Technical Paper. Securing SAS Business Intelligence Content That Is Managed in Metadata

Size: px
Start display at page:

Download "Technical Paper. Securing SAS Business Intelligence Content That Is Managed in Metadata"

Transcription

1 Technical Paper Securing SAS Business Intelligence Cntent That Is Managed in Metadata

2 Release Infrmatin Cntent Versin: 1.0 Nvember Trademarks and Patents SAS Institute Inc., SAS Campus Drive, Cary, Nrth Carlina SAS and all ther SAS Institute Inc. prduct r service names are registered trademarks r trademarks f SAS Institute Inc. in the USA and ther cuntries. indicates USA registratin. Other brand and prduct names are registered trademarks r trademarks f their respective cmpanies.

3 Cntents Intrductin... 3 Patterns f Use... 3 Access Cntrls and the Repsitry Default ACT... 4 Granting WriteMetadata in the Default ACT... 4 Setting Permissins fr PUBLIC and SASUSERS Implicit Grups in the Repsitry Default ACT... 6 Securing Permissin Patterns in the Default ACT...6 Tw Appraches t Defining Grup Access Cntrls... 7 Basic Permissin Patterns fr Securing Cntent Mdeled in the Metadata Repsitry... 7 Flat and Hierarchic Grup Flder Structure... 8 Securing Cntent Lcatins in the Metadata Repsitry... 9 Infrmatin Maps... 9 Web Reprts Stred Prcesses Creating and Securing Stred Prcesses with SAS Enterprise Guide Publishing Framewrk Metadata Publish-Subscribe Usage Prtal Permissin Trees Audits fr Metadata Permissins Areas fr Custmer Attentin Best Practices fr a Strnger Metadata-Based Security Plicy Appendix A: Flat Flder Structure Permissins (Generic Example) Appendix B: Hierarchic Flder Structure (Generic Example) i

4 ii

5 Intrductin Nte: Infrmatin in this dcument pertains t SAS Service Pack 4. SAS client sftware uses metadata t manage and secure business intelligence (BI) cntent items. Secure access t cntent items thrugh client user interfaces is cntrlled by metadata permissins, which are enfrced by the SAS Metadata Server. ReadMetadata and WriteMetadata access cntrls that are placed n individual items r flders grant r deny access t cntent items based n the identity f the user. Cntent items managed in metadata include: stred prcesses infrmatin maps data explratins web reprts publicatins channels and archived result packages Data tables and libraries are nt discussed in this dcument, but infrmatin abut them is given in SAS Data Integratin Studi (frmerly named SAS ETL Studi) dcumentatin. Fr infrmatin abut cntrlling OLAP cube access in metadata, see "Access Requirements fr OLAP Data," available at supprt.sas.cm/nlinedc/913/getdc/en/bisecag.hlp/a htm. Patterns f Use Client applicatins create bjects in the metadata repsitry t mdel and prvide authrizatin cntrl t cntent items. Sme applicatins have specific repsitry lcatins fr cntent metadata; ther applicatins let the SAS administratr create and manage the lcatins. SAS administratrs must manage grups f users. Each grup requires secure access t specific sets f cntent. The administratr creates subsetted flders (subflders) in the metadata rt flder and applies access permissins s that PUBLIC is denied access while specific grup access is granted. The administratr shuld als grant access t an administratrs' grup fr cntent management. Fr mre infrmatin abut applying access cntrls, see the nline Help fr the Authrizatin Manager plug-in t SAS Management Cnsle. Access t cntent is cntrlled by tw permissins: ReadMetadata and WriteMetadata. These permissins are enfrced by the server based n the identity f the cnnecting client. ReadMetadata permissin is needed t navigate and read cntent. If a user des nt have ReadMetadata permissin fr a cntent item, the item is nt fund in a search and is nt viewable in a metadata brwse client. WriteMetadata permissin is needed t create new bjects such as trees (flders) r cntent bjects such as stred prcesses, reprts, and infrmatin maps. A first step in prviding secure access t cntent is t secure wh can mdify grup identities and membership. Grup identities shuld be secured s that nly administratrs can mdify membership. 3

