SlideShare a Scribd company logo
1 of 19
User ID Maintenance Project - Phase 1
Product Walkthrough



September 6, 2011
Agenda



    ●    Project Overview and Updates
    ●    Key Features
    ●    Demo
    ●    Next Steps
Project Overview and Updates



    User ID maintenance challenges:
    ●    Multiple channels for requests
    ●    Unsecured and time-consuming process for delivering passwords to users
    ●    No central view of the user for ITO-managed applications



    Project Objectives:
     ●   To streamline and standardize the end-to-end user ID maintenance process.
     ●   To provide a common channel for user ID related requests and follow-ups.
     ●   To incorporate standard and/or automated tools in the process
Project Overview and Updates



    Key decisions made:
     ●   Create a separate, simpler front-end for common users vs. authorized requestors
     ●   Remove ESS from the proposed application architecture
     ●
         Introduce verification of requester identity instead as 2nd authentication factor
     ●   Divide the project into phases, based on functionality to be delivered



    Project Phases & Scope:
     ●   Phase 1: Self-service requests (Reset and Unlock) and password delivery
     ●   Phase 2: Requests requiring approval (e.g. Creation, Deletion, Modification, etc.)
     ●   Phase 3: User ID database
Application Architecture Roadmap




                              3
                                                          ID                                5
             RT
                                       5a
                                                   Administrator           Password                 Business
                                                                           Generator               Application
                                               4



                                               BU         7
                                             Approver                          6
                                               DB




                                            User ID Maintenance Application

                                                                                          10
        1                                                                                                    8
                      2



                     BU                                            Windows
      User                        2a                    User ID                          User      9      Approver
                  Requestor                                         Active
                                                          DB
                                                                   Directory




                  Approver




             Demand                                 Process                            Deliver Password
Application Architecture Roadmap




                              3
                                                        ID                                  5
             RT
                                       5a
                                                   Administrator           Password                 Business
                                                                           Generator               Application

                                       rate
                                         4

                                    pa
                                  Se ject
                                   pro Approver
                                          BU            7                      6
                                              DB




                                            User ID Maintenance Application

                                                                                          10
        1                                                                                                    8
                       2
                                                     3
                                                a se
      User
                     BU           2a
                                              Ph User ID           Windows
                                                                                         User      9      Approver
                  Requestor                                         Active
                                                       DB

                   e   2                                           Directory


             Ph as
                  Approver




             Demand                                 Process                            Deliver Password
Product Overview



   The User ID Maintenance Application
    ●   is a web-based application
    ●   will be made accessible over the BDO intranet (https://userid.bdo.com.ph)
    ●   will serve as the default channel for requests and follow-ups from BDO users
    ●   will cover user IDs managed by ITO only
    ●   will interface with but not replace ITO's central ticketing system (RT)
    ●   will not be integrated with business applications (ex. ICBS, OPICS, etc.)
    ●   will have major releases corresponding to the 3 project phases
Key Product Features (Release 1)



    Works with Windows AD
        ●   Uses Windows AD authentication
        ●   Retrieves relevant employee information from AD (name, employee number,
            email address, etc.)



    Works with Request Tracker
        ●   Web front-end connects to Request Tracker
        ●   Creates RT ticket
        ●   Assigns ticket to RT Coordinator based on the business application
        ●   Closes ticket upon password delivery
Key Product Features (Release 1)



    Secures password delivery to user
        ●   Removes the need for administrators to remember / write down passwords
        ●   Requires 2-factor authentication for password retrieval:
                 Windows password + password key
                 OR 2 password keys
        ●   Deletes encrypted password in the database N days after resolution (N = 7 )


    Secures viewing of requests
        ●   Allows viewing of requests by the requestor or approvers only after log-in
        ●   Exception: requests for Windows IDs (log-in not required)
Key Product Features (Release 1)




    Guides the user
         ●       User chooses among limited options to get to desired page
         ●       Tool tips, hints and reminders

