|
Level I -
Logon Protection Once the
bioLock technology is installed via transports in the SAP System, the
first step customers take is to protect the logon to the SAP User
Profile for their critical Power Users. In addition to the logon
and the password these selected Power Users have to put their finger on a
biometric device to uniquely verify their identity, when logging on
with their SAP User profile. For the first time, you can check their
true identity and you can make sure that
only "Joe" can log in with "Joe's" SAP User ID. Level
II - Transaction Protection As
a next step, you can protect any transactions on the transaction level.
When a protected transaction, e.g., a purchase order
transaction is executed, the user has to put their finger on the sensor
again. bioLock will first check if it can identify the person. Then,
it will check what SAP User Profile this person is logged in as and if
the person is authorized to use this profile (for example, an
administrator's or a superior's profile). Last, it will authorize or
reject the request based on the biometric template. Level
III - Fields and Infotypes bioLock
allows you to protect fields or infotypes on the field level. One example, in HR
hundreds of 3-digit Infotypes call an HR sub menu.
Individual infotypes (for example 008 Basic Pay) can be
protected individually. You can also protect buttons, for example, printing
or executing a function and even checkmarks. When a check mark is
checked or unchecked a biometric verification could be required. Level
IV - Field Values It is possible
to implement the biometric verification in combination with a
predefined value. A good example would be a predefined amount for an outgoing wire transfer of $10,000. All users can issue wire transfers
based on their SAP authorization without any biometric verification,
but as soon as the entered amount exceeds $10,000 a biometric
verification will be required. The system could be set up so that 10
users, based on their SAP user profile, can issue wire transfers, but
only the department head can issue transfers exceeding the predefined
amount - all others will be rejected based on the biometric template. Level
V - Two Signatures on a Check With
internal fraud on the rise and mandatory regulations demanding
enhanced controls, it is becoming more important to have two individuals
sign off on extremely critical tasks. At most companies, it has long
been an established practice that
two signatures are required for high value checks.
bioLock brings this functionality to the SAP workflow. Any biometric door lock
(all scenarios described above) can be protected either with a single
biometric template or with a dual confirmation group. In this group
there could be two or more templates, so two users would have to put their finger
on the sensor to execute the protected task. The system could even be
set up so that only one user could request the protected task
and all others can only confirm the task. Conclusion:
|
bioLock is the first and only
certified biometric technology available for SAP. bioLock will
allow a company to ensure that only the actual authorized user
can use the assigned SAP User Profile. Furthermore, bioLock will
protect individual functions in the system (in case the
authorized user leaves without logging out of the system).
Unauthorized users will always be rejected even when walking up
to an open computer. Most importantly, bioLock will
not only uniquely identify the actual user, but will also log in a log file,
which actual user - uniquely identified via biometrics - has
actually executed a task or was rejected trying to execute a
task without being authorized. The log file will give the
business managers and auditors the ultimate knowledge and
control about what is going on in their SAP System. Please
check out this document to understand this simple security
concept in an easy comparison and learn, how bioLock will help
maintaining the integrity of your SAP data (pdf). |
|
|
|