Creating Customer Portals with Sensitive Personal Data without Compromising Security
Facebook Twitter LinkedIn

Creating Customer Portals with Sensitive Personal Data without Compromising Security

Combined Session
Wednesday, May 15, 2013 11:30—12:30
Location: AMMERSEE 2

This is a real life case study about how CSS implemented the security for a customer and sales portal using a Federated Identity Provider, 2 factor SSO with SAML, and attribute based access control on the SOA mediator between portal and backend using XACML.

CSS has a well established SOA backend with Role Based Access Control: Employees are assigned to one or more roles, based upon which access to varying levels of customer data is granted. However, when opening up such an IT system to customers via an online portal, access control becomes a more delicate issue. If customers are to gain access to only their and their dependent family´s data, a new layer of security is required to protect sensitive data in the backend.

You´ll gain insight in to some of the implementation issues we had along the way and how we overcame them.

Creating Customer Portals with Sensitive Personal Data without Compromising Security
Presentation deck
Creating Customer Portals with Sensitive Personal Data without Compromising Security
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Sebastian Goodrick
Sebastian Goodrick
CSS Versicherung
Sebastian Goodrick is the head of IT Security and Identity Management at CSS Versicherung, the largest health insurance provider in Switzerland. He has worked with mobile phone anti-virus solutions...
Subscribe for updates
Please provide your email address