privilege: Create Purchase Order
Role: Buyer
Permission List: Buyer Duty
SOD Conflict
PeopleSoft
EBS
Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal31
Role
Permission List
Menu
Component
Page Definition
Component
Page Definition
Access Hierarchy Example – PeopleSoft
Other important attributes:
Business Unit, Effective Date, Set ID, Ledger, Account Lock etc.
Access Points
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal32
Glossary of Terminology
Control ManagementAccessPoint
Any level node in
the access model
hierarchy for a
particular
application.
Entitlement
A logical
grouping of
Access points.
E.g. All pages
that allow a user
to create a
voucher grouped
as a single
Entitlement
“Create Voucher”
ModelControl
A rule that
defines toxic
combinations of
entitlements
and/or access
points.
Copyright © 2013 Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal33
 Review Model Definition
 Analyze Results
 Modify Entitlement
 Deploy Control
 Generate Incidents
 Secure, Route and Remediate
Incidents
Demonstration
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal34
Demonstration Summary
• Review Entitlements and Model Definition
• Modify to fit needs and generate focused results
• Compliment PeopleSoft embedded controls with Advanced Controls
Leverage
Delivered Content
• Limit who can see generated results
• Route generated results for Investigation, Review and Approval
• Determine and document remediation actions
Secure, Route and
Take Action
• Validate role structure during PeopleSoft Implementation
• Identify and update role structures during an upgrade
Implementation or
Upgrades
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
35
Lessons Learned
• While implementing new
systems, integrating a formal
risk-management approach
increases value of the effort
• Staying on point for a focus area
narrows work effort
• Smaller scope enables
confirmation with audit team
that this is a viable and valid
solution for all business
processes
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
36
Lessons Learned
• Once completed, it provides not
only proof of concept but a
foundation for future expansion
• As system is deployed and user
population changes or grows,
delivered reports and remediation
steps become part of normal
maintenance
• Create a roadmap for the future
based on feedback from internal
and external auditors as to high
risk areas
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
37
Lessons Learned - not just for new
implementations
• Security is one area likely to get out of control – time to fix it!
• Advanced Controls can resolve negative audit finding with your current
PeopleSoft implementation
• Advanced Control findings can help to justify the upgrade cost
Upgrades
• Security will be reviewed in light of new roles, integrating Advanced Controls
into this work effort minimizes overall cost
• Especially pertinent to expanding Payables to full Procure-to-Pay solution
• Update of SOX documentation will incorporate additional, tighter controls
New Modules
• Easily cost justified in reduction of audit costs
• Great target area for IT compliance as well as business requirements
• Quick win for maximum return
Standalone GRC
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
38
Questions
Beacon Application Services Corporation
info@beaconservices.com
Beacon Application Services Corporation Proprietary and Confidential
www.beaconservices.com
Oracle Financial Services
The Choice of Experience.
Madeline Osit
Beacon Application Services Corporation
mosit@beaconservices.com
508.663.4407
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal40
Oracle Advance Controls
OOW2013 Sessions &
Demo Pod Slides
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal41
Demo Workstation
Moscone West 1st Floor #W-013
Monday Tuesday Wednesday
Demo ID 3532
Workstation #: W--013
9:45 – 6:00 9:45 – 6:00 9:45 – 4:00
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal42
Demo Workstation
Moscone West 1st Floor #W-013
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal43
General Session: Empowering Modern Governance, Risk, and Compliance
 12:15PM Moscone West – 2006/2008
 GEN8812
Automate Robust User Access and Security Controls for PeopleSoft
 10:45AM Moscone West - 2009
 CON8820
Panel Discussion: Intelligent Controls for Key Business Processes & Upgrades in PeopleSoft
 3:15PM Moscone West - 3020
 CON8822
Deloitte: Leveraging Oracle GRC Technology to Reduce Revenue Loss, Cost Leakage & Fraud
 3:15PM Moscone West - 2000
 CON8822
Learn More About Oracle Advance Controls
Monday
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal44
Top 10 Advanced Controls for Procure-to-Pay to Improve the Bottom Line
 10:30AM Moscone West – 2003
 CON8814
Center for Medicare & Medicaid Services Automates Internal Controls with Oracle GRC
 3:45PM St Francis – Elizabethan C/D
 CON9346
Enforce Segregation of Duties with Identity Management and Oracle Advanced Controls
 5:15PM Moscone West – 3018
 CON8827
Learn More About Oracle Advance Controls
Tuesday
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal45
Optimizing Order-to-Cash with Oracle Advanced Controls for Oracle E-Business Suite
 10:15AM Moscone West – 3018
 CON8816
Reducing Risk for Oracle E-Business Suite Upgrades and Implementations
 1:15PM Moscone West – 3018
 CON8830
Panel Discussion: Intelligent Controls for Key Business Processes and Upgrades
 3:30PM Moscone West – 2002 / 2004
 CON8832
Learn More About Oracle Advance Controls
Wednesday
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal46
Advanced Access and User Security for Oracle E-Business Suite and Fusion Applications
 2:00PM Moscone West – 3018
 CON8824
Meet the Governance, Risk, and Compliance Experts
 12:30PM Moscone West 2001A
 MTE9412
Learn More About Oracle Advance Controls
Thursday
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal47
Specialized Advanced Controls Partners
 New Benefit for Advanced Controls owners
 Specialized Partners:
– Trained by Oracle:
 Designing and delivering OAC solutions
– Demonstrated ability to deliver reliable OAC
solutions
 Coming soon
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal48
@OracleAdvCntrls