    Manages privileged users via roles
         ●       ID administrator
         ●       Website administrator

    Keeps an audit trail for critical actions:
             ●    Action: login, create/approve/view request, retrieve password
             ●    Information: IP address, session ID, Windows ID, timestamp

    Email notification capability
Demo
Demo



                    User   RT Coordinator   Servicing Personnel
                                             (ID Administrator)


   Request
   Tracker




 Application
 (ex. ICBS,Opics,
     Cadencie)




  User ID
  Website
Demo – Unlock ID



                            User       RT Coordinator    Servicing Personnel
                                                          (ID Administrator)

                                           Review &      Open
   Request                                  assign      assigned
   Tracker                                   ticket       ticket

                                                                     Set ticket
                                             Steal                   status to    End
                                             ticket                 “Resolved”



  Application
                                                        Unlock
 (ex. ICBS,Opics,                                         ID
     Cadencie)




                    Start
                             Submit
                             request




  User ID
  Website
Demo – Reset Password



                            User       Approver   RT Coordinator   Servicing Personnel
                                                                    (ID Administrator)

                                                    Review &             Open
   Request                                           assign             assigned
   Tracker                                            ticket              ticket


                                                      Steal
                                                      ticket


  Application                                                            Reset
 (ex. ICBS,Opics,                                                       password
     Cadencie)




                    Start
                             Submit    Approve                         Search for
                             request   request                         RT ticket #



                                                                        Send new
                            Retrieve
  User ID           End                                                 password
                            password
  Website                                                                to user
Demo – Reset Password (Windows)



                            User         Approver 1   Approver 2   RT Coordinator   Servicing Personnel
                                                                                     (ID Administrator)

                                                                       Review &             Open
  Request                                                               assign             assigned
  Tracker                                                                ticket              ticket


                                                                         Steal
                                                                         ticket



  Application                                                                               Reset
                                                                                           password
 (ex. ICBS,Opics,
     Cadencie)




                    Start
                              Submit      Approve       Approve                           Search for
                              Request     request       request                           RT ticket #



                                                                                           Send new
                              Retrieve
  User ID           End                                                                    password
                              password
  Website                                                                                   to user
Next Steps




    Key Dates:
             Dates                              Activities
     9/14 - 9/26     Product testing
                     Pilot deployment preparations
     10/6            Application deployment (bdoulx023)
     10/10 - 10/31   Pilot to selected business units
                     Technical support and fixes as needed
                     Performance testing and tuning parallel to pilot (bdoulx024)


    Bank-wide rollout and timeline will be decided after the pilot.
Q&A




      ?
Application Architecture Roadmap




      User ID
                          RT
                               3
                                         ID Administrator
                                                             Password      5
                                                                                    Business
      Website                                                Generator             Application
                                   8



                                                        7
                                          4
         1




       User                              BU
                                                   User ID                                            9
                                       Approver
                                                     DB                                                   Approver
                                         DB
                                                                               6     User ID
                                                                                     Website
        BU
                     2                                                                                      10
     Requestor
                                                                                                 11
                                                               Windows
                                                                Active
                                                               Directory
      Approver       2a
                                                                                                           User




                 Demand                    Process                                   Deliver Password
Application Architecture Roadmap




       User ID
                           RT
                                3
                                          ID Administrator
                                                              Password        5
                                                                                       Business
       Website                                                Generator               Application
                                    8



                                                         7
                                           4
         1




        User                              BU
                                                    User ID                                              9
                                        Approver
                                       te                     3
                                                       ase
                                                      DB
                                    ara
                                          DB                                                                 Approver
                                  p
                                Se ject             Ph
                                                                                  6     User ID
                                                                                        Website
         BU
      Requestor       2          pro                                                                           10

          2
       se
                                                                                                    11

      a                                                           Windows

   PhApprover
                                                                   Active
                                                                  Directory
                      2a
                                                                                                              User




                  Demand                    Process                                     Deliver Password

