Security and Authorization
Reviews
Maintain full control of system access
Over time, as employees change roles, change
responsibilities, are hired and leave, systems are exposed to
numerous security risks. While external threats to customer
data tend to capture attention, inappropriate access by employees,
whether deliberate or accidental, actually represents a greater
risk in terms of customer/member service, financial loss, audit
exposure and regulatory comment. By undertaking a periodic analysis
of your Security and Authorization structure, you can ensure
access to customer data is tightly controlled within the
system.
Our Process
The Security and Authorization review includes a series of
four workshops with management and staff. These workshops
ensure that your institution understands all the capabilities
of TCBS Security and Authorizations. They take place
over a three-day period and consist of the following activities:
I.
System Security Overview
We ensure that all appropriate personnel understand how
the system security works, the key decisions to be made and
the effect of those decisions. This workshop includes security
theory, authorization structure, authorizations and cashboxes,
supervisor override authorizations, transaction exceptions,
lockout flags and bank options.
II. High Level Design
We guide your institution through defining an overall authorization
structure. This includes defining authorization levels and
determining functionality requirements for each authorization
level.
III. Authorization Level Design Sessions
We guide you through the creation of a detailed authorization
structure for your test database. Executable applications are
assigned to each authorization and detailed structures are
determined for each authorization level.
IV. Supervisor Override
Processing
Clients are advised on the appropriate number of supervisor
override authorization levels and their application to individual
exceptions. We review the Transaction Exception table to
assign an appropriate level of override for each exception
set.
Our consultants also assist during the testing
process – reviewing test results, recommending changes and helping
coordinate migration of revised authorizations from the
test environment to production.
Outcomes
Security and Authorization Reviews ensure that each system user
has access only to data and transactions necessary to execute
his or her responsibility. Open Solutions Professional Services
works with clients to restructure the security and authorizations
of each job function.
Pre-Conversion
Best Practices | Operational Reviews
Security
and Authorization Reviews | CRM and Business Intelligence Services
Revenue
Enhancement Initiatives | Platform and Infrastructure Services
Client
Testimonials | Contact
Us
|