More Related Content

What's hot

Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...
Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...
Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...Prolifics
 
Applying an IBM SOA Approach to Manual Processes Automation
Applying an IBM SOA Approach to Manual Processes AutomationApplying an IBM SOA Approach to Manual Processes Automation
Applying an IBM SOA Approach to Manual Processes AutomationProlifics
 
Project List of Ook Anthony Kim_
Project List of Ook Anthony Kim_Project List of Ook Anthony Kim_
Project List of Ook Anthony Kim_Anthony Kim
 
Alfa bank installed Micro Focus Performance Centre
Alfa bank installed Micro Focus Performance CentreAlfa bank installed Micro Focus Performance Centre
Alfa bank installed Micro Focus Performance CentreAnatoliy Arkhipov
 
OOW-CON3640-portal
OOW-CON3640-portalOOW-CON3640-portal
OOW-CON3640-portalBen Duan
 
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast Iron
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast IronIntegrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast Iron
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast IronProlifics
 
Future of Oracle Forms AUSOUG 2013
Future of Oracle Forms AUSOUG 2013Future of Oracle Forms AUSOUG 2013
Future of Oracle Forms AUSOUG 2013Chris Muir
 
ING webcast platform
ING webcast platformING webcast platform
ING webcast platformOracleIDM
 
App portal 2015: Universal Enterprise App Store
App portal 2015: Universal Enterprise App StoreApp portal 2015: Universal Enterprise App Store
App portal 2015: Universal Enterprise App StoreFlexera
 
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...Prolifics
 
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease Kellton Tech Solutions Ltd
 
2014 10 23 Twin Cities User Group Presentation
2014 10 23 Twin Cities User Group Presentation2014 10 23 Twin Cities User Group Presentation
2014 10 23 Twin Cities User Group PresentationRoger Snook
 
Oracle IDAM overview
Oracle IDAM overviewOracle IDAM overview
Oracle IDAM overviewEslam Hafez
 
Why Mobile will Change your Business - Parmelee
Why Mobile will Change your Business - ParmeleeWhy Mobile will Change your Business - Parmelee
Why Mobile will Change your Business - ParmeleeProlifics
 
Top 10 Reasons to Choose Oracle ERP Cloud Financials
Top 10 Reasons to Choose Oracle ERP Cloud FinancialsTop 10 Reasons to Choose Oracle ERP Cloud Financials
Top 10 Reasons to Choose Oracle ERP Cloud FinancialsLiz Kensicki
 
Soa cloud con8968_pdf_8968_0001
Soa cloud con8968_pdf_8968_0001Soa cloud con8968_pdf_8968_0001
Soa cloud con8968_pdf_8968_0001jucaab
 
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...Steven Davelaar
 
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...Prolifics
 
Applying DevOps for more reliable Public Sector Software Delivery
Applying DevOps for more reliable Public Sector Software DeliveryApplying DevOps for more reliable Public Sector Software Delivery
Applying DevOps for more reliable Public Sector Software DeliverySanjeev Sharma
 

What's hot (20)

Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...
Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...
Smarter Integration Using the IBM SOA Foundation Stack: Best Practices and Le...
 
Applying an IBM SOA Approach to Manual Processes Automation
Applying an IBM SOA Approach to Manual Processes AutomationApplying an IBM SOA Approach to Manual Processes Automation
Applying an IBM SOA Approach to Manual Processes Automation
 
Project List of Ook Anthony Kim_
Project List of Ook Anthony Kim_Project List of Ook Anthony Kim_
Project List of Ook Anthony Kim_
 
Alfa bank installed Micro Focus Performance Centre
Alfa bank installed Micro Focus Performance CentreAlfa bank installed Micro Focus Performance Centre
Alfa bank installed Micro Focus Performance Centre
 
OOW-CON3640-portal
OOW-CON3640-portalOOW-CON3640-portal
OOW-CON3640-portal
 
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast Iron
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast IronIntegrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast Iron
Integrating Salesforce.com and Oracle ERP Using IBM WebSphere Cast Iron
 
Future of Oracle Forms AUSOUG 2013
Future of Oracle Forms AUSOUG 2013Future of Oracle Forms AUSOUG 2013
Future of Oracle Forms AUSOUG 2013
 
ING webcast platform
ING webcast platformING webcast platform
ING webcast platform
 
App portal 2015: Universal Enterprise App Store
App portal 2015: Universal Enterprise App StoreApp portal 2015: Universal Enterprise App Store
App portal 2015: Universal Enterprise App Store
 
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...
Using the Power of IBM Tivoli Common Reporting to Make Smart Decisions: The U...
 