More Related Content

Similar to Uidm deck unit heads 2011 09-06

Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...djmichael156
 
Updated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeUpdated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeSaket Mrinal
 
Software Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeSoftware Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeHari
 
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughAzure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughVinu Gunasekaran
 
SpotMe pitch
SpotMe pitchSpotMe pitch
SpotMe pitchjbusuito
 
OMGi application store
OMGi application storeOMGi application store
OMGi application storetothtamas
 
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...apidays
 
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...WSO2
 
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)Carles Farré
 
Saas webinar-dec6-01
Saas webinar-dec6-01Saas webinar-dec6-01
Saas webinar-dec6-01Paul Madsen
 

Similar to Uidm deck unit heads 2011 09-06 (20)

BI FirstBank
BI FirstBank BI FirstBank
BI FirstBank
 
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...Ric V2.0 Development Workshop   Ric 2.0 Requirements Overview   David Michael...
Ric V2.0 Development Workshop Ric 2.0 Requirements Overview David Michael...
 
Updated SAKET MRINAL Resume
Updated SAKET MRINAL ResumeUpdated SAKET MRINAL Resume
Updated SAKET MRINAL Resume
 
Srs
SrsSrs
Srs
 
Software Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet CafeSoftware Requirement Specification For Smart Internet Cafe
Software Requirement Specification For Smart Internet Cafe
 
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy WalkthroughAzure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
Azure AD B2C Webinar Series: Custom Policies Part 2 Policy Walkthrough
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
SpotMe pitch
SpotMe pitchSpotMe pitch
SpotMe pitch
 
OMGi application store
OMGi application storeOMGi application store
OMGi application store
 
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...INTERFACE, by apidays  - The Evolution of API Security by Johann Dilantha Nal...
INTERFACE, by apidays - The Evolution of API Security by Johann Dilantha Nal...
 
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
Tc Management Srs
Tc Management SrsTc Management Srs
Tc Management Srs
 
CustomerCopy
CustomerCopyCustomerCopy
CustomerCopy
 
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
[DSBW Spring 2009] Unit 07: WebApp Design Patterns & Frameworks (2/3)
 
Saas webinar-dec6-01
Saas webinar-dec6-01Saas webinar-dec6-01
Saas webinar-dec6-01
 
ASP.NET Lecture 5
ASP.NET Lecture 5ASP.NET Lecture 5
ASP.NET Lecture 5
 
Resume
ResumeResume
Resume
 

Recently uploaded

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 

Recently uploaded (20)

