Presentation is loading. Please wait.

Presentation is loading. Please wait.

National Australia Group (UK) With Hindsight!. Rules of Engagement If you have a question… raise your hand. If you are shy… speak to me later or drop.

Similar presentations


Presentation on theme: "National Australia Group (UK) With Hindsight!. Rules of Engagement If you have a question… raise your hand. If you are shy… speak to me later or drop."— Presentation transcript:

1 National Australia Group (UK) With Hindsight!

2 Rules of Engagement If you have a question… raise your hand. If you are shy… speak to me later or drop me an email at: Stephen.Swann@eu.nabgroup.com

3 About the National The Group is an international financial services organisation that provides a comprehensive and integrated range of financial products and services. Our Purpose Growth through excellent relationships. Our Vision We will be a leading international financial services company which is trusted by you and renowned for getting it right. STRATEGIC OVERVIEW Deliver solutions that help meet customer’s complete financial needs Build and sustain a high level performance culture Build trusted relationships with all stakeholders Build and manage our portfolio of businesses for strong and sustainable total shareholder return Create and leverage strategic assets and capabilities for competitive advantage

4 So You’re Australian, right? National Australia Group’s UK interests include: Clydesdale Bank Yorkshire Bank. National Australia Bank (London) The UK division has its own Technology team based in development centres in Glasgow (Scotland) Leeds (England) Belfast (Northern Ireland) More information can be found at www.nabgroup.com

5 NAG’s Applications Retail Internet Banking (J2EE) Branch Teller System (WSBTT) Maintenance/Enquiries System (J2EE) Sales & Illustration System (Siebel) eMail System (iNotes) Provisioning System (ITIM) Adobe Print Servers/Archivers I.M.M.P.s

6 NAG’s Applications 3270 Access to mainframe Client/Server Applications -Visual Basic -C/C++ -Access -Java

7 NAG Project Methodology & Success Criteria PhaseBusiness ProcessIM Technology Success Criteria Phase 1 (2003) Front End Replacement Common authentication & authorisation service for J2EE application, Siebel and iNotes Tivoli Access Manager/eTrust Directory Reduction in UserIDs & Passwords Phase 2 (2004) New Application Rollout New applications protected by security architecture Tivoli Access Manager/eTrust Directory Reuse of UserIDs & Passwords Phase 3 (2005) Internet Banking Programme Reuse of security architecture for customer interfaces Tivoli Access Manager/eTrust Directory Creation of internet facing infrastructure Phase 4 (2006) Teller Replacement Account ManagementTivoli Identity Manager Self-Password Reset & Provisioning Phase 5 (2006) 3 rd Party Integration Single Sign-On from company intranet to internet applications hosted by trusted 3 rd Parties Tivoli Federated Identity Manager Reuse of UserIDs & Passwords We are here

8 The Final Picture

9 Phase 1 Administrator End Users (500) WebSEAL Application Directory Phase 1 - 2003 -500 Users -3 Protected Applications -“Manual” Scripted Provisioning

10 Phase 2 Auditor End Users (260,000) WebSEAL Applications Directory ITIM Phase 4 - 2006 -260,000 Users -Many Protected Applications -Internet Banking Protected -Automated Provisioning

11 NAG’s User Base & Tivoli Products Web based access control for staff based applications 10,000 staff across hundreds of retail outlets and Head Office locations. Web based access control for customer based applications 250,000 Internet Banking customers ( -> 700,000 by Dec. 06) Applications Protected 14 Web based applications (including Internet Banking) The Tivoli Products in use are: Tivoli Access Manager v5.1Tivoli Identity Manager v4.5.1 Tivoli Directory Server v5.2Tivoli Directory Integrator v6.0

12 Real World v Utopia IM TEAM Real World Many Project Managers By-Pass Identity Management Major programmes forced to use Identity Management (& pick up cost) Technology Risk & Auditors have limited involvement Service Delivery not involved Utopia Policies & Principles in place; CEO/CIO sponsorhip in place All Project Managers embrace Identity Management Technology Risk & Auditors involved in design process Service Delivery integrated into the process Policies/Principles CEO Mandate Project Managers Tech Risk/Auditor Service Delivery

13 If We Had It All To Do Again… Identity Management Programme Create an Identity Management programme rather than relying on projects to fund the infrastructure Create strategy for future utilisation of infrastructure (rather than deployment by stealth Create the architectural policies, principles and guidelines up-front Deploy a provisioning solution up-front Enterprise Support Get Leadership Team sponsorship – both Business Sponsorship (CEO?) and Technology (CIO?) Engage Audit and Technology Risk teams earlier in the design phase Management Tools Spend additional time working on Configuration Management; Log File Management; Auditing Capabilities and infrastructure monitoring(!)

14 If We Had It All To Do Again… Pay our full-time employees a lot more money!

15 Will We Achieve Our Aims? Tivoli Access Manager for eBusiness YES TAMeb is well integrated into our infrastructure Performance is good & Reliability is good – “despite what they say” Enhances productivity – Java developers no longer need worry about security Tivoli Identity Manager YES Work is required to fully understand the organisational structure Provisioning new target platforms required to fully embed the product in the infrastructure Would greatly enhance productivity; reduce costs and free up resources – benefits, however, still to be realised Other Tivoli Security Products Tivoli Federated Identity Manager is a good fit for us but we are waiting on other 3 rd parties to catch up with the technology!

16 THANK YOU National Australia Group’s Hindsight


Download ppt "National Australia Group (UK) With Hindsight!. Rules of Engagement If you have a question… raise your hand. If you are shy… speak to me later or drop."

Similar presentations


Ads by Google