VRP Consulting
VRP ConsultingVRP Consulting
VRP Consulting
 
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease
Software AG’s webMethods Integration Cloud: Integrate Cloud Apps with ease
 
2014 10 23 Twin Cities User Group Presentation
2014 10 23 Twin Cities User Group Presentation2014 10 23 Twin Cities User Group Presentation
2014 10 23 Twin Cities User Group Presentation
 
Oracle IDAM overview
Oracle IDAM overviewOracle IDAM overview
Oracle IDAM overview
 
Why Mobile will Change your Business - Parmelee
Why Mobile will Change your Business - ParmeleeWhy Mobile will Change your Business - Parmelee
Why Mobile will Change your Business - Parmelee
 
Top 10 Reasons to Choose Oracle ERP Cloud Financials
Top 10 Reasons to Choose Oracle ERP Cloud FinancialsTop 10 Reasons to Choose Oracle ERP Cloud Financials
Top 10 Reasons to Choose Oracle ERP Cloud Financials
 
Soa cloud con8968_pdf_8968_0001
Soa cloud con8968_pdf_8968_0001Soa cloud con8968_pdf_8968_0001
Soa cloud con8968_pdf_8968_0001
 
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...
The Mobile Enterprise in Action: Managing Business Processes from Your Mobile...
 
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...
How Broadcast Music, Inc. Devised and Enabled Enterprise Architecture from Co...
 
Applying DevOps for more reliable Public Sector Software Delivery
Applying DevOps for more reliable Public Sector Software DeliveryApplying DevOps for more reliable Public Sector Software Delivery
Applying DevOps for more reliable Public Sector Software Delivery
 

Viewers also liked

PSI_aboveFold_parvez_2016_07.pptx
PSI_aboveFold_parvez_2016_07.pptxPSI_aboveFold_parvez_2016_07.pptx
PSI_aboveFold_parvez_2016_07.pptxpahammad
 
Getting Started with Containers
Getting Started with ContainersGetting Started with Containers
Getting Started with ContainersScott Lowe
 
Rkt Container Engine
Rkt Container EngineRkt Container Engine
Rkt Container EngineThuc Le Dong
 
Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation
 Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation
Deutsche Telekom CMD 2015 - Cost and Portfolio TransformationDeutsche Telekom
 
Go or No-Go: Operability and Contingency Planning at Etsy.com
Go or No-Go: Operability and Contingency Planning at Etsy.comGo or No-Go: Operability and Contingency Planning at Etsy.com
Go or No-Go: Operability and Contingency Planning at Etsy.comJohn Allspaw
 
2014 Future of Open Source Survey Results
2014 Future of Open Source Survey Results2014 Future of Open Source Survey Results
2014 Future of Open Source Survey ResultsBlack Duck by Synopsys
 
2013 11 mobile eating the world
2013 11 mobile eating the world2013 11 mobile eating the world
2013 11 mobile eating the worldBenedict Evans
 

Viewers also liked (10)

PSI_aboveFold_parvez_2016_07.pptx
PSI_aboveFold_parvez_2016_07.pptxPSI_aboveFold_parvez_2016_07.pptx
PSI_aboveFold_parvez_2016_07.pptx
 
Getting Started with Containers
Getting Started with ContainersGetting Started with Containers
Getting Started with Containers
 
Rkt Container Engine
Rkt Container EngineRkt Container Engine
Rkt Container Engine
 
RKT
RKTRKT
RKT
 
Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation
 Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation
Deutsche Telekom CMD 2015 - Cost and Portfolio Transformation
 
<dc:title>Metadata, identifiers and linking content</dc:title>
<dc:title>Metadata, identifiers and linking content</dc:title><dc:title>Metadata, identifiers and linking content</dc:title>
<dc:title>Metadata, identifiers and linking content</dc:title>
 
Go or No-Go: Operability and Contingency Planning at Etsy.com
Go or No-Go: Operability and Contingency Planning at Etsy.comGo or No-Go: Operability and Contingency Planning at Etsy.com
Go or No-Go: Operability and Contingency Planning at Etsy.com
 
2014 Future of Open Source Survey Results
2014 Future of Open Source Survey Results2014 Future of Open Source Survey Results
2014 Future of Open Source Survey Results
 
2013 11 mobile eating the world
2013 11 mobile eating the world2013 11 mobile eating the world
2013 11 mobile eating the world
 
Creative portfolio
Creative portfolioCreative portfolio
Creative portfolio
 

Similar to Chief Risk Officer, American Fidelity, strengthens secuirty with Advanced Controls

Innovation Showcase: Top Public Sector Apps Built on Salesforce App Cloud
Innovation Showcase: Top Public Sector Apps Built on Salesforce App CloudInnovation Showcase: Top Public Sector Apps Built on Salesforce App Cloud
Innovation Showcase: Top Public Sector Apps Built on Salesforce App CloudDreamforce
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsOracle
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Oracle
 
Sharing APIs at Scale for a Great Developer Experience
Sharing APIs at Scale for a Great Developer ExperienceSharing APIs at Scale for a Great Developer Experience
Sharing APIs at Scale for a Great Developer ExperiencePostman
 
Salesforce Mobile architecture introduction
Salesforce Mobile architecture introductionSalesforce Mobile architecture introduction
Salesforce Mobile architecture introductionDavid Scruggs
 
