WP#4 - HCM Delivered Masking of PII Data
Purpose: As part of the Work Package #4 - Masking of PII Data the ctcLink Security Support Team researched how to activate delivered masking, provided by Oracle. By updating the implementation settings the team was able to turn on delivered masking and prevent the viewing of highly sensitive data on those pages, unless a specific security role is granted enabling the viewing of this sensitive data.
Audience: HCM Support Team performing Functional Testing, Local Security Administrators and HR Staff participating in User Acceptance Testing.
It is recommended during testing to first navigate and confirm the masking using a User Profile with no unmasking roles, then have an HR staff person test the same navigational paths with the unmask all role. Finally, have one or more HR staff test without the unmasking all role, but rather with the individual field masking role applied.
The following navigational paths will have Oracle delivered masking turned on to mask Category 4 data for all records:
Navigation: Main Menu>Benefits>Employee/Dependent Information>Update Dependent/Beneficiary
On the Personal Profile tab, in the National ID section the National ID field is masked, with only the last 4 digits of each of the employee's dependents/beneficiaries. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).
The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Payroll for North America>Employee Pay Data USA>Request Direct Deposit
On the Request Direct Deposit page, in the Distribution section the Account Number field is masked, with only the last 4 digits of the account number visible.
The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Payroll for North America>Payroll Processing USA>Produce Payroll>Review Paycheck
On the Review Paycheck page, click the Paycheck Deductions tab, and in the Net Pay Distribution section the Account Number field is masked, with only the last 4 digits of the account number visible.
The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Payroll for North America>Payroll Processing USA>Produce Payroll>Review Self Service Paycheck
On the Review Self Service Paycheck page, in the Net Pay Distribution section, the Account Number field is masked, with only the last 4 digits of the account number visible.
The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Workforce Administration>Personal Information>Biographical>Driver's License Data
On the Driver's License Data page, in the Driver's License Information section the Driver's License Nbr field is masked, with only the last 4 digits of the number visible.
The Local Security Administrator would need to apply the ZZ HC Unmask Drivers License security role to unmask the specific Driver's License Nbr field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Workforce Administration>Personal Information>Biographical>Update Person Detail
On the Biographical Details tab, in the National ID section the National ID field is masked, with only the last 4 digits of the employee's Social Security Number displayed. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).
The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Workforce Administration>Personal Information>Citizenship>Citizenship, Visa and Permits
On the Citizenship/Passport tab, in the Citizenship/Passport section the Passport Number field is masked, with no digits of the employee's passport number displayed:
On the Visa/Permit Data tab, in the Visa/Permit History section the Number field is masked, with no digits of the employee's visa permit number displayed:
The Local Security Administrator would need to apply the ZZ HC Unmask Passport security role to unmask the specific passport or visa/permit field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Workforce Administration>Personal Information>Modify a Person
On the Biographic Details tab, in the National ID section the National ID field is masked, with only the last 4 digits of the employee's SSN displayed. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).
The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.
Navigation: Main Menu>Workforce Administration>Personal Information>Personal Relationships>Dependent Identification
While this page has been included in HCM masking delivered masking set, it is unlikely that colleges will have data on this page as it is not a standard business practice to collect the passport and/or visa permit data for dependents.
On the Depdnt Citizenship/Passport tab, in the Passport Details section the Passport Number field is masked, where no digits of the passport number of the dependent of the employee are displayed:
On the Depdnt Visa/Permit Data tab, in the Visa/Permit History section the Number field is masked, where no digits of the visa permit number belonging to the dependent of the employee are displayed:
The Local Security Administrator would need to apply the ZZ HC Unmask Passport security role to unmask the specific passport or visa/permit field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM Unmask PII Data security role.











0 Comments
Add your comment