6 T restrict grup identity editing t administratrs, cmplete the fllwing steps: 1. Start SAS Management Cnsle. 2. In the User Manager plug-in, select the grup and then select Prperties. 3. On the Authrizatin tab: Select Grant WriteMetadata t Administratr grups. Select Deny WriteMetadata t PUBLIC. Apply a similar security pattern t Access Cntrl Templates (ACTs) that are applied t bjects and flders. Yu can access ACTs frm the Authrizatin Manager plug-in in SAS Management Cnsle. 1. Frm the plug-in, select Prperties Authrizatin fr each ACT. 2. Select Grant WriteMetadata t Administratr grups. 3. Select Deny WriteMetadata t PUBLIC grup. Sme SAS applicatins have a specific lcatin fr shared grup cntent; ther applicatins allw the administratr t set the lcatin. Sme applicatins prvide a User flder t stre persnal cntent items that are created in specific lcatins in the repsitry as presented later in the sectin "Errr! Reference surce nt fund.." This sectin reviews these lcatins and prvides strategies fr securing cntent at these lcatins. Access Cntrls and the Repsitry Default ACT Yu can use Access Cntrl Templates (ACTs) t apply sets f access cntrls t bjects. The Default ACT has a unique rle in that it applies (thrugh inheritance) t all bjects in the repsitry. Whenever a new bject is created, the access cntrls f the Default ACT gvern the initial creatin f the bject. This means that the identity that creates bjects in the repsitry must be granted WriteMetadata in the Default ACT. Granting WriteMetadata in the Default ACT Custmer administratrs ften ask why brad ReadMetadata and WriteMetadata permissins are needed in the Default ACT fr peratin f client sftware. ReadMetadata is required in rder t navigate and search fr bjects. WriteMetadata is required fr the initial creatin f bjects in the repsitry. Parent bjects like servers and flders prvide permissins thrugh inheritance dwn t child bjects. After an bject is created and assciated with a flder, permissins are inherited frm the flder as well as frm the Default ACT. Fr example, cnsider the creatin f a stred-prcess bject. SAS Enterprise Guide users must have WriteMetadata in the Default ACT t create the bject. T assciate that bject with a flder, users must have WriteMetadata fr these bjects als. After a user assciates the bject with a flder, that bject inherits permissins frm the parent bject as well as frm the Default ACT. 4

7 The fllwing table describes when and why identities must have WriteMetadata in the Default ACT. Client Task Creating Stred Prcesses Requirement fr WriteMetadata in Default ACT Authr f the stred prcess needs WriteMetadata fr initial creatin f the stred-prcess bject. Infrmatin Delivery Prtal Persnal Desktp Infrmatin Delivery Prtal Permissin Trees Prtal users manage persnal desktp cnfiguratin in the Prtal prfile bject that is assciated with each prtal user s identity. WriteMetadata is needed in the Default ACT fr creating and editing the prfile bject. The Prtal Applicatin Tree flder is accessed by Prtal cde t create user and grup permissin tree flders that are used t secure Prtal cntent n a per-user and per-grup basis. Prtal users must be granted WriteMetadata permissin fr the Prtal Applicatin Tree rt flder when they first lg n t the prtal. This permissin is required because the user's permissin tree flder is created as part f their first lgn prcess. A prtal user can be granted WriteMetadata in either f tw ways: directly granted by Access Cntrl Entries (ACE) r an ACT n a per-user r per-grup basis inherited frm the Default ACT Nte: Because all Prtal users must have a metadata identity (t save desktp persnalizatins), yu can use the SASUSERS grup (users with identities) t grant this required access permissin. After a user's first lgn, yu can remve the WriteMetadata grant that allwed initial creatin f the user's permissin trees. CAUTION: Be careful when changing the permissins fr the Prtal Applicatin Tree. The SAS Web Administratr identity and all prtal users (including SAS Guest) must have WriteMetadata n this rt flder. A best practice fr applying access cntrls is t use flders (tree bjects) t apply individual ACEs and ACTs t bjects in the flders. Objects within a flder inherit access cntrls frm the flder. Fr mre infrmatin abut access cntrls, inheritance f access cntrls, and precedence in inheritance, see the SAS Management Cnsle Authrizatin Manager nline Help. Mst administratrs als apply access cntrls at the rt f a flder path t prvide additinal and specific access cntrls t thse bjects within that flder that augment thse inherited frm the Default ACT. 5