Salesforce Intro to the Internet of Things
Salesforce Intro to the Internet of ThingsSalesforce Intro to the Internet of Things
Salesforce Intro to the Internet of ThingsDavid Scruggs
 
Creating Business Agility and Connectivity using Open Technologies
Creating Business Agility and Connectivity using Open TechnologiesCreating Business Agility and Connectivity using Open Technologies
Creating Business Agility and Connectivity using Open TechnologiesAppnovation Technologies
 
Starting A Successful ISV Business with Salesforce (October 13, 2014)
Starting A Successful ISV Business with Salesforce (October 13, 2014)Starting A Successful ISV Business with Salesforce (October 13, 2014)
Starting A Successful ISV Business with Salesforce (October 13, 2014)Salesforce Partners
 
Location-aware Mobile Apps with Chatter & iBeacon
Location-aware Mobile Apps with Chatter & iBeaconLocation-aware Mobile Apps with Chatter & iBeacon
Location-aware Mobile Apps with Chatter & iBeaconjohngifford
 
Heroku + Salesforce = Partner Success
Heroku + Salesforce = Partner SuccessHeroku + Salesforce = Partner Success
Heroku + Salesforce = Partner SuccessAlexander Sutherland
 
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!Dreamforce
 
How Morgan Stanley is Using Apps to Transform the Workplace
How Morgan Stanley is Using Apps to Transform the WorkplaceHow Morgan Stanley is Using Apps to Transform the Workplace
How Morgan Stanley is Using Apps to Transform the WorkplaceDreamforce
 
Moving Your ERP to the Cloud
Moving Your ERP to the CloudMoving Your ERP to the Cloud
Moving Your ERP to the CloudKenandy
 
Communities & Dreamforce Key Takeaways
Communities & Dreamforce Key TakeawaysCommunities & Dreamforce Key Takeaways
Communities & Dreamforce Key TakeawaysMagnet 360
 
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsOracle
 
Forcelandia 2016 Wave App Development
Forcelandia 2016   Wave App DevelopmentForcelandia 2016   Wave App Development
Forcelandia 2016 Wave App DevelopmentSkip Sauls
 
Data Integrity to Data Intelligence
Data Integrity to Data IntelligenceData Integrity to Data Intelligence
Data Integrity to Data IntelligenceSalesforce.org
 
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...David Resnic
 
Modev presentation
Modev presentationModev presentation
Modev presentationRyan Upton
 

Similar to Chief Risk Officer, American Fidelity, strengthens secuirty with Advanced Controls (20)

Innovation Showcase: Top Public Sector Apps Built on Salesforce App Cloud
Innovation Showcase: Top Public Sector Apps Built on Salesforce App CloudInnovation Showcase: Top Public Sector Apps Built on Salesforce App Cloud
Innovation Showcase: Top Public Sector Apps Built on Salesforce App Cloud
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 
Sharing APIs at Scale for a Great Developer Experience
Sharing APIs at Scale for a Great Developer ExperienceSharing APIs at Scale for a Great Developer Experience
Sharing APIs at Scale for a Great Developer Experience
 
Salesforce Mobile architecture introduction
Salesforce Mobile architecture introductionSalesforce Mobile architecture introduction
Salesforce Mobile architecture introduction
 
Salesforce Intro to the Internet of Things
Salesforce Intro to the Internet of ThingsSalesforce Intro to the Internet of Things
Salesforce Intro to the Internet of Things
 
Creating Business Agility and Connectivity using Open Technologies
Creating Business Agility and Connectivity using Open TechnologiesCreating Business Agility and Connectivity using Open Technologies
Creating Business Agility and Connectivity using Open Technologies
 
Dev ops.enterprise.2014 (1)
Dev ops.enterprise.2014 (1)Dev ops.enterprise.2014 (1)
Dev ops.enterprise.2014 (1)
 
Starting A Successful ISV Business with Salesforce (October 13, 2014)
Starting A Successful ISV Business with Salesforce (October 13, 2014)Starting A Successful ISV Business with Salesforce (October 13, 2014)
Starting A Successful ISV Business with Salesforce (October 13, 2014)
 
Location-aware Mobile Apps with Chatter & iBeacon
Location-aware Mobile Apps with Chatter & iBeaconLocation-aware Mobile Apps with Chatter & iBeacon
Location-aware Mobile Apps with Chatter & iBeacon
 
Heroku + Salesforce = Partner Success
Heroku + Salesforce = Partner SuccessHeroku + Salesforce = Partner Success
Heroku + Salesforce = Partner Success
 
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!
Eli Lilly is All In on Salesforce App Cloud. How They Did It and You Can Too!
 
How Morgan Stanley is Using Apps to Transform the Workplace
How Morgan Stanley is Using Apps to Transform the WorkplaceHow Morgan Stanley is Using Apps to Transform the Workplace
How Morgan Stanley is Using Apps to Transform the Workplace
 
Moving Your ERP to the Cloud
Moving Your ERP to the CloudMoving Your ERP to the Cloud
Moving Your ERP to the Cloud
 
Communities & Dreamforce Key Takeaways
Communities & Dreamforce Key TakeawaysCommunities & Dreamforce Key Takeaways
Communities & Dreamforce Key Takeaways
 
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
 
Forcelandia 2016 Wave App Development
Forcelandia 2016   Wave App DevelopmentForcelandia 2016   Wave App Development
Forcelandia 2016 Wave App Development
 
Data Integrity to Data Intelligence
Data Integrity to Data IntelligenceData Integrity to Data Intelligence
Data Integrity to Data Intelligence
 
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...
Virtualization Adoption: The Secrets of a Successful Journey: A Case Study of...
 
