Customer Snapshot: Financial Services

CCS Česká společnost pro platební karty s.r.o.

Financial Services Company Centralizes User Administration with Sun Java System Identity Manager

CCS Česká společnost pro platební karty s.r.o. is a fleet card provider and operator in the Czech Republic. It manages company payment cards and loyalty programs as well as payment and assistance cards for individuals. In addition to providing supplies hardware and software for card technologies, CCS provides logistic management, car pool management, and company car fleet cost services. Founded in 1991, CCS has been a subsidiary of FleetCor Technologies since October 2006.

Customer Challenges

  • Centralize management of user accounts across multiple systems
  • Decrease security risk of dormant accounts
  • Prepare for expansion of the IT infrastructure
  • Establish processes for auditing user accounts

Solution

CCS chose Sun Java System Identity Manager to centralize its user administration and provisioning system. The solution ensures end-to-end security and provides accountability of user access to internal resources. CCS automated many processes that were previously done manually and implemented the solution with minimal disruption to existing processes.

Business Results

  • Streamlined user provisioning process
  • Achieved transparency of user accounts across all systems
  • Adapted access policies to align with the customer's organizational structure
  • Simplified and documented security audits

Story Details

CCS Česká společnost pro platební karty s.r.o. plays a significant role in the noncash purchases market in the Czech Republic. The company is the largest nonbanking processor of card transactions in the Czech Republic, administering more than 300,000 specialized cards designed for purchasing products and services related especially to automobile travel. Individuals who hold loyalty cards receive exclusive offers for special rewards, products, and discounts. The company uses a “flexible acceptance network” that helps increase the number of places its cards are accepted.

In 2005, CCS wanted to expand its IT infrastructure and deploy new systems and applications, but it was difficult for IT administrators to manage and audit access to user accounts and resources across multiple systems. Many dormant user accounts remained in the system long after employees had left the company. Administrators also had to create many special user accounts and make frequent changes to existing accounts, all of which had to be monitored manually. In addition, new legal requirements concerning privacy and data security made it critical for CCS to be able to audit its user access and security policies.


" Implementation of Sun Identity Manager helped us to increase security of our IT environment by centralizing user management, and aligning organizational structure with user accounts and access rights. Automatization of processes associated with user maintenance save valuable time of our system administrators. "
— Michal Šrámek, IT Operations Manager, CCS

To solve these challenges, CCS decided to centralize its user account administration. Security was a primary consideration, and any changes to the infrastructure had to be accomplished without increasing operating expenses. The company’s primary requirement was to maintain existing standard processes while automating as many tasks as possible, thus contributing to higher overall efficiency of user provisioning and management.

CCS needed individual access control for various data resources at the group and account level. It also required immediate discovery, modification, cancellation, and audit capabilities for all user access privileges across as many resources as possible. In addition, it was imperative that CCS be able to provide accountability for user access to specific software systems. To position itself for future large-scale operations, CCS wanted to deploy a robust, proven platform. From a software infrastructure perspective, the new solution needed to be adaptable to current CCS capabilities.

After assessing potential solutions, CCS selected Sun Identity Manager, which makes it possible for administrators to securely and efficiently manage and audit access to accounts and resources. The implementation was a collaborative effort between Sun partner AMI Praha a.s. and Sun distributor Avnet Technology Solutions.

At the heart of the user management system is a provisioning server that communicates through adapters with managed resources (such as user accounts and access rights) that are stored on target systems. Communication is handled using native protocols of the various systems and also through industry standard protocols such as Java Database Connectivity (JDBC), Lightweight Directory Access Protocol (LDAP), and Secure Socket Shell (SSH). The target systems required almost no modification, and user accounts, including their associated privileges, remained in the original system repositories. Sun Identity Manager creates a single, virtual identity that maps to disparate resources. This makes it possible for administrators to manage users as a single entity, and if Identity Manager were to become unavailable, access to individual systems would not be disrupted.

For fundamental user administration processes (such as Creates, Changes, and Deletes), CCS defined and implemented automated workflows. When a new employee is entered into the human resources system, the user creation process is automatically triggered. Sun Identity Manager detects the new user and, based on his or her assigned organizational unit and role, establishes the user’s access privileges to specific applications. Manual intervention is required only when a user’s access privileges to certain systems requires special approval.

During the implementation phase of the project, CCS developed and deployed a new adapter for user management within CommuniGate, an Internet server and email system from Stalker Software. Sun Identity Manager’s direct logging and auditing capabilities fully covered the needs of CCS in the area of user management. The implementation, begun in late 2005, was completed in May 2006.

For CCS, the entire user provisioning process has been greatly simplified with the Sun Identity Manager. From one location, administrators can establish user identity across multiple systems, and they now have comprehensive visibility over active and inactive user accounts. Because CCS adheres to stringent definition and assignment of roles, system access is now fully aligned with the company’s organizational structure. Automated workflow helps to minimize errors and omissions in various user account and privilege administration processes. With a centralized user administration solution, security audits are far simpler to perform and the results are conclusive. The Sun Identity Manager is an open and robust platform that CCS can link with other systems in the future, enabling CCS to operate systems with many more users.

  
 
Interested in Sun's Open Storage?
Download this paper today to learn about the tools, trends and key features of Sun's Open Storage solutions.