Showing posts with label enforced. Show all posts
Showing posts with label enforced. Show all posts

Friday, February 24, 2012

Cell Security : Help

SECURITY USING CELL-SECURITY:

From what i've read cell security s enforced on the client. If someone is able to gain access to a machine running the client (for example an application server or a web server) he is able to get cell values independently of the fact that those values will be defined as #N/A in the secured cell value property. The real value is travelling between theAnalysis Server and the application server. Is this true ? How can we effectively garantee true security ?Did you look in BOL?

Cell Security
In a cube role, you can implement cell security to limit the cube cells that end users in the role can view as they browse cubes. You can also grant read/write access to a write-enabled cube and limit the cells that end users in the role can update. You do this by selecting a policy and by selecting a rule or defining a custom rule for each permission.

Cell security is optional. If you do not specify cell security, end users see all cell values in cubes they are authorized to access. (However, if dimension security is specified, cells for some members might not be viewable.) If a cube is write-enabled, end users cannot update cell values. If one or more of a virtual cube's component cubes are write-enabled, end users cannot update the cell values of virtual cubes.

If a policy or rule permits updates to a cell, it can be updated if it is an atomic cell. If the cell is not atomic, it can be updated only if the client application provides a way of dispersing the update over the subordinate atomic cells. For example, in a client application a write-enabled cube is displayed with the lowest level of every dimension except Time. On the axis for the Time dimension, the nonatomic cells for months are displayed, but the subordinate atomic cells for days are not. (Days is the lowest level in the Time dimension.) A cell for June can be updated by adding $90 if the client application provides a way of dividing the +$90 update into thirty +$3 updates, one to each of the cells for the 30 days in June. Dispersion methods other than simple division can also be used. The UPDATE CUBE statement provides several methods. For more information, see UPDATE CUBE Statement.

Sunday, February 19, 2012

CC and SSN encryption

All,
Is there any law enforced by regulatory bodies to encrypt
1.Credit Card info
2. SSN
I need some document on it, which I can use for my presentation to my
management. Any US Bill's text can also be usefull.
TIAThe following is a FAQ concerning the PCI and CISP standards for encrypting
CC numbers.
http://www.patownsend.com/VisaPCI-CISP.htm
Federal legislation such as SOX, HIPAA and GLBA also have regulations for
how such information is stored and how it can be shared with 3rd parties.
However, some of these regulations, such as SOX compliance, only apply to
publicly held companies.
"Kay" <CallDBA@.hotmail.com> wrote in message
news:OrmvCxc%23FHA.2608@.tk2msftngp13.phx.gbl...
> All,
> Is there any law enforced by regulatory bodies to encrypt
> 1.Credit Card info
> 2. SSN
> I need some document on it, which I can use for my presentation to my
> management. Any US Bill's text can also be usefull.
> TIA
>|||It can depend on what type of data it is. For example, if these are SSN in
medical records or health care claims, then HIPAA regulations would be in
effect. There can be other industry specific regulations such as banking,
etc. I don't know of any general encryption requirements in any law for the
storage of data.
Usually if there is a law, it requires the keeper of the data to protect
access to the data. Other laws such as HIPPA go a bit futher and require yo
u
to log who, what, where, when and how the data was accessed.
Hope that helps,
Joe
"Kay" wrote:

> All,
> Is there any law enforced by regulatory bodies to encrypt
> 1.Credit Card info
> 2. SSN
> I need some document on it, which I can use for my presentation to my
> management. Any US Bill's text can also be usefull.
> TIA
>
>|||Basically data is related to eLearning. So what Law says about this domain?
-Kay
"Joe from WI" <JoefromWI@.discussions.microsoft.com> wrote in message
news:2FF1EDD3-0070-4106-AD4E-3A43C591250F@.microsoft.com...
> It can depend on what type of data it is. For example, if these are SSN
> in
> medical records or health care claims, then HIPAA regulations would be in
> effect. There can be other industry specific regulations such as banking,
> etc. I don't know of any general encryption requirements in any law for
> the
> storage of data.
> Usually if there is a law, it requires the keeper of the data to protect
> access to the data. Other laws such as HIPPA go a bit futher and require
> you
> to log who, what, where, when and how the data was accessed.
> Hope that helps,
> Joe
> "Kay" wrote:
>|||Basically data is related to eLearning.
-Kay
"Joe from WI" <JoefromWI@.discussions.microsoft.com> wrote in message
news:2FF1EDD3-0070-4106-AD4E-3A43C591250F@.microsoft.com...
> It can depend on what type of data it is. For example, if these are SSN
> in
> medical records or health care claims, then HIPAA regulations would be in
> effect. There can be other industry specific regulations such as banking,
> etc. I don't know of any general encryption requirements in any law for
> the
> storage of data.
> Usually if there is a law, it requires the keeper of the data to protect
> access to the data. Other laws such as HIPPA go a bit futher and require
> you
> to log who, what, where, when and how the data was accessed.
> Hope that helps,
> Joe
> "Kay" wrote:
>|||Basically data is related to eLearning. So what Law says about this domain?
-Kay
"Joe from WI" <JoefromWI@.discussions.microsoft.com> wrote in message
news:2FF1EDD3-0070-4106-AD4E-3A43C591250F@.microsoft.com...
> It can depend on what type of data it is. For example, if these are SSN
> in
> medical records or health care claims, then HIPAA regulations would be in
> effect. There can be other industry specific regulations such as banking,
> etc. I don't know of any general encryption requirements in any law for
> the
> storage of data.
> Usually if there is a law, it requires the keeper of the data to protect
> access to the data. Other laws such as HIPPA go a bit futher and require
> you
> to log who, what, where, when and how the data was accessed.
> Hope that helps,
> Joe
> "Kay" wrote:
>|||I don't see how SSN and credit card numbers could be related to eLearning;
except perhaps in a peripheral way when the user pays for the service, but
that would be more related to eCommerce.
"Kay" <CallDBA@.hotmail.com> wrote in message
news:e$V2GUm%23FHA.1032@.TK2MSFTNGP09.phx.gbl...
> Basically data is related to eLearning. So what Law says about this
> domain?
> -Kay
> "Joe from WI" <JoefromWI@.discussions.microsoft.com> wrote in message
> news:2FF1EDD3-0070-4106-AD4E-3A43C591250F@.microsoft.com...
>
>|||Just like Jay, I don't see what SSN and CC have to do with eLearning.
If you are accepting credit cards for payments, you may be bound by your
credit card agreement. I don't know of any federal law relating to
eCommerce. Now, if you're a financial instition, credit card company, etc.,
that's a whole other story.
I suggest you contact the financial institution that services your merchant
account or the company that handles your credit card processing for specific
rules.
BTW, I coded an ecommerce site that used a third party credit card
processing company. All we stored in the database was the last four digits
of the cc number and the approval code. The secured web pages, cc
processing, etc. took place at the third party site.
If there is a law either now or in the future, it will undoubtly be like
HIPPA. You'll have to have comprehensive written procedures outlining how
you protect confidential information from access to the physical hardware
(how do you control who enters the computer room? do they have to swipe a
badge in and out? etc.), how you handle backup media? are tapes are stored i
n
a bank vault or secure location?, network security (each user has a separate
login with a strong password?), database security, table security, column
security, stored procedure execution rights, etc. Who can access the data,
how do they access the data, when do they access it (i.e. audit log of who
accesses cc, ssn, etc., when, how, for what purpose.) If you encrypt data,
how do you do it? Do you use keys? Where are the keys kept? How often do
you review internal procedures and training of personal?
An example is: User \\Wkstn1\JDoe ran stored procedure usp_Select_All_CC on
12/05/2005 at 1:45 PM at ip address 192.168.1.101 using application "Credit
Application".
Get the jist? Most laws require you to prove that you were taking
reasonable precautions to protect and safegaurd the data. Treat ssn, cc,
etc. like you would salary information. Would you want your salary in a
table that anyone could access on the server by running a simple query?
Probably not. Salary information is usually stored in a separate table,
sometimes in a separate database, and in larger companies often stored on a
separarte computer. Usually only authorized people are allowed to access
salary information and usually only for "approved" purposes or bonifide
business reasons--not just because they are curious about what someone is
making.
Hope that helps,
Joe
"Kay" wrote:

> Basically data is related to eLearning. So what Law says about this domain
?
> -Kay
> "Joe from WI" <JoefromWI@.discussions.microsoft.com> wrote in message
> news:2FF1EDD3-0070-4106-AD4E-3A43C591250F@.microsoft.com...
>
>