Modev presentation
Modev presentationModev presentation
Modev presentation
 

More from Oracle

How your vendor master file is critical to governance, risk management and co...
How your vendor master file is critical to governance, risk management and co...How your vendor master file is critical to governance, risk management and co...
How your vendor master file is critical to governance, risk management and co...Oracle
 
Con8208 achieve a quicker and compliant financial close
Con8208 achieve a quicker and compliant financial closeCon8208 achieve a quicker and compliant financial close
Con8208 achieve a quicker and compliant financial closeOracle
 
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...Oracle
 
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...Oracle
 
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...Oracle
 
GRC Advanced Controls OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...
GRC Advanced Controls  OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...GRC Advanced Controls  OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...
GRC Advanced Controls OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...Oracle
 
Oracle OpenWorld 2014 GRC events and sessions
Oracle OpenWorld 2014 GRC events and sessionsOracle OpenWorld 2014 GRC events and sessions
Oracle OpenWorld 2014 GRC events and sessionsOracle
 
Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824Oracle
 
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
Optimizing order to-cash (e-business suite) with GRC Advanced ControlsOptimizing order to-cash (e-business suite) with GRC Advanced Controls
Optimizing order to-cash (e-business suite) with GRC Advanced ControlsOracle
 
Integrate Oracle Identity Management and Advanced Controls for maximum effici...
Integrate Oracle Identity Management and Advanced Controls for maximum effici...Integrate Oracle Identity Management and Advanced Controls for maximum effici...
Integrate Oracle Identity Management and Advanced Controls for maximum effici...Oracle
 
Top 10 P2P Advanced Controls to improve your bottom line!
Top 10 P2P Advanced Controls to improve your bottom line!Top 10 P2P Advanced Controls to improve your bottom line!
Top 10 P2P Advanced Controls to improve your bottom line!Oracle
 
CFO.Com and Oracle - Improving Bottom Line with Advanced Controls
CFO.Com and Oracle - Improving Bottom Line with Advanced ControlsCFO.Com and Oracle - Improving Bottom Line with Advanced Controls
CFO.Com and Oracle - Improving Bottom Line with Advanced ControlsOracle
 

More from Oracle (12)

How your vendor master file is critical to governance, risk management and co...
How your vendor master file is critical to governance, risk management and co...How your vendor master file is critical to governance, risk management and co...
How your vendor master file is critical to governance, risk management and co...
 
Con8208 achieve a quicker and compliant financial close
Con8208 achieve a quicker and compliant financial closeCon8208 achieve a quicker and compliant financial close
Con8208 achieve a quicker and compliant financial close
 
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
 
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
Symantec, Facebook and Navillus - a comprehensive approach to securing & moni...
 
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...
Comcast, Integra LifeSciences, LPL Financial, and Smucker's - Doing Your ERP ...
 
GRC Advanced Controls OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...
GRC Advanced Controls  OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...GRC Advanced Controls  OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...
GRC Advanced Controls OOW2014 Stop Financial Leakage - Cisco, Noble Energy, ...
 
Oracle OpenWorld 2014 GRC events and sessions
Oracle OpenWorld 2014 GRC events and sessionsOracle OpenWorld 2014 GRC events and sessions
Oracle OpenWorld 2014 GRC events and sessions
 
Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824
 
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
Optimizing order to-cash (e-business suite) with GRC Advanced ControlsOptimizing order to-cash (e-business suite) with GRC Advanced Controls
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
 
Integrate Oracle Identity Management and Advanced Controls for maximum effici...
Integrate Oracle Identity Management and Advanced Controls for maximum effici...Integrate Oracle Identity Management and Advanced Controls for maximum effici...
Integrate Oracle Identity Management and Advanced Controls for maximum effici...
 
Top 10 P2P Advanced Controls to improve your bottom line!
Top 10 P2P Advanced Controls to improve your bottom line!Top 10 P2P Advanced Controls to improve your bottom line!
Top 10 P2P Advanced Controls to improve your bottom line!
 
