MSAMM
Back to course

Implementing Global HR: From Enterprise Model to Live Workforce · Module 2 · Security and Role Provisioning

Data protection by design

Lesson 19 of 175 · 5 min

Here is the principle, and everything else follows from it. The system should make it structurally difficult to see data you have no business reason to see. Not "against policy", not "logged and reviewed" — difficult, as in the data is not in your list, the record does not open, the field is not populated. Security profiles are what that principle is implemented with; this lesson is the intent behind the mechanism. Five questions to take into a design workshop. Who genuinely needs to see national identifiers, and should they be masked for everyone else? Note "genuinely": the answer is almost always a much smaller group than the one with access today. Which countries' data can cross borders, and does the design respect that? A global HR team with visibility of everyone may be a transfer that needs a basis. Who can see document records, and which types? Document records

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Implementing Global HR: From Enterprise Model to Live Workforce, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 2 · Security and Role Provisioning

  1. 1Why HCM security is different
  2. 2Security profiles: the six types
  3. 3Building person security profiles
  4. 4Organization, position and LDG profiles
  5. 5HCM data roles
  6. 6Areas of responsibility
  7. 7User and role provisioning
  8. 8Data protection by design
  9. 9What breaksFree preview
  10. 10Lab: build the security model for four countries