SlideShare a Scribd company logo
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Introducing Oracle Fusion
Advanced Access Controls
to Strengthen Security
OpenWorld 2016
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Introducing Oracle Fusion
Advanced Access Controls
to Strengthen Security
This session provides a first look at this upcoming cloud service:
Continually detect and manage unwanted user access in ERP, HCM & SCM Clouds
Streamline role design, access policies
Improve access controls for SOX, other regulations
This session will help you:
Learn about this cloud service from industry experts and Oracle’s product developers
Determine whether this cloud service will be right for your organization
Get answers to your questions in live Q&A with our panelists
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Safe Harbor Statement
The following is intended to outline our general product direction. It is intended for
information purposes only, and may not be incorporated into any contract. It is not a
commitment to deliver any material, code, or functionality, and should not be relied upon
in making purchasing decisions. The development, release, and timing of any features or
functionality described for Oracle’s products remains at the sole discretion of Oracle.
3
4
© 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG
International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International.
Why Are Access Controls
Needed?
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
5
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Panelists
– Katrina Johnson
Chief Audit Executive
Service Corp International
– Nicholas Seeman
Director, Advisory Services
KPMG LLP
– Mark Stebelton
Director, Product Management
Oracle Product Development
Moderator
– Barry Greenhut
Director, Product Strategy
Oracle Product Development
6
Session Speakers
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
11
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Advanced Access Controls – Design Objectives
Find users in
Oracle
ERP/HCM/SCM
Cloud who…
• Can generate unwanted transactions – e.g., have
separation of duties (SoD) conflicts
• Have access to sensitive data
Let
organizations…
• Identify and minimize unnecessary financial and
operational risk
• Demonstrate compliance with SOX and similar obligations
12
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Why Are Access Controls Needed?
14
• Enforcement includes detecting users who can:
• Application owners must continually enforce those policies
Enter unwanted
transactions
Create invoices then pay them
Create purchase orders then record
receipts for them
Create/change critical setup
data and configurations
Spending authorization limits
Opening closed accounting periods
Create/change
master data
Supplier
Customer
Employee
Item
17
© 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG
International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International.
Access Control Maturity
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Create Supplier Invoice Create PaymentSupplier
Create Supplier Create Payment for
same supplier
+ Create Supplier Create Payment for
supplier
≠
Why Is Separation of Duties Needed?
18
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Advanced Access Controls – Design Objectives
Restrict Unauthorized Access & Automate SoD Analysis
Manage Exceptions & Simulate Changes
Link Results to Business Risks
Automate User Security Analysis
Deploy Pre-Built SoD Controls
Author New Access Rules & Policies
19
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Deep, Dynamic Analysis
• Generate unwanted transactions
E.g., Separation of Duties
• Access to sensitive data
ERP/HCM/SCM
user abilities
• Ready to grow as privileges are added
to ERP/HCM/SCM
6,000+
ERP/HCM/SCM
privileges
20
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
User: Janie Adams
Job Role: Accounts Payable Supervisor
Duty Role: Payables Payment Creation
Privilege: Create Payables Payments
Privilege: Create Purchase Order
Job Role: Buyer
SoD Conflict
Deep, Dynamic Analysis
Duty Role: Purchase Order Authoring
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Closed-loop, Compliant System
Enforce
control
objectives,
policies,
regulations
Maintain
as users
are added,
assigned
other roles
Evaluate
& enact
treatment
Detect users’
access
continually
Detect Evaluate
EnforceMaintain
24
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Preview
Panelist Q&A
More Resources
1
2
3
4
26
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Preview
InFusion Corp: Goals and Requirements
Requirements: We need an enterprise solution that:
• Automates detection of users with excessive access
• Provides an audit trail of remediation activities for access issues
• Secures what users see and do within the solution
• Provides data and reports that key stakeholders need to make good decisions
• Requires minimum resources to administer after go-live
27
Goal: We need to address user access risk by understanding excessive
