Download PUBLIC SECTOR SECURITY
Transcript
SECURITY 51 To help alleviate some of the burden on Beth in IT the HR department got approval to hire their own dedicated Analyst to run utilities and write CDD Reports. Solution: Once hired, the new position will be setup basically the same as the Assistant Director of HR except that "Create Reports" will be added to the role list. This will grant the ability to change and create reports but only within the HR folders. In addition to this a new Role is created named "HR Utitlities" with just the HR utility masks and is assigned to the new position. PY Manager can now run utilities Solution: A new role is created named "Payroll Utilities" with the PY utility masks granted and assigned to the Payroll Manager. One of the Procurement Clerks (Jesse) can write SI reports but only in the SI folders. This is an especially tricky change because up until now the organization was operating under the premise that all the folders would grant full access and the ability to edit or create would be controlled at the functional level. Solution: At first it looked like the "Financial Reports" role would need to be removed and replaced by two new roles to accommodate this change. However, after further analysis they found that the only people in the organization who were editing or creating financial reports were people in IT that already had access to the "All Reports" role. Therefore, the "Financial Reports" role was changed to only grant Execute access and a new role "Edit SI Reports" was created with Read, Write, Update and Delete access on the SI folders. The Procurement Clerks writing SI reports didn't seem to grasp the concept of reusability and when creating far too many categories. Also, the categories were including tables that were not limited to Stores Inventory. Solution: To address this need the "Create Reports" role was change to only grant Read, Write, Update and Delete on "CDD Reports". Then, a new role "Create Categories" was added that allowed access to Read, Write, Update and Delete Information Categories and Table Definitions and that role was assigned to all the same people who had "Create Reports" other than the Procurement Clerks. The result was that now that clerks could only create reports and not categories and therefore all the subsequent report designs were limited to existing categories in the SI category folders. Due to some miscommunication the Vanilla School District decides only IT can delete reports, information categories and table definitions. Solution: To address this need the Delete permission was removed from the "Create Reports" role and a new role was created named "Delete Reports" and that role was only assigned to the people in IT who had "Create Reports" before. 1.1.14 Security Planning Please keep in mind that this portion of the documentation is simply intended to provide some suggestions about how to plan for security within your organization. These are definitely no formal requirements of the software but merely one possible approach of setting up security. Breaking Down Your Organization Once you have a solid understand of Role-Based Security the next step is to start planning for its implementation. Its important during this phase to focus on the types of security needed without considering what specific Security Roles will be needed.