CFO.Com and Oracle - Improving Bottom Line with Advanced Controls
CFO.Com and Oracle - Improving Bottom Line with Advanced ControlsCFO.Com and Oracle - Improving Bottom Line with Advanced Controls
CFO.Com and Oracle - Improving Bottom Line with Advanced Controls
 

Recently uploaded

How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterMydbops
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesThousandEyes
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...panagenda
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...AliaaTarek5
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rick Flair
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
Sample pptx for embedding into website for demo
Sample pptx for embedding into website for demoSample pptx for embedding into website for demo
Sample pptx for embedding into website for demoHarshalMandlekar2
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 

Recently uploaded (20)

How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL Router
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
Sample pptx for embedding into website for demo
Sample pptx for embedding into website for demoSample pptx for embedding into website for demo
Sample pptx for embedding into website for demo
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 

Chief Risk Officer, American Fidelity, strengthens secuirty with Advanced Controls

  • 1. Automate Robust User Access and Security Controls for PeopleSoft David Maberry Chief Risk Officer American Fidelity Assurance Company Madeline Osit Chief Operating Officer Beacon Application Services Corporation Stephanie Golly Sr. Product Manager, Oracle
  • 2. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal2 Agenda  Introduction to AFA and David Maberry – Glimpse into the unfolding events leading up to PeopleSoft and GRC Advanced Controls implementation  Introduction to Beacon Application Services – Glimpse into implementation approach  Introduction to Advanced Controls and a demonstration  Lessons learned  Q&A
  • 3. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 3 About American Fidelity Assurance (AFA) American Fidelity provides supplemental health insurance benefits and financial services to education employees, auto dealerships, health care providers and municipal workers across the United States. American Fidelity was also named one of FORTUNE magazine’s “100 Best Companies to Work For” in America for nine years. American Fidelity serves more than 1 million Customers in 49 states and in 23 countries worldwide.
  • 4. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 4 Your Speaker from AFA David Maberry, Chief Risk Officer • Responsible for developing and maintaining a comprehensive process for identifying, assessing, mitigating, monitoring, and reporting key operational, financial, strategic, technology and regulatory related risks that could potentially impact the organization’s operations. • Prior to coming to American Fidelity, worked for 10 years as a Principal & Director in Deloitte and Touche’s Audit and Enterprise Risk Services practice in Los Angeles. • Presented at numerous events hosted by the Institute of Internal Auditors (IIA) and the Information Systems Audit and Control Association (ISACA). • Frequent guest speaker at Texas A&M University, the University of Southern California and California State - Los Angeles on topics including enterprise risk management, internal control rationalization, and information technology risk. • Graduate of Baylor University and the University of Wisconsin in Madison.
  • 5. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 5 Timeline for selection process March 2011 Investigation and Demo August 2011 Demonstration Contract July 2012 July 2011 Implementation Scoping June Justification Due Diligence
  • 6. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 6 AFA pre-Oracle/PeopleSoft ERP GL/AP – multiple systems, both home grown and via acquisition Assets – FAS and CLAS Cash Management - manual AR/Billing – manually for internal charges Purchasing – manual, excel/access based system Hyperion for budget and planning
  • 7. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 7 AFA pre-Oracle/PeopleSoft ERP Risks & Vulnerabilities Outdated systems – some without support, many unrecognizable Lack of visibility and transparency to financial data No analytics – no drilldown to detail – no info on separate accounts Hard coded integration with insurance admin systems, no flexibility Lack of controls – worries about audit Costs out of line with benefits Quality compromises Internal customer satisfaction low Consolidations, Allocations (other) outside ledger – lack of transparency and manual intervention Usability issues Finance viewed as reporters of data not information
  • 8. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Key AFA Business Issues Addressed Antiquated/non- integrated Financial Systems required significant manual intervention Complex and Manually Intensive Reporting processes Manual governance processes
  • 9. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Reasons for Selecting PeopleSoft and Advanced Controls Benefits Enhanced user experience and reduction in manual tasks Increased automation – straight through Processing Higher efficiency, accuracy and timeliness of approvals and tighter controls Shift from manual to automated controls Single source of the truth for statutory, regulatory, tax, GAAP and management reporting Eliminate disparate systems offering partial solutions that are difficult to maintain and reconcile Transition away from legacy systems to support future growth through enabling technology Reduction in audit costs and increased accountability to management Automation Efficiency Cost Reduction
  • 10. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Solution New Financial Platform • PeopleSoft Financial • PeopleSoft Cash Management • Supply Chain Procurement Applications New Financial Reporting Platform • PeopleSoft Financials • Oracle Business Intelligence Analytic Applications New Governance Framework • Oracle Advanced Controls for select PeopleSoft processes • Implemented in the initial go-live
  • 11. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Why Advanced Controls Bringing high value product to • Document, manage, remediate • Enforce user access policies and procedures • Control introduction of new systems to the organization Strong audit capabilities to reduce external costs Tight integration with PeopleSoft security