user access, treating access issues, and documenting accordingly
Process Owner and
Auditor
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 28
Best Practice Process
Identify
Excessive
Access
Deploy
Controls
Address
Issues
Report
Results
28
Create Models and
assess results
Remediate excessive access
where feasible
Convert Models to
Controls
Run Control Analysis
periodically
Manage incidents - options:
Adjust ERP/HCM/SCM
security configuration
Add compensating
transaction controls
Report incident
management results to
managers, auditors
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 31
I import pre-built models, test and
refine them, and use the results to
guide improvements to role
definitions
Preview
Diane Analyst
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 32
Import Pre-built Models
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Import Pre-built Models
Procurement
• Create Payments &
• Create Suppliers
• Set Up Payment
• Create Purchase Orders &
• Approval Authorization
Control
• Approve Invoices
• Create Invoices
Financials
• Enter Journal Entry &
• Approve Invoices
• Assets Workbench
• Create Invoices
• Create Payments
• Create Purchase Orders
• Post Journal Entry &
• Approve Invoices
• Assets Workbench
• Create Invoices
• Create Payments
• Create Purchase Orders
• Physical Inventory
Supply Chain
• Create Items &
• Cycle Counting
• Inventory Transactions
• Inventory Transactions &
• Receive Goods and Services
• Item Costing &
• Create Items
• Create Purchase Orders
• Ship Confirm Goods
33
Some of the planned pre-built models (100+ planned)
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 34
Review Model
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 35
Configure Model – Business Objects
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 36
Configure Model- Filter Logic
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 37
Configure Model- Access Conditions
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 38
Review Model Results
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 39
Visualize Incidents
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 40
Convert Models to Controls
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 41
I review and remediate incidents in
my business area
Review and Remediate Incidents
Chris Owner
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 42
Review and Remediate Incidents
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 43
Simulate Role Redesign
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 44
I review incident reports and re-
evaluate our existing access controls
Review Incident Reports
Alan Auditor
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 45
Review Incident Reports
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Advanced Access Controls – Design Objectives
Restrict Unauthorized Access & Automate SoD Analysis
Manage Exceptions & Simulate Changes
Link Results to Business Risks
Automate User Security Analysis
Deploy Pre-Built SoD Controls
Author New Access Rules & Policies
46
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
Katrina Johnson Service Corp International
Nicholas Seeman KPMG LLP
Mark Stebelton Oracle Product Development
More Resources
1
2
3
4
51
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.
Agenda
Panelist Introductions
Introducing Advanced Access Controls
Panelist Q&A
More Resources
1
2
3
4
52
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
DEMOgrounds
Moscone West Level 3 Lobby (M,T,W) ERP Showcase
Workstation
WEP-020
53
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Wednesday
CUSTOMER CASE STUDY
Sep 21, 11:00 AM – 11:45 AM| Moscone West 3005
Securing ERP: Application Compliance
and Controls Implementation
[CAS7689]
Gautham Ramkumar: Director, Advisory Services, KMPG LLP
Chuck Devore, Director, Finance Transformation, ADM
Kenneth Kobia, Risk & Controls Lead, Archer Daniels Midland
Organizations have successfully transformed their business
operations by leveraging Oracle ERP technologies. Yet they
continue to struggle to balance the two divergent needs of
empowering ERP business users, while protecting sensitive
data and transactions. In this session KPMG and Archer
Daniels Midland detail how they took advantage of Oracle’s
ERP security and controls capabilities, to support ADM’s
initiative to deploy Oracle ERP .
PANEL SEESION
Sep 21, 1:30 PM – 2:15PM | Moscone West 3005
Introducing Oracle Fusion Advanced
Access Controls to Strengthen Security
[CON7290]
Katrina Johnson, VP Risk Assurance, Service Corp
International
Nicholas Seeman, Director, Advisory Services, KMPG LLP
Barry Greenhut, Director, Product Strategy, Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides an overview of Oracle Fusion Advanced
Access Controls to continuously detect segregation of duties
violations, manage exceptions, and fix unauthorized access to
sensitive functions and data. Compliance managers and
auditors can use Oracle Fusion Advanced Access Controls to
ensure strong access controls across ERP, HCM and SCM
cloud applications.