8 Nte the tw rles f the Default ACT: When yu create an bject, nly the access cntrls f the Default ACT apply. After yu create the bject and assciate it with a flder r ther bjects, access cntrls are inherited frm the Default ACT and frm parent bjects (flders, servers) thrugh assciatin. Setting Permissins fr PUBLIC and SASUSERS Implicit Grups in the Repsitry Default ACT The SAS Metadata Server supprts tw implicit membership grups: PUBLIC All authenticated users. SASUSERS a subset f PUBLIC; authenticated users that have an identity in the repsitry. Administratrs can chse t cntrl access t cntent based n these grups. If ReadMetadata permissin is denied fr PUBLIC users but granted t SASUSERS, PUBLIC users can lg n t SAS applicatins but cannt view any cntent. In this cnfiguratin, a user identity must be added t the repsitry in rder fr the applicatin user t access cntent. This permissin pattern (Deny PUBLIC ReadMetadata, WriteMetadata) can be applied thrugh the Default ACT. Securing Permissin Patterns in the Default ACT The SAS Intelligence Platfrm: Security Administratin Guide, Secnd Editin (supprt.sas.cm/dcumentatin/cnfiguratin/bisecag.pdf) prvides guidance fr securing yur metadata repsitry with permissins applied in the Default ACT. After cmpleting these steps, the permissins in the Default ACT are as fllws: PUBLIC Deny ReadMetadata, WriteMetadata SAS Guest Grant ReadMetadata, WriteMetadata SAS Dem User Grant ReadMetadata, WriteMetadata Administratrs grup (sasadm) Grant ReadMetadata, WriteMetadata SAS System Services grup (SAS Web Administratr, SAS Trusted User) Grant ReadMetadata, WriteMetadata With this cnfiguratin, the Dem User can lg n t SAS web applicatins, and the SAS Guest accunt can be used t custmize the prtal s public kisk. The web administratr accunt can be used t manage web-applicatin cntent and be used as a utility accunt fr managing security. Nte: The SAS Intelligence Platfrm: Security Administratin Guide includes cntent that was frmerly in the SAS Enterprise Intelligence Platfrm: Administratin Guide befre Nvember Mst administratrs als apply access cntrls at the rt f a flder path t prvide additinal and specific access cntrls t thse bjects within that flder that augment thse inherited frm the Default ACT. 6

