Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

security questions

Status
Not open for further replies.

MissReportNet

Programmer
Dec 11, 2005
29
0
0
NL
Hi,

For authorisation and security issues the business has asked me to write some questions so they can discuss about the issue.

The security will be set top down and bottom up and line and based on capabilities, hierarcie, roles.


The only questions i realised is,
- who can see what

Can someone please help me out!!

Thx in advance!!

Regards,

MissReportNet

 
Hi MissReportNet,

Here are some questions around security that randomly occur to me:

1. Which packages will users/groups/roles be granted access to use?
2. Within a package, what filtering is required to limit the rows returned for each user/group/role?
3. Within a package, which objects (Query Subjects, Query Items) will need to be visible/hidden for each user/group/role?
4. Within Cognos Connection, what capabilites are required by each user/group/role? (ie which studio(s) will be available, which admin tools etc)
5. Within Cognos Connection, what permissions are required on each folder/report for each user/group/role (ie which reports are hidden, can be viewed, can be run, can be modified etc)
6. Which users need to belong to multiple groups/roles? If this is implemented, will the users be given the sum of their privileges based on their group memberships, or the sum of their restrictions?
7. Which authentications source(s) will be required?
8. How do connections to these sources need to be defined?
9. Will anonymous access be allowed?
10. If so, what privileges will the anonymous users require?
11. Is single-signon required?
12. Are secure sockets required?
13. If so, which ssl database will be used?
14. Is the standard 40-bit encryption strong enough for your business?
15. If not, which encryption provider will you use, and what strength?

I'm sure there are many more, but my fingers ache! :)

Hope that helps,

MF.

 
Hi MF,

Thanks, i am sorry about your fingers :). The questions i need has to be functional, some of what you have writen are functional like nr. 3,4,5,6,9,10 others are more technical questions. Can you come up with more functional issues?

Thx!!

Kind regards,

MissReportNet
 
One of the simplest questions you need to ask, is "how" the data needs to be secured or does it need to be secured. If it does, then you can start asking more in depth questions like mfgf brought up.
 
Hi CognosChicago,

In our datamart we also have security tabels. I am also thinking to hire a dba to set authorisation en security at data level. Do you now or have more info about what a dba can do for us?

Thx!!

MissReportNet
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top