WP#4 - HCM Masking of PII Data

Purpose: As part of the Work Package #4 - Masking of PII Data the ctcLink Security Support Team researched how to activate delivered masking, provided by Oracle. By updating the implementation settings the team was able to turn on delivered masking and prevent the viewing of highly sensitive data on those pages, unless a specific security role is granted enabling the viewing of this sensitive data. One field was not covered in delivered masking, so the Page & Field configurator was used to mask the visa permit number.

Audience: HCM Support Team performing Functional Testing, Local Security Administrators and HR Staff participating in User Acceptance Testing.

It is recommended during testing to first navigate and confirm the masking using a User Profile with no unmasking roles, then have an HR staff person test the same navigational paths with the unmask all role. Finally, have one or more HR staff test without the unmasking all role, but rather with the individual field masking role applied.

The following navigational paths will have Oracle delivered or applied (via Page & Field Configurator) masking turned on to mask PII data for all records:

Expand or collapse content Update Dependent/Beneficiary

Navigation: Main Menu>Benefits>Employee/Dependent Information>Update Dependent/Beneficiary

On the Personal Profile tab, in the National ID section the National ID field is masked, with only the last 4 digits of each of the employee's dependents/beneficiaries. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).

The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Request Direct Deposit

Navigation: Main Menu>Payroll for North America>Employee Pay Data USA>Request Direct Deposit

On the Request Direct Deposit page, in the Distribution section the Account Number field is masked, with only the last 4 digits of the account number visible.

The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Review Paycheck

Navigation: Main Menu>Payroll for North America>Payroll Processing USA>Produce Payroll>Review Paycheck

On the Review Paycheck page, click the Paycheck Deductions tab, and in the Net Pay Distribution section the Account Number field is masked, with only the last 4 digits of the account number visible.

The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Review Self Service Paycheck

Navigation: Main Menu>Payroll for North America>Payroll Processing USA>Produce Payroll>Review Self Service Paycheck

On the Review Self Service Paycheck page, in the Net Pay Distribution section, the Account Number field is masked, with only the last 4 digits of the account number visible.

The Local Security Administrator would need to apply the ZZ HC Unmask Bank Acct security role to unmask the specific bank account field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Driver's License Data

Navigation: Main Menu>Workforce Administration>Personal Information>Biographical>Driver's License Data

On the Driver's License Data page, in the Driver's License Information section the Driver's License Nbr field is masked, with only the last 4 digits of the number visible.

The Local Security Administrator would need to apply the ZZ HC Unmask Drivers License security role to unmask the specific Driver's License Nbr field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Update Person Detail

Navigation: Main Menu>Workforce Administration>Personal Information>Biographical>Update Person Detail

On the Biographical Details tab, in the National ID section the National ID field is masked, with only the last 4 digits of the employee's Social Security Number displayed. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).

The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Citizenship, Visa and Permits

Navigation: Main Menu>Workforce Administration>Personal Information>Citizenship>Citizenship, Visa and Permits

On the Citizenship/Passport tab, in the Citizenship/Passport section the Passport Number field is masked, with no digits of the employee's passport number displayed:

On the Visa/Permit Data tab, in the Visa/Permit History section the Number field is masked, with no digits of the employee's visa permit number displayed:

The Local Security Administrator would need to apply the ZZ HC Unmask Passport security role to unmask the specific passport or visa/permit field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Modify a Person

Navigation: Main Menu>Workforce Administration>Personal Information>Modify a Person

On the Biographic Details tab, in the National ID section the National ID field is masked, with only the last 4 digits of the employee's SSN displayed. The National Identification Number (NID) for US citizens equates to the Social Security Number (SSN).

The Local Security Administrator would need to apply the ZZ HC Unmask National ID_SSN security role to unmask the specific NID/SSN field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM PII Data security role.

Expand or collapse content Dependent Identification

Navigation: Main Menu>Workforce Administration>Personal Information>Personal Relationships>Dependent Identification

While this page has been included in HCM masking delivered masking set, it is unlikely that colleges will have data on this page as it is not a standard business practice to collect the passport and/or visa permit data for dependents.

On the Depdnt Citizenship/Passport tab, in the Passport Details section the Passport Number field is masked, where no digits of the passport number of the dependent of the employee are displayed:

On the Depdnt Visa/Permit Data tab, in the Visa/Permit History section the Number field is masked, where no digits of the visa permit number belonging to the dependent of the employee are displayed:

The Local Security Administrator would need to apply the ZZ HC Unmask Passport security role to unmask the specific passport or visa/permit field. To unmask all masked fields in the HCM pillar the Local Security Administrator to apply the ZZ HCM Unmask PII Data security role.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.