9 Tw Appraches t Defining Grup Access Cntrls As a best practice, yu shuld grant permissins thrugh grups. Using this apprach, yu can mdify the Default ACT as fllws: Optin 1: Identity-based grups PUBLIC Deny ReadMetadata, WriteMetadata SASUSERS Grant ReadMetadata, WriteMetadata Administratrs Grant ReadMetadata, WriteMetadata Prtal Admins (SAS Web Administratr, custmer Prtal admins) Grant ReadMetadata, WriteMetadata SAS System Services (SAS Web Administratr, SAS Trusted User) Grant ReadMetadata, WriteMetadata With this cnfiguratin, users wh have identities in metadata (SASUSERS) have permissins t access the prtal and ther web applicatins. Administratrs, including the Prtal Admins grup (SAS Web Administratr, SAS Trusted User), have permissins t manage web-applicatin security and peratins. All web applicatin users must have an identity in SAS Metadata Server because PUBLIC users are denied permissins. Mst cntent flders are accessible. Permissin fr securing cntent is described later in this dcument. Optin 2: Applicatin User Grups PUBLIC Deny ReadMetadata, WriteMetadata SASUSERS Deny ReadMetadata, WriteMetadata Create the Web Applicatin Users grup Grant ReadMetadata, WriteMetadata. Add SAS Guest, SAS Dem User, and all prtal and web-applicatin users. Administratrs grup Grant ReadMetadata, WriteMetadata Prtal Admins Grant ReadMetadata, WriteMetadata SAS System Services Grant ReadMetadata, WriteMetadata In Optin 2, yu have the same user permissin pattern as in Optin 1. Hwever, nw yu are creating specific applicatin user grups (fr example, Web Applicatin Users), and granting permissins t the grup instead f the brader permissin grant t SASUSERS. Nte: Yu need t create a grup fr each applicatin user grup in yur system and grant each ne ReadMetadata permissin at a minimum and WriteMetadata fr certain activities. Basic Permissin Patterns fr Securing Cntent Mdeled in the Metadata Repsitry ReadMetadata permissin is required fr navigating flder paths r searching fr cntent items. Fr this reasn, ReadMetadata permissin is granted at rt flders and then denied as needed t secure lwer cntent flders. It is a best practice t deny WriteMetadata permissin t PUBLIC at the rt flder level, and then grant it as required in lwer flders. Users wh nly view cntent items d nt need WriteMetadata permissin. WriteMetadata permissin is required t create, mve, r delete a cntent bject, and is therefre typically granted t cntent authrs and administratrs. 7

10 Use Access Cntrl Templates (ACTs) t implement this best practice. T use ACTs t restrict access at the rt flder level, fllw these steps: 1. Start SAS Management Cnsle. 2. In the Authrizatin Manager plug-in, create an ACT named Public RM Only. 3. On the Authrizatin tab, select Grant WriteMetadata t Administratr grups. Then select Deny WriteMetadata t PUBLIC. Apply this ACT t the rt f cntent flders such as /BIP Tree. The permissin pattern f the ACT is inherited frm the rt t subflders and cntent within thse subflders. This prevents WriteMetadata access. The administratr then grants WriteMetadata permissin t specific grups that need it. This permissin pattern allws flder path navigatin but blcks users frm creating cntent in lcatins that are nt secured r apprpriate. In lwer flder lcatins, create ACTs fr grup flders by using the fllwing grup permissin pattern: PUBLIC Deny ReadMetadata, Deny WriteMetadata Grup Grant ReadMetadata. Can view but nt alter. Grup administratrs and cntent authrs Grant ReadMetadata, Grant WriteMetadata. Can create, delete, and cpy. Using this permissin pattern, applicatin users can navigate nly r search flders where they have ReadMetadata access. When navigating r searching, they see in the user interface nly the flders and cntent items that are available t their grup. The grup wner permissin pattern demnstrates three best practice rules fr permissin-based security: Rule 1: Deny permissin bradly (PUBLIC) and grant permissin specifically (Grup). Rule 2: Use grups t cntrl permissins and nt individual identities. This is mre manageable and easier t administer; users are added r remved frm grups based n their need fr rle-based security. Rule 3: Apply access cntrls t flders either directly r thrugh inheritance, and let cntent items in the flder inherit access cntrls frm the cntaining flder. Flat and Hierarchic Grup Flder Structure There are tw cmmn patterns fr applying access cntrls t grup flders: flat flder structure and hierarchic flder structure. A flat flder structure is mst cmmn and is easy t visualize and manage. /BIP Tree/Grups/Dept A /BIP Tree/Grups/Dept B /BIP Tree/Grups/Marketing Divisin A hierarchic flder structure typically fllws the rganizatinal structure fr a business unit. There is a need t access cntent based n a hierarchy f rle-based permissins. Fr example, wrk grups can access nly grup 8