PANEL SESSION
Sep 21, 4:15 PM – 5:00 PM | Moscone West 3005
Implement the Best Practice for Oracle
Financial Reporting Compliance Cloud
[CON7291]
Swarnali Bag, Governance, Risk & Compliance Practice Lead,
Oracle
Barry Greenhut, Director, Product Strategy , Oracle
Lakshmi Rajamohan, Principal Product Strategy Mgr., Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides a more detailed walkthrough of Oracle
Financial Reporting Compliance from an end user’s
perspective, and highlights how the product can be
configured to automate the best practice process. Based on
learning from a decade of customer experience, it showcases
the shortest and most cost-effective path to go live and
streamline operations.
54
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
Thursday
PANEL SESSION
Sep 22, 9:30 AM – 10:15 AM| Moscone West 3005
Implement the Best Practice for Oracle Fusion Advanced Financial
Controls Cloud Service
[CAS7286]
Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle
Barry Greenhut, Director, Product Strategy, Oracle
Christine Doxey, President, Doxey, Inc.
Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle
Mark Stebelton, Director, Product Management, Oracle
This session provides a detailed walkthrough of Oracle Fusion Financial Controls Cloud Service
from an end user’s perspective, and highlights how the product can be configured to automate
best practice controls. Oracle Fusion Advanced Financial Controls Cloud Service is designed to
meet the common needs of Oracle Financials Cloud subscribers. Based on learning from a decade
of customer experience, this session showcases Oracle’s best practice business process for
maximum ROI with minimum cost of ongoing operation.
PANEL SESSION
Sep 22, 12:00 PM – 12:45 PM | Moscone West 3005
Get Started with Financial Reporting Compliance and Advanced
Financial Controls
[CON7284]
Barry Greenhut, Director, Product Strategy, Oracle
Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle
Joel Alvarado, Customer Success Manager, Oracle
This session provides you with the most effective project plan to implement Oracle Financial
Reporting Compliance or Oracle Fusion Advanced Financial Controls Cloud Service. Participants
will learn the shortest and most cost-effective path to success using Oracle’s customer and
partner-tested “get started” process. Learn how to plan and adopt these cloud services, and then
sustain your use through growth and change. Learn how to get the experience and expertise
needed to succeed.
55
Arturo Martínez del
Campo Saucedo
Corporate Chief Financial Officer
Grupo Posadas S.A.B. de C.V. .
LEADERSHIP IN FINANCE
LATIN AMERICA - CLOUD
2016
Best
Practice
Adopter
First
Adopter
of Risk
Cloud
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |
 For subscribers and partners
To Learn More
Cloud Portal Release Readiness User Documentation Modern Best Practice
Oracle University Success Managers  Get Started  Customer Connect 
57
Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | 5959
Join our LinkedIn Group
For the latest Updates and Presentations .
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 60
| Confidential – Oracle Internal/Restricted/Highly Restricted61

More Related Content

PDF
5 enterprise structures
PDF
Introducing Oracle Advanced Financial Controls Cloud Service
PDF
#OOW16 - Risk Management Cloud / GRC General Session
DOCX
Fusion Financial Reporting and Analysis Proof of Concept
PPT
Oracle property manager
PDF
8 legal structures
PPTX
Rapid implementation Spreadsheets in Oracle ERP Cloud
PDF
Oracle fusion cloud financial : How to create Journal , Manual Vs Spreadsheet?
5 enterprise structures
Introducing Oracle Advanced Financial Controls Cloud Service
#OOW16 - Risk Management Cloud / GRC General Session
Fusion Financial Reporting and Analysis Proof of Concept
Oracle property manager
8 legal structures
Rapid implementation Spreadsheets in Oracle ERP Cloud
Oracle fusion cloud financial : How to create Journal , Manual Vs Spreadsheet?

What's hot (20)

PPTX
Oracle Fusion Financial Report Centre Reporting Beginner course
PPTX
Cloudy with a chance of 1099
PPTX
Oracle EBS Apps HRMS Presentation
PDF
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...
PPTX
Presentation i recruitment
PPTX
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...