  • 12. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Project Approach Installation •Installation of new Financial ERP Platform •Installation of Delivered OBIAA solutions with roadmap for future capabilities Implementation •Implement Advanced Controls foundation, targeting high-value controls with roadmap for future expansion •Rapid implementation with low impact (time and budget) to overall implementation Partner •Select a partner who could achieve these objectives as a co-owner of the implementation with expertise to pull it off.
  • 13. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Project Implementation Approach
  • 14. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 14 About Beacon Application Services Beacon is an Oracle Platinum Partner exclusively focused on the delivery of services and software for PeopleSoft customers. Since 1993, Beacon has been providing implementation, upgrade, enhancement and integration services for Human Capital Management, Financials, and Supply Chain. To meet our PeopleSoft customers’ increasing regulatory requirements and complex information needs, Beacon also offers services for Advanced Controls for PeopleSoft and Oracle Business Intelligence. We also offer our Oracle Validated BEAM suite of software to manage your PeopleSoft environment.
  • 15. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 15 Timeline for Project Activities January 2012 Chartfield design Workshop Requirements Thru Jan 2013 Go Live January 2014 July 2012 - Implementation Construct August 2013 Test Creating a timeline that achieved the objectives at a pace comfortable to AFA
  • 16. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Project Approach for PeopleSoft Simplify, Automate, Consolidate, Standardize • Identify areas of pain with current business processes • Conduct Business Process Review sessions to document manual, off-line or redundant activities and high audit risk process areas • Create a future “to be” state to remediate the above either through process redesign in delivered PeopleSoft applications or through adoption of AC • Implement Advanced Controls foundation, targeting high-value controls with roadmap for future expansion rather than “biting off more than we could chew” • Embrace audit requirements as a fundamental part of the implementation rather than an afterthought • Target a specific area of concern to serve as a model for approaching all other target areas
  • 17. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Advanced Controls Business Drivers and Requirements • Eliminate cumbersome and costly manual auditing of system controls – Reduction in Time, increase in transparency • Reduce External Audit Cost and Effort – Reduction in Cost • Enforce Separation of Duties – Eliminate possibility of Fraud • Minimize Risk of Financial Loss – Reduction in Cost
  • 18. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Advanced Controls – Implementing our focus area Initial focus on Procure-to-Pay process where highest risk was identified • Separation of duties for adding and paying vendors - Advanced Controls identifies violations of the controls (entitlements) and flags them allowing for correction • Paying unapproved invoices – implementing workflow processes • Identifying potentially fraudulent payments – AC was to be used in support of ensuring that multiple payments are not unknowingly processed to bypass certain threshold levels established in the application
  • 19. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Advanced Controls – Approach Key to success was narrowing scope from all available and non- material or appropriate to AFA 255 Delivered Controls 57 Procure to Pay Identify Pertinent 11 GOAL
  • 20. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 20 Controls Implemented No. Control Names Entitlement 1 Add Vendors & Create Vouchers 1. Add Vendors 2. Create Vouchers 2 Create Control Groups & Approve Control Groups 1. Create Control Group 2. Approve Control Groups 3 Create Payments & Create Vouchers 1. Create Vouchers 2. Create Payments 4 Create Self Service Invoice & Create Urgent Payment 1. Create Self-Service Invoice 2. Create Urgent Payment 5 Create Suppliers & Create Vouchers 1. Create Vouchers 2. Create Suppliers 6 Create Voucher & Selective Payment Update 1. Create Vouchers 2. Selective Urgent Payment 7 Create Voucher & Vendor Maintenance 1. Create Vouchers 2. Vendor Maintenance 8 Create Voucher & Voucher Maintenance 1. Create Vouchers 2. Voucher Maintenance 9 Create Vouchers & Approve Vouchers 1. Create Vouchers 2. Approve Vouchers 10 Create Vouchers & Create Express Checks 1. Create Vouchers 2. Create Express Checks 11 Create Vouchers & Print Checks 1. Print Checks 2. Create Vouchers
  • 21. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 21 Tactical Steps Install and activate integration with Financials Select Targeted business process (procure to pay) Identify delivered entitlements – Pare down list Execute delivered controls against configured security Produce delivered reports to identify conflicts Adjust Roles and Rules as identified
  • 22. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Demonstration of how it’s done!
  • 23. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com
  • 24. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal24 The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle.
  • 25. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal25 Create Supplier Invoice Create PaymentSupplier Create Supplier Create Payment for same supplier + Create Supplier Create Payment for supplier≠ Prevent user from creating and paying the same supplier
  • 26. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal26 Prevent user from creating and paying the same supplier  AACG : Find users who could create and pay fictitious suppliers – Users with both “Create Supplier” and “Create Payment” privileges – Remove privileges when possible  TCG: Monitor users who have created and paid the same supplier – For users who must have both privileges
  • 27. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal27 Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal27 Advanced Controls Foundation Custom or Legacy Applications Fusion Platform with Dashboards, Alerts & Drilldowns Sophisticated Controls Monitoring and Enforcement Engine Many Types of Controls against Various Business Applications
  • 28. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal28 • Move away from silo’d information • Multiple ERPs monitored from a single application. • Control totals and exposure areas in self-serve capacity. Advanced Controls – Embedded Dashboards
  • 29. Copyright © 2013 Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal29 Application Access Controls Governor (AACG)  Document, assess and certify Application Security/SOD policies  Library of pre-built automated SOD controls for EBS, PSFT  Author new controls, extend to any business application Advanced SOD and Security Controls Compensating Policies Preventive Provisioning Remediation (Clean-up) Access Analysis Define Access Controls Detection Prevention
