Creating Customer Portals with Sensitive Personal Data without Compromising Security
Facebook Twitter LinkedIn

Creating Customer Portals with Sensitive Personal Data without Compromising Security

Combined Session
Wednesday, May 15, 2013 11:30—12:30
Location: AMMERSEE 2

Creating Customer Portals with Sensitive Personal Data without Compromising Security

This is a real life case study about how CSS implemented the security for a customer and sales portal using a Federated Identity Provider, 2 factor SSO with SAML, and attribute based access control on the SOA mediator between portal and backend using XACML.

CSS has a well established SOA backend with Role Based Access Control: Employees are assigned to one or more roles, based upon which access to varying levels of customer data is granted. However, when opening up such an IT system to customers via an online portal, access control becomes a more delicate issue. If customers are to gain access to only their and their dependent family´s data, a new layer of security is required to protect sensitive data in the backend.

You´ll gain insight in to some of the implementation issues we had along the way and how we overcame them.

Creating Customer Portals with Sensitive Personal Data without Compromising Security
Presentation deck
Creating Customer Portals with Sensitive Personal Data without Compromising Security
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Sebastian Goodrick
Sebastian Goodrick
CSS Versicherung
Sebastian Goodrick is the head of IT Security and Identity Management at CSS Versicherung, the largest health insurance provider in Switzerland. He has worked with mobile phone anti-virus solutions...

G4S Bulgaria: Identify and Protect Critical Information and Prevent Data Leaks

For organizations that deal with sensitive information on a daily basis, and work with people and organizations located around the world, preventing information leaks is a top priority. There are many ways that sensitive data can leak from organizations, however the insider threat remains the hardest to quantify and resolve.

G4S discovered that before they could improve their data loss prevention efforts and effectively protect sensitive information, they needed to be able to answer other significant questions about the data itself, including:

In this session, Boris Goncharov, CISO and CTO with G4S Bulgaria and TITUS Chief Technology Officer Stephane Charbonneau will discuss specific ways in which organizations can improve their DLP practices in order to help prevent both accidental and malicious losses of sensitive information.

Stephane Charbonneau
Stephane Charbonneau
TITUS
Stephane Charbonneau serves as Chief Technology Officer for TITUS. His background as an IT Security Architect helps bridge the gap between customer requirements and the product suites offered by...
Boris Goncharov
Boris Goncharov
G4S Secure Solutions Bulgaria EAD
IT & Information Security Manager of G4S Bulgaria with more than 12 years in the Information Security, Risk Management and IT Governance areas. Experienced in Information Security strategic...
Subscribe for updates
Please provide your email address