DOC
Planning learn step by step
PDF
Understanding Multi-Org Structure in Oracle Apps
PPTX
Oracle Time and Labor
PPTX
Oracle PPM Cloud Project Financial Management - Oracle Training
PDF
Presentation oracle ebs r12
PPT
Fusion applications gl and ar suresh c-mishra
PPT
Oracle Fusion Payments
PPT
PDF
Fusion apps receivables
PPTX
Creating Reports with Financial Reporting Web Studio.pptx
PDF
HFM Member List Tips
DOCX
Oracle EBS R 12 Core hr user manual
PPT
Oracle EPM/BI Overview
PDF
Designing a Chart of Accounts for a Global Company Going to Oracle E-Business...
Oracle Fusion Financial Report Centre Reporting Beginner course
Cloudy with a chance of 1099
Oracle EBS Apps HRMS Presentation
#OOW16 - Implement the Best Practice for Oracle Financial Reporting Complianc...
Presentation i recruitment
Designing a Chart of Accounts and Enterprise Structure in Oracle Fusion ERP C...
Planning learn step by step
Understanding Multi-Org Structure in Oracle Apps
Oracle Time and Labor
Oracle PPM Cloud Project Financial Management - Oracle Training
Presentation oracle ebs r12
Fusion applications gl and ar suresh c-mishra
Oracle Fusion Payments
Fusion apps receivables
Creating Reports with Financial Reporting Web Studio.pptx
HFM Member List Tips
Oracle EBS R 12 Core hr user manual
Oracle EPM/BI Overview
Designing a Chart of Accounts for a Global Company Going to Oracle E-Business...
Ad

Similar to #OOW16 - Introduction to Advanced Access Controls (20)

PDF
Advanced Controls access and user security for superusers con8824
PDF
Oracle Scene Safeguard your Business
PDF
Oracle Scene Oct 2017
PDF
Integrate Oracle Identity Management and Advanced Controls for maximum effici...
PDF
Oracle Database 11g Security and Compliance Solutions - By Tom Kyte
PDF
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
PDF
Best Practices for implementing Database Security Comprehensive Database Secu...
PDF
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
PPTX
Reduce License costs and increase security in Oracle Applications
PPTX
The Enablement of an Identity-Centric SOC in the Regulatory Rumba Era
PDF
Self Service Access Control - Help Yourself to More Productivity
PPTX
SANS Institute Product Review: Oracle Entitlements Server
PDF
Auditing Oracle Applications Primer For Internal Auditors
PPTX
The EU General Protection Regulation and how Oracle can help
PDF
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
PPT
3 oraclex evento reg puglia_v2017-09-14-2
PDF
Oracle Identity & Access Management
PPTX
Oracle 11g security - 2014
PPTX
Round table guide
PPTX
Sroaug October 27 2017 Learn to Streamline User Provisioning in Oracle Apps
Advanced Controls access and user security for superusers con8824
Oracle Scene Safeguard your Business
Oracle Scene Oct 2017
Integrate Oracle Identity Management and Advanced Controls for maximum effici...
Oracle Database 11g Security and Compliance Solutions - By Tom Kyte
Optimizing order to-cash (e-business suite) with GRC Advanced Controls
Best Practices for implementing Database Security Comprehensive Database Secu...
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Reduce License costs and increase security in Oracle Applications
The Enablement of an Identity-Centric SOC in the Regulatory Rumba Era
Self Service Access Control - Help Yourself to More Productivity
SANS Institute Product Review: Oracle Entitlements Server
Auditing Oracle Applications Primer For Internal Auditors
The EU General Protection Regulation and how Oracle can help
Stop the fraudster! Pennsylvania Treasury, Industry Expert Chris Doxey and Fu...