  • 30. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal30 AACG – Finding Conflicts User: Janie Adams Responsibility: Payables Super User (Process Operations) Menu: AP_Navigate_GUI12 Submenu: AZN_AP_Invoices_Entry Function: Payments Privilege: Create Purchase Order Role: Buyer Permission List: Buyer Duty SOD Conflict PeopleSoft EBS
  • 31. Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal31 Role Permission List Menu Component Page Definition Component Page Definition Access Hierarchy Example – PeopleSoft Other important attributes: Business Unit, Effective Date, Set ID, Ledger, Account Lock etc. Access Points
  • 32. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal32 Glossary of Terminology Control ManagementAccessPoint Any level node in the access model hierarchy for a particular application. Entitlement A logical grouping of Access points. E.g. All pages that allow a user to create a voucher grouped as a single Entitlement “Create Voucher” ModelControl A rule that defines toxic combinations of entitlements and/or access points.
  • 33. Copyright © 2013 Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal33  Review Model Definition  Analyze Results  Modify Entitlement  Deploy Control  Generate Incidents  Secure, Route and Remediate Incidents Demonstration
  • 34. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal34 Demonstration Summary • Review Entitlements and Model Definition • Modify to fit needs and generate focused results • Compliment PeopleSoft embedded controls with Advanced Controls Leverage Delivered Content • Limit who can see generated results • Route generated results for Investigation, Review and Approval • Determine and document remediation actions Secure, Route and Take Action • Validate role structure during PeopleSoft Implementation • Identify and update role structures during an upgrade Implementation or Upgrades
  • 35. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 35 Lessons Learned • While implementing new systems, integrating a formal risk-management approach increases value of the effort • Staying on point for a focus area narrows work effort • Smaller scope enables confirmation with audit team that this is a viable and valid solution for all business processes
  • 36. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 36 Lessons Learned • Once completed, it provides not only proof of concept but a foundation for future expansion • As system is deployed and user population changes or grows, delivered reports and remediation steps become part of normal maintenance • Create a roadmap for the future based on feedback from internal and external auditors as to high risk areas
  • 37. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 37 Lessons Learned - not just for new implementations • Security is one area likely to get out of control – time to fix it! • Advanced Controls can resolve negative audit finding with your current PeopleSoft implementation • Advanced Control findings can help to justify the upgrade cost Upgrades • Security will be reviewed in light of new roles, integrating Advanced Controls into this work effort minimizes overall cost • Especially pertinent to expanding Payables to full Procure-to-Pay solution • Update of SOX documentation will incorporate additional, tighter controls New Modules • Easily cost justified in reduction of audit costs • Great target area for IT compliance as well as business requirements • Quick win for maximum return Standalone GRC
  • 38. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com 38 Questions Beacon Application Services Corporation info@beaconservices.com
  • 39. Beacon Application Services Corporation Proprietary and Confidential www.beaconservices.com Oracle Financial Services The Choice of Experience. Madeline Osit Beacon Application Services Corporation mosit@beaconservices.com 508.663.4407
  • 40. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal40 Oracle Advance Controls OOW2013 Sessions & Demo Pod Slides
  • 41. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal41 Demo Workstation Moscone West 1st Floor #W-013 Monday Tuesday Wednesday Demo ID 3532 Workstation #: W--013 9:45 – 6:00 9:45 – 6:00 9:45 – 4:00
  • 42. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal42 Demo Workstation Moscone West 1st Floor #W-013
  • 43. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal43 General Session: Empowering Modern Governance, Risk, and Compliance  12:15PM Moscone West – 2006/2008  GEN8812 Automate Robust User Access and Security Controls for PeopleSoft  10:45AM Moscone West - 2009  CON8820 Panel Discussion: Intelligent Controls for Key Business Processes & Upgrades in PeopleSoft  3:15PM Moscone West - 3020  CON8822 Deloitte: Leveraging Oracle GRC Technology to Reduce Revenue Loss, Cost Leakage & Fraud  3:15PM Moscone West - 2000  CON8822 Learn More About Oracle Advance Controls Monday
  • 44. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal44 Top 10 Advanced Controls for Procure-to-Pay to Improve the Bottom Line  10:30AM Moscone West – 2003  CON8814 Center for Medicare & Medicaid Services Automates Internal Controls with Oracle GRC  3:45PM St Francis – Elizabethan C/D  CON9346 Enforce Segregation of Duties with Identity Management and Oracle Advanced Controls  5:15PM Moscone West – 3018  CON8827 Learn More About Oracle Advance Controls Tuesday
  • 45. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal45 Optimizing Order-to-Cash with Oracle Advanced Controls for Oracle E-Business Suite  10:15AM Moscone West – 3018  CON8816 Reducing Risk for Oracle E-Business Suite Upgrades and Implementations  1:15PM Moscone West – 3018  CON8830 Panel Discussion: Intelligent Controls for Key Business Processes and Upgrades  3:30PM Moscone West – 2002 / 2004  CON8832 Learn More About Oracle Advance Controls Wednesday
  • 46. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal46 Advanced Access and User Security for Oracle E-Business Suite and Fusion Applications  2:00PM Moscone West – 3018  CON8824 Meet the Governance, Risk, and Compliance Experts  12:30PM Moscone West 2001A  MTE9412 Learn More About Oracle Advance Controls Thursday
  • 47. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal47 Specialized Advanced Controls Partners  New Benefit for Advanced Controls owners  Specialized Partners: – Trained by Oracle:  Designing and delivering OAC solutions – Demonstrated ability to deliver reliable OAC solutions  Coming soon
  • 48. Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Confidential – Oracle Internal48 @OracleAdvCntrls