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 

Uidm deck unit heads 2011 09-06

  • 1. User ID Maintenance Project - Phase 1 Product Walkthrough September 6, 2011
  • 2. Agenda ● Project Overview and Updates ● Key Features ● Demo ● Next Steps
  • 3. Project Overview and Updates User ID maintenance challenges: ● Multiple channels for requests ● Unsecured and time-consuming process for delivering passwords to users ● No central view of the user for ITO-managed applications Project Objectives: ● To streamline and standardize the end-to-end user ID maintenance process. ● To provide a common channel for user ID related requests and follow-ups. ● To incorporate standard and/or automated tools in the process
  • 4. Project Overview and Updates Key decisions made: ● Create a separate, simpler front-end for common users vs. authorized requestors ● Remove ESS from the proposed application architecture ● Introduce verification of requester identity instead as 2nd authentication factor ● Divide the project into phases, based on functionality to be delivered Project Phases & Scope: ● Phase 1: Self-service requests (Reset and Unlock) and password delivery ● Phase 2: Requests requiring approval (e.g. Creation, Deletion, Modification, etc.) ● Phase 3: User ID database
  • 5. Application Architecture Roadmap 3 ID 5 RT 5a Administrator Password Business Generator Application 4 BU 7 Approver 6 DB User ID Maintenance Application 10 1 8 2 BU Windows User 2a User ID User 9 Approver Requestor Active DB Directory Approver Demand Process Deliver Password
  • 6. Application Architecture Roadmap 3 ID 5 RT 5a Administrator Password Business Generator Application rate 4 pa Se ject pro Approver BU 7 6 DB User ID Maintenance Application 10 1 8 2 3 a se User BU 2a Ph User ID Windows User 9 Approver Requestor Active DB e 2 Directory Ph as Approver Demand Process Deliver Password
  • 7. Product Overview The User ID Maintenance Application ● is a web-based application ● will be made accessible over the BDO intranet (https://userid.bdo.com.ph) ● will serve as the default channel for requests and follow-ups from BDO users ● will cover user IDs managed by ITO only ● will interface with but not replace ITO's central ticketing system (RT) ● will not be integrated with business applications (ex. ICBS, OPICS, etc.) ● will have major releases corresponding to the 3 project phases
  • 8. Key Product Features (Release 1) Works with Windows AD ● Uses Windows AD authentication ● Retrieves relevant employee information from AD (name, employee number, email address, etc.) Works with Request Tracker ● Web front-end connects to Request Tracker ● Creates RT ticket ● Assigns ticket to RT Coordinator based on the business application ● Closes ticket upon password delivery
  • 9. Key Product Features (Release 1) Secures password delivery to user ● Removes the need for administrators to remember / write down passwords ● Requires 2-factor authentication for password retrieval: Windows password + password key OR 2 password keys ● Deletes encrypted password in the database N days after resolution (N = 7 ) Secures viewing of requests ● Allows viewing of requests by the requestor or approvers only after log-in ● Exception: requests for Windows IDs (log-in not required)
  • 10. Key Product Features (Release 1) Guides the user ● User chooses among limited options to get to desired page ● Tool tips, hints and reminders Manages privileged users via roles ● ID administrator ● Website administrator Keeps an audit trail for critical actions: ● Action: login, create/approve/view request, retrieve password ● Information: IP address, session ID, Windows ID, timestamp Email notification capability
  • 11. Demo
  • 12. Demo User RT Coordinator Servicing Personnel (ID Administrator) Request Tracker Application (ex. ICBS,Opics, Cadencie) User ID Website
  • 13. Demo – Unlock ID User RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Set ticket Steal status to End ticket “Resolved” Application Unlock (ex. ICBS,Opics, ID Cadencie) Start Submit request User ID Website
  • 14. Demo – Reset Password User Approver RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Steal ticket Application Reset (ex. ICBS,Opics, password Cadencie) Start Submit Approve Search for request request RT ticket # Send new Retrieve User ID End password password Website to user
  • 15. Demo – Reset Password (Windows) User Approver 1 Approver 2 RT Coordinator Servicing Personnel (ID Administrator) Review & Open Request assign assigned Tracker ticket ticket Steal ticket Application Reset password (ex. ICBS,Opics, Cadencie) Start Submit Approve Approve Search for Request request request RT ticket # Send new Retrieve User ID End password password Website to user
  • 16. Next Steps Key Dates: Dates Activities 9/14 - 9/26 Product testing Pilot deployment preparations 10/6 Application deployment (bdoulx023) 10/10 - 10/31 Pilot to selected business units Technical support and fixes as needed Performance testing and tuning parallel to pilot (bdoulx024) Bank-wide rollout and timeline will be decided after the pilot.
  • 17. Q&A ?
  • 18. Application Architecture Roadmap User ID RT 3 ID Administrator Password 5 Business Website Generator Application 8 7 4 1 User BU User ID 9 Approver DB Approver DB 6 User ID Website BU 2 10 Requestor 11 Windows Active Directory Approver 2a User Demand Process Deliver Password
  • 19. Application Architecture Roadmap User ID RT 3 ID Administrator Password 5 Business Website Generator Application 8 7 4 1 User BU User ID 9 Approver te 3 ase DB ara DB Approver p Se ject Ph 6 User ID Website BU Requestor 2 pro 10 2 se 11 a Windows PhApprover Active Directory 2a User Demand Process Deliver Password

Editor's Notes

  1. -