3 oraclex evento reg puglia_v2017-09-14-2
Oracle Identity & Access Management
Oracle 11g security - 2014
Round table guide
Sroaug October 27 2017 Learn to Streamline User Provisioning in Oracle Apps
Ad

Recently uploaded (20)

PDF
IFRS Notes in your pocket for study all the time
PPTX
Probability Distribution, binomial distribution, poisson distribution
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
Chapter 5_Foreign Exchange Market in .pdf
PPTX
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
PPTX
5 Stages of group development guide.pptx
PPTX
Principles of Marketing, Industrial, Consumers,
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
PPT
Data mining for business intelligence ch04 sharda
PDF
How to Get Business Funding for Small Business Fast
PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
PPTX
HR Introduction Slide (1).pptx on hr intro
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PDF
A Brief Introduction About Julia Allison
PDF
Types of control:Qualitative vs Quantitative
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
IFRS Notes in your pocket for study all the time
Probability Distribution, binomial distribution, poisson distribution
ICG2025_ICG 6th steering committee 30-8-24.pptx
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
Ôn tập tiếng anh trong kinh doanh nâng cao
Chapter 5_Foreign Exchange Market in .pdf
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
5 Stages of group development guide.pptx
Principles of Marketing, Industrial, Consumers,
New Microsoft PowerPoint Presentation - Copy.pptx
Data mining for business intelligence ch04 sharda
How to Get Business Funding for Small Business Fast
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
HR Introduction Slide (1).pptx on hr intro
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
A Brief Introduction About Julia Allison
Types of control:Qualitative vs Quantitative
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi

#OOW16 - Introduction to Advanced Access Controls

  • 1. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Introducing Oracle Fusion Advanced Access Controls to Strengthen Security OpenWorld 2016
  • 2. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Introducing Oracle Fusion Advanced Access Controls to Strengthen Security This session provides a first look at this upcoming cloud service: Continually detect and manage unwanted user access in ERP, HCM & SCM Clouds Streamline role design, access policies Improve access controls for SOX, other regulations This session will help you: Learn about this cloud service from industry experts and Oracle’s product developers Determine whether this cloud service will be right for your organization Get answers to your questions in live Q&A with our panelists
  • 3. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Safe Harbor Statement The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle. 3
  • 4. 4 © 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International. Why Are Access Controls Needed?
  • 5. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 5
  • 6. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Panelists – Katrina Johnson Chief Audit Executive Service Corp International – Nicholas Seeman Director, Advisory Services KPMG LLP – Mark Stebelton Director, Product Management Oracle Product Development Moderator – Barry Greenhut Director, Product Strategy Oracle Product Development 6 Session Speakers
  • 7. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 11
  • 8. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Advanced Access Controls – Design Objectives Find users in Oracle ERP/HCM/SCM Cloud who… • Can generate unwanted transactions – e.g., have separation of duties (SoD) conflicts • Have access to sensitive data Let organizations… • Identify and minimize unnecessary financial and operational risk • Demonstrate compliance with SOX and similar obligations 12
  • 9. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Why Are Access Controls Needed? 14 • Enforcement includes detecting users who can: • Application owners must continually enforce those policies Enter unwanted transactions Create invoices then pay them Create purchase orders then record receipts for them Create/change critical setup data and configurations Spending authorization limits Opening closed accounting periods Create/change master data Supplier Customer Employee Item
  • 10. 17 © 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. The KPMG name and logo are registered trademarks or trademarks of KPMG International. Access Control Maturity
  • 11. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Create Supplier Invoice Create PaymentSupplier Create Supplier Create Payment for same supplier + Create Supplier Create Payment for supplier ≠ Why Is Separation of Duties Needed? 18
  • 12. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Advanced Access Controls – Design Objectives Restrict Unauthorized Access & Automate SoD Analysis Manage Exceptions & Simulate Changes Link Results to Business Risks Automate User Security Analysis Deploy Pre-Built SoD Controls Author New Access Rules & Policies 19
  • 13. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Deep, Dynamic Analysis • Generate unwanted transactions E.g., Separation of Duties • Access to sensitive data ERP/HCM/SCM user abilities • Ready to grow as privileges are added to ERP/HCM/SCM 6,000+ ERP/HCM/SCM privileges 20
  • 14. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. User: Janie Adams Job Role: Accounts Payable Supervisor Duty Role: Payables Payment Creation Privilege: Create Payables Payments Privilege: Create Purchase Order Job Role: Buyer SoD Conflict Deep, Dynamic Analysis Duty Role: Purchase Order Authoring
  • 15. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Closed-loop, Compliant System Enforce control objectives, policies, regulations Maintain as users are added, assigned other roles Evaluate & enact treatment Detect users’ access continually Detect Evaluate EnforceMaintain 24
  • 16. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Preview Panelist Q&A More Resources 1 2 3 4 26
  • 17. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Preview InFusion Corp: Goals and Requirements Requirements: We need an enterprise solution that: • Automates detection of users with excessive access • Provides an audit trail of remediation activities for access issues • Secures what users see and do within the solution • Provides data and reports that key stakeholders need to make good decisions • Requires minimum resources to administer after go-live 27 Goal: We need to address user access risk by understanding excessive user access, treating access issues, and documenting accordingly Process Owner and Auditor
  • 18. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 28 Best Practice Process Identify Excessive Access Deploy Controls Address Issues Report Results 28 Create Models and assess results Remediate excessive access where feasible Convert Models to Controls Run Control Analysis periodically Manage incidents - options: Adjust ERP/HCM/SCM security configuration Add compensating transaction controls Report incident management results to managers, auditors
  • 19. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 31 I import pre-built models, test and refine them, and use the results to guide improvements to role definitions Preview Diane Analyst
  • 20. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 32 Import Pre-built Models
  • 21. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Import Pre-built Models Procurement • Create Payments & • Create Suppliers • Set Up Payment • Create Purchase Orders & • Approval Authorization Control • Approve Invoices • Create Invoices Financials • Enter Journal Entry & • Approve Invoices • Assets Workbench • Create Invoices • Create Payments • Create Purchase Orders • Post Journal Entry & • Approve Invoices • Assets Workbench • Create Invoices • Create Payments • Create Purchase Orders • Physical Inventory Supply Chain • Create Items & • Cycle Counting • Inventory Transactions • Inventory Transactions & • Receive Goods and Services • Item Costing & • Create Items • Create Purchase Orders • Ship Confirm Goods 33 Some of the planned pre-built models (100+ planned)
  • 22. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 34 Review Model
  • 23. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 35 Configure Model – Business Objects
  • 24. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 36 Configure Model- Filter Logic
  • 25. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 37 Configure Model- Access Conditions
  • 26. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 38 Review Model Results
  • 27. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 39 Visualize Incidents
  • 28. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 40 Convert Models to Controls
  • 29. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 41 I review and remediate incidents in my business area Review and Remediate Incidents Chris Owner
  • 30. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 42 Review and Remediate Incidents
  • 31. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 43 Simulate Role Redesign
  • 32. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 44 I review incident reports and re- evaluate our existing access controls Review Incident Reports Alan Auditor
  • 33. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 45 Review Incident Reports
  • 34. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Advanced Access Controls – Design Objectives Restrict Unauthorized Access & Automate SoD Analysis Manage Exceptions & Simulate Changes Link Results to Business Risks Automate User Security Analysis Deploy Pre-Built SoD Controls Author New Access Rules & Policies 46
  • 35. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A Katrina Johnson Service Corp International Nicholas Seeman KPMG LLP Mark Stebelton Oracle Product Development More Resources 1 2 3 4 51
  • 36. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Agenda Panelist Introductions Introducing Advanced Access Controls Panelist Q&A More Resources 1 2 3 4 52
  • 37. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | DEMOgrounds Moscone West Level 3 Lobby (M,T,W) ERP Showcase Workstation WEP-020 53
  • 38. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Wednesday CUSTOMER CASE STUDY Sep 21, 11:00 AM – 11:45 AM| Moscone West 3005 Securing ERP: Application Compliance and Controls Implementation [CAS7689] Gautham Ramkumar: Director, Advisory Services, KMPG LLP Chuck Devore, Director, Finance Transformation, ADM Kenneth Kobia, Risk & Controls Lead, Archer Daniels Midland Organizations have successfully transformed their business operations by leveraging Oracle ERP technologies. Yet they continue to struggle to balance the two divergent needs of empowering ERP business users, while protecting sensitive data and transactions. In this session KPMG and Archer Daniels Midland detail how they took advantage of Oracle’s ERP security and controls capabilities, to support ADM’s initiative to deploy Oracle ERP . PANEL SEESION Sep 21, 1:30 PM – 2:15PM | Moscone West 3005 Introducing Oracle Fusion Advanced Access Controls to Strengthen Security [CON7290] Katrina Johnson, VP Risk Assurance, Service Corp International Nicholas Seeman, Director, Advisory Services, KMPG LLP Barry Greenhut, Director, Product Strategy, Oracle Mark Stebelton, Director, Product Management, Oracle This session provides an overview of Oracle Fusion Advanced Access Controls to continuously detect segregation of duties violations, manage exceptions, and fix unauthorized access to sensitive functions and data. Compliance managers and auditors can use Oracle Fusion Advanced Access Controls to ensure strong access controls across ERP, HCM and SCM cloud applications. PANEL SESSION Sep 21, 4:15 PM – 5:00 PM | Moscone West 3005 Implement the Best Practice for Oracle Financial Reporting Compliance Cloud [CON7291] Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle Barry Greenhut, Director, Product Strategy , Oracle Lakshmi Rajamohan, Principal Product Strategy Mgr., Oracle Mark Stebelton, Director, Product Management, Oracle This session provides a more detailed walkthrough of Oracle Financial Reporting Compliance from an end user’s perspective, and highlights how the product can be configured to automate the best practice process. Based on learning from a decade of customer experience, it showcases the shortest and most cost-effective path to go live and streamline operations. 54
  • 39. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | Thursday PANEL SESSION Sep 22, 9:30 AM – 10:15 AM| Moscone West 3005 Implement the Best Practice for Oracle Fusion Advanced Financial Controls Cloud Service [CAS7286] Swarnali Bag, Governance, Risk & Compliance Practice Lead, Oracle Barry Greenhut, Director, Product Strategy, Oracle Christine Doxey, President, Doxey, Inc. Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle Mark Stebelton, Director, Product Management, Oracle This session provides a detailed walkthrough of Oracle Fusion Financial Controls Cloud Service from an end user’s perspective, and highlights how the product can be configured to automate best practice controls. Oracle Fusion Advanced Financial Controls Cloud Service is designed to meet the common needs of Oracle Financials Cloud subscribers. Based on learning from a decade of customer experience, this session showcases Oracle’s best practice business process for maximum ROI with minimum cost of ongoing operation. PANEL SESSION Sep 22, 12:00 PM – 12:45 PM | Moscone West 3005 Get Started with Financial Reporting Compliance and Advanced Financial Controls [CON7284] Barry Greenhut, Director, Product Strategy, Oracle Lakshmi Rajamohan, Principal Product Strategy Manager, Oracle Joel Alvarado, Customer Success Manager, Oracle This session provides you with the most effective project plan to implement Oracle Financial Reporting Compliance or Oracle Fusion Advanced Financial Controls Cloud Service. Participants will learn the shortest and most cost-effective path to success using Oracle’s customer and partner-tested “get started” process. Learn how to plan and adopt these cloud services, and then sustain your use through growth and change. Learn how to get the experience and expertise needed to succeed. 55
  • 40. Arturo Martínez del Campo Saucedo Corporate Chief Financial Officer Grupo Posadas S.A.B. de C.V. . LEADERSHIP IN FINANCE LATIN AMERICA - CLOUD 2016 Best Practice Adopter First Adopter of Risk Cloud
  • 41. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. |  For subscribers and partners To Learn More Cloud Portal Release Readiness User Documentation Modern Best Practice Oracle University Success Managers  Get Started  Customer Connect  57
  • 42. Copyright © 2016, Oracle and/or its affiliates. All rights reserved.Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | 5959 Join our LinkedIn Group For the latest Updates and Presentations .
  • 43. Copyright © 2016, Oracle and/or its affiliates. All rights reserved. 60
  • 44. | Confidential – Oracle Internal/Restricted/Highly Restricted61