The Preliminary Specification Part XXXI (S&AC Part IV)
Looking at the security aspects of the Security & Access Control module we find that today’s technologies provide levels of security that are substantially higher then just a few years ago. With the security needs of the industry being so high, I believe the following security policies would be more then satisfactory to those needs. And it is suggested that these are the base case, as time passes we will be able to build on these specifications.
For people to be available online anytime and anywhere presents problems from the point of view of authentication. What we can do is ensure that only registered devices have access to the applications, information and data. These devices would include desktop computers, notebooks, phones and iPads etc. Where only certain registered devices on certain IP addresses are available to access the People, Ideas & Objects applications. In addition user name and password protection for access would be required. But in addition, we would require two step authentication where we text a code to their registered company phone, which would then have to be keyed into the device they were trying to log into. These three steps ensure that only authorized users were gaining access to the system.
Next we would ensure that all network traffic was encrypted. It has not been determined as of yet how the application will be presented to the users (browser or otherwise). However, once logged out of the system all data and information will be cleared from the cache and the device will have no information or data stored of the session. It should be noted that one of the advantages of the tools that we are using is that we should be able to present to the user the same desktop environment that they had left when they last logged out.
In our Hardware Policies and Procedures we have discussed how the People, Ideas & Objects application is hosted. This separate company is proposed to be jointly owned by industry, People, Ideas & Objects and Oracle. It is also proposed to be operated by the oil and gas industry primarily to meet their needs of maintaining the control they need for SEC regulatory compliance of their ERP systems. With industry having de-facto control of the “Cloud” infrastructure. This provides them with the means to maintain the physical control necessary to maintain their SEC needs. People, Ideas & Objects will be able to deliver a runnable binary of the application for them to operate without the need to be physically on-site.
And as I mentioned the other day it was an oversight that the Draft Specification initially indicated that the data storage and data base systems were not encrypted. Oracle provides high levels of encryption of both the storage medium and the database, at the data level itself. This will in turn provide no one at the industry operated cloud infrastructure with the ability to read any of the producers confidential data or information.
Implementing the technologies in this fashion will provide the industry with the security that they need to ensure that their data and information remains secure. These technologies are only the beginning of what will be implemented in the People, Ideas & Objects Security & Access Control module as they are all standard fare for the base level technologies used in Oracle. It is a simple manner of selecting them for use.
For the industry to successfully provide for the consumers energy demands, it’s necessary to build the systems that identify and support the Joint Operating Committee. Building the Preliminary Specification is the focus of People, Ideas & Objects. Producers are encouraged to contact me in order to support our Revenue Model and begin their participation in these communities. Those individuals that are interested in joining People, Ideas & Objects can join me here and begin building the software necessary for the successful and innovative oil and gas industry.
Please note what Google+ provides us is the opportunity to prove that People, Ideas & Objects are committed to developing this community. That this is user developed software, not change that is driven from the top down. Join me on the People, Ideas & Objects Google+ Circle and begin building the community for the development of the Preliminary Specification. Email me here if you need an invite.