|
Wipro conducted business workshops to understand
the monitoring process of the application and
suggested suitable deployment and technical solution.
This was followed by architecture, design and
implementation of the security solution using
Netegrity SiteMinder, an access management security
product, used to securely manage user access across
applications. However, since SiteMinder deployment
alone could not have achieved all the application
security requirements of the system, additionally,
a security administration module was also integrated
with the application to provide role administration
and reporting facilities.
The security features implemented for this project
comprise of,
 |
Authentication
(UserId/ Password, SSL Certificate) and Single
Sign On for all the web applications |
 |
Authorization
Model that can be deployed in any application
where SiteMinder or a similar Access Management
product is chosen to implement Access Control. |
 |
Role Based
Access Control - the security process intercepts
all the user requests and performs an Access
Control Check/User Validation before authorizing
a user to gain access |
 |
Personalization
Framework that can fit into all systems with
similar requirements based on user privileges
|
 |
Data Security - achieved
by restricting user access to business activities
of only those control centers to which he/she
is associated. |
 |
Encryption - to ensure
non-repudiation of business transactions |
 |
Audit and Reporting –
Log and monitor business related events |
|