Sunteți pe pagina 1din 33

1

For Oracle employees and authorized partners only. Do not distribute to third parties.

1-1

2013 Oracle Corporation Proprietary and Confidential

<Insert Picture Here>

Security Profiles and Data Roles

Safe Harbor Statement


The following is intended to outline our general
product direction. It is intended for information
purposes only, and may not be incorporated into any
contract. It is not a commitment to deliver any
material, code, or functionality, and should not be
relied upon in making purchasing decisions.
The development, release, and timing of any
features or functionality described for Oracles
products remains at the sole discretion of Oracle.

3
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Oracle Training Materials Usage


Agreement
Use of this Site (Site) or Materials constitutes agreement with the following terms and conditions:
1. Oracle Corporation (Oracle) is pleased to allow its business partner (Partner) to download and copy
the information, documents, and the online training courses (collectively, Materials") found on this Site.
The use of the Materials is restricted to the non-commercial, internal training of the Partners employees
only. The Materials may not be used for training, promotion, or sales to customers or other partners or
third parties.
2. All the Materials are trademarks of Oracle and are proprietary information of Oracle. Partner or other
third party at no time has any right to resell, redistribute or create derivative works from the Materials.
3. Oracle disclaims any warranties or representations as to the accuracy or completeness of any
Materials. Materials are provided "as is" without warranty of any kind, either express or implied, including
without limitation warranties of merchantability, fitness for a particular purpose, and non-infringement.
4. Under no circumstances shall Oracle or the Oracle Authorized Delivery Partner be liable for any loss,
damage, liability or expense incurred or suffered which is claimed to have resulted from use of this Site of
Materials. As a condition of use of the Materials, Partner agrees to indemnify Oracle from and against any
and all actions, claims, losses, damages, liabilities and expenses (including reasonable attorneys' fees)
arising out of Partners use of the Materials.
5. Reference materials including but not limited to those identified in the Boot Camp manifest can not be
redistributed in any format without Oracle written consent.
4
For Oracle employees and authorized partners only. Do not distribute to third parties.

1-4

2013 Oracle Corporation Proprietary and Confidential

Agenda
Data security through security profiles
Predefined HCM security profiles
Approaches to creating Data Roles

5
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Learning Objectives
At the end of this lesson you should be able to:
Explain data security through security profiles
Use predefined HCM security profiles
Explain approaches to creating Data Roles

6
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Section 1:

Explain data security


through security profiles

7
For Oracle employees and authorized partners only. Do not distribute to third parties.

1-7

2013 Oracle Corporation Proprietary and Confidential

Security Profile: Overview


Security profiles define data sets
Security profiles are defined by customers
Security profiles are assigned to roles that are directly
assigned to users

8
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Security Profile: Overview


Types of Security Profiles
Point

Person
Organization
Position
Country
Legislative data group
Document type
Payroll
Payroll Flow
9
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Fusion RBAC Transparent and Finely


Grained
Data Role and Security Profiles

What is your Job?

Organization
Position
Countries
Legislative Data Groups
Person Type
Document Type
Payroll

What would you say you


do here?

How exactly do you


get that done?

10
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Security Profiles Example

11
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Section 2:

Predefined HCM security


profiles

12
For Oracle employees and authorized partners only. Do not distribute to third parties.

1 - 12

2013 Oracle Corporation Proprietary and Confidential

Predefined HCM Security Profiles


Security Profile

Business Objects

View All People

All person records

View Own Record

Signed-on users own person record


and user contacts

View Manager Hierarchy

All person records in the signed-on


users manager hierarchy

View All Workers

All person records of people who have a


work relationship

View All Organizations

All organizations

View All Positions

All positions

View All Legislative Data Groups

All legislative data groups

View All Countries

All countries

View All Document Types

All document types

View All Payrolls

All payrolls

View All Payroll Flows

All payroll flows

View All Workforce Business Processes

All workforce business processes


13

For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Predefined HCM Security Profiles


User can not
Edit or delete the predefined security profiles
Create a custom security profile that provides access to all
seeded objects; you must use the appropriate predefined View
All security profile instead

14
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Section 3:

Approaches to creating Data


Roles

15
For Oracle employees and authorized partners only. Do not distribute to third parties.

1 - 15

2013 Oracle Corporation Proprietary and Confidential

Approaches to creating Data Roles


Give employees access to their own records, the person
records of their emergency contacts, beneficiaries, and
dependents, and all public-person records
Assign relevant HCM security profiles directly to the
employee abstract role
Give managers access to the person records of direct
and indirect reports. Assign relevant HCM security
profiles directly to the line manager abstract role
For individual job roles, determine whether all users with
that job role access the same HCM business object
instances
16
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

17
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

18
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

19
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

20
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

21
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

22
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

23
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to existing role

24
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to new data role

25
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to new data role

26
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Assign Security Profiles to new data role

27
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Security Profiles Best Practices


HCM security profiles are reusable and modular. Once
you create a security profile, you can assign it to
multiple data roles.
You can reference organization, position, payroll, and
other security profiles in a person security profile.
Use the predefined security profiles wherever
appropriate.
Security profile names must be unique in the enterprise
for the security profile type.

28
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Summary of the lesson


Describing data security through security profiles
Usage of predefined HCM security profiles
Approaches to creating Data Roles

29
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

Module Review

30
For Oracle employees and authorized partners only. Do not distribute to third parties.

1 - 30

2013 Oracle Corporation Proprietary and Confidential

Key Points
Security profiles are assigned to roles that are
directly assigned to users
User can not edit or delete the predefined security
profiles
User can not create a custom security profile that
provides access to all seeded objects
Assign relevant HCM security profiles directly to the
employee and line manager abstract role

31
For Oracle employees and authorized partners only. Do not distribute to third parties.
2013 Oracle Corporation Proprietary and Confidential

32
For Oracle employees and authorized partners only. Do not distribute to third parties.

1 - 32

2013 Oracle Corporation Proprietary and Confidential

33
For Oracle employees and authorized partners only. Do not distribute to third parties.

1 - 33

2013 Oracle Corporation Proprietary and Confidential

S-ar putea să vă placă și