11 cntent, managers can access cntent acrss all grups plus a manager s area, and executives can lk at cntent acrss all grup and managers areas plus an executive reprts area. /BIP Tree/ReprtStudi/Shared/ Reprts/Sales Reprts/Sales/Natinal Reprts/Sales/Sutheast/Regin Reprts/Sales/Sutheast/Flrida Reprts/Sales/Sutheast/Gergia These tw appraches t flder structure each require a unique pattern f access permissins t prperly secure the cntent flders. Examples that present these access permissin patterns are prvided in the Appendices. Securing Cntent Lcatins in the Metadata Repsitry SAS client applicatins can have default lcatins fr string metadata cntent entries, r the applicatin administratr might be allwed t define these lcatins. Multiple SAS clients fr each cntent type exist, and each client is designed t meet the needs f a specific user grup. Sme f these SAS clients are read-nly viewers; ther clients enable the user t create and edit cntent. T understand, secure, and audit access t cntent, the applicatin administratr must knw hw and where client applicatins access cntent bjects and flders. The fllwing sectin presents a summary, rganized by cntent type, f SAS client sftware that views r creates cntent that is managed in metadata. The sectin als details the typical lcatins f that cntent in the metadata repsitry. Use this summary t review these cntent lcatins and apply the apprpriate access cntrl patterns t secure the cntent. Infrmatin Maps Clients that Create Infrmatin Maps: SAS Infrmatin Map Studi, Data Explrer Clients that View Infrmatin Maps: SAS Web Reprt Studi, SAS Infrmatin Delivery Prtal, SAS Infrmatin Maps Navigatr prtlet and Tree Navigatr prtlet, Prtal Search feature (prtal uses Data Explrer t view maps that are surfaced in Navigatr prtlets and Search result lists); SAS Web OLAP Viewer fr Java views OLAP maps. SAS Web Reprt Studi Infrmatin Maps The default repsitry lcatin fr maps used by SAS Web Reprt Studi is /BIP Tree/ReprtStudi/Maps/. Secure grup subflders can be created at this lcatin. SAS Web Reprt Studi searches all subflders at this lcatin when prviding the user with a list f data surces. A typical grup flder pattern wuld be: /BIP Tree/ReprtStudi/Maps/Public /BIP Tree/ReprtStudi/Maps/DeptA /BIP Tree/ReprtStudi/Maps/DeptB /BIP Tree/ReprtStudi/Maps/MarketingDivisin 9

12 Data Explrer Infrmatin Maps Maps used primarily by the Data Explrer can be stred in any lcatin in the Infrmatin Service. Creating a Maps flder higher in a BI rt flder makes navigatin and access cntrl easier. /BIP Tree/Grups/DeptA secured t Department A grup (see grup-wner pattern in Appendix B.) /BIP Tree/Grups/DeptB secured t Department B grup In this example, the lcatin /BIP Tree/Grups can be secured s that nly the administratr can create grup flders and security permissins can be applied when grup flders are created. A permissin pattern t secure flder creatin nly fr administratrs is as fllws: PUBLIC Grant ReadMetadata, Deny WriteMetadata Administratrs grups Grant ReadMetadata, Grant WriteMetadata Data Explratins Visual Data Explrer and SAS Web OLAP Viewer fr Java prvide a File Save feature t stre data explratins (specific views n infrmatin maps) in user flders created in the repsitry as /BIP Tree/Users/user-ID/. Fr SAS Service Pack 3, these flders are nt secured t the wner. Apply the fllwing permissin pattern using an ACE t each flder after creatin. PUBLIC Deny ReadMetadata, Deny WriteMetadata User Grant ReadMetadata, Grant WriteMetadata SAS Service Pack 4 includes enhancements fr Visual Data Explrer (VDE) and SAS Web OLAP Viewer fr Java limits the Save feature t a user s secure flder at /BIP Tree/Users/user-ID. Bth Data Explrer and SAS Web OLAP Viewer fr Java prvide a File Open feature. Because File Open access is cntrlled by ReadMetadata permissins, access cntrls shuld be placed n flders and cntent items such that the File Open feature prvides secure access t cntent. Specifically, all users have sle access t their wn user flders and can als access grup flders based n grup membership. Viewing and Saving OLAP Cubes When yu use Data Explrer r SAS Web OLAP Viewer fr Java applicatins t view OLAP cubes, infrmatin maps are generated fr use by the query subsystem. These maps are created in the fllwing shared area: /BIP Tree/SASGeneratedMaps/OLAP-schema-name/ All users f Data Explrer and SAS Web OLAP Viewer fr Java must have ReadMetadata and, WriteMetadata access t this area when creating cubes. As a result, infrmatin maps that are created here are accessible t all users. Althugh the infrmatin map cannt expse cube attributes restricted by cube metadata permissins, applicatin develpers might want t limit access t these maps and limit this type f direct access t cubes. Nte: SAS Service Pack 4 allws limiting direct access t cubes thrugh an applicatin parameter setting. In this cnfiguratin, the File Open dialg bx des nt allw cubes in the Open ptin. It nly allws OLAP infrmatin maps. 10

13 Web Reprts Clients that Create Web Reprts: SAS Web Reprt Studi Clients that View Web Reprts: SAS Infrmatin Delivery Prtal Web Reprt Navigatr prtlet and Tree Navigatr prtlet Nte: The Prtal Search feature als accesses web reprts. By default, the prtal uses SAS Web Reprt Viewer t view web reprts that are displayed in Navigatr prtlets and Search feature result lists. The default lcatin in the repsitry fr shared web reprts is /BIP Tree/ReprtStudi/Shared/Reprts/. Secure grup subflders shuld be created at this lcatin, as shwn in the fllwing examples: /BIP Tree/ReprtStudi/Shared/Reprts/DeptA /BIP Tree/ReprtStudi/Shared/Reprts/DeptB Yu can als create a Public flder that has ReadMetadata and WriteMetadata permissins granted t PUBLIC: /BIP Tree/ReprtStudi/Shared/Reprts/Public Such a flder prvides pen access s that any authenticated user can create and share cntent with all users. Other flders can be created and secured t share cntent within a grup f grups. When a user lgs in fr the first time, SAS Web Reprt Studi prgrammatically creates a persnal user flder fr that user. In the default flder naming structure, the lcatin is /BIP Tree/ReprtStudi/Users/user- ID/Reprts/. Fr SAS Service Pack 3, the /Users flder has PUBLIC access by default, with each user s /Reprts flder prtected at creatin by the fllwing ACE settings: PUBLIC Deny ReadMetadata, Deny WriteMetadata User Grant ReadMetadata, Grant WriteMetadata These settings prtect the /Reprts flder frm view and access f cntent, but it des nt secure the user flder named /BIP Tree/ReprtStudi/Users/user-ID frm view by anther metadata brwsing client such as the Web Reprt Navigatr prtlet in SAS Infrmatin Delivery Prtal. SAS Service Pack 4 applies the user secured permissin pattern ne level up frm the /Reprts flder, which prtects the user flder name frm view. Stred Prcesses Clients that Create Stred Prcesses: BI Manager plug-in versin 1.4 fr SAS Management Cnsle Stred Prcess Manager, SAS Enterprise Guide 3 Nte: The BI Manager plug-in versin 1.4 fr SAS Management Cnsle includes functinality previusly cntained in the Stred Prcess Manager. Clients that View Stred Prcesses: SAS Add-In fr Micrsft Office, SAS Infrