logo

NJP

How to Safeguard Sensitive HR Data with COE Security Policies (ServiceNow Orlando)

Import · Aug 07, 2020 · video

[Music] hello my name is william smith i'm a technical consultant with cerno solutions today i will be showing you how you can easily create coe security policies to control access to your hr cases when using coe security policies you get all the benefits of now platform security in easy to configure policy rules coes or centers of excellence are tables that allow cases to be grouped by hr departments where security policy records can then be created to restrict access to hr cases groups that are not included will have their access restricted but we'll get to that in just a moment this feature is provided as an alternative to acl rules and adding coe security makes it simple to control access to your sensitive hr cases and ensures that only the proper groups can view cases that pertain to them implementing these security policies takes just a few clicks and when completed you'll have peace of mind knowing your hr cases are secure oh and a bonus only minimal testing is needed let's jump over to servicenow for a quick demo of how to set one up the first thing you want to look at when creating coe security policies is to ensure that you're in the hr course scope i am so we'll get started start by typing coe in the left nav and choosing coe acl configuration you can see i don't currently have any security policies set up so let's create one i'm going to create one for our hr employee relations cases as i want to restrict those to only the employee relations group i can choose whether i want this to apply to all services or if i only want to narrow it down to a specific list of services for now i'm going to leave it set to all services on the right side of the form there's an active box if you want to deactivate these in the future and a type that is set to read or write when the type is read hr agents cannot read the item being restricted from a list or a form if i set the type to right they cannot write to the item being restricted all the fields are marked as read only it's similar to failing a write acl rule where the record is marked as read only i can add conditions so that i can granularly apply this rule but for now i'm just going to leave it alone i'm going to go ahead and press save and you can see the groups list that i was talking about earlier i'm going to add our hr employee relations group and once i press save and i turn on the rule that's it i'm done now i'm going to flip over to one of our hr administrators and show you what it looks like from their perspective this is alva she's an hr administrator in our company and you can see that prior to adding the coe security policy she can see all the disciplinary cases but when i refresh the screen all those cases are now gone for alva so those cases have been locked down and secured from our hr administrators coe security policies do not apply to the employee service center so additional measures will need to be taken to restrict cases in the employee service center coa security policies will also remove a coe on the hr case creation screen so that's another good way that you can restrict access i want to thank you for watching this video on hr coe security policies presented by cerna like this video and subscribe to our channel for additional hr related content for more information or to contact us see the information on the screen thank you [Music] you

View original source

https://www.youtube.com/watch?v=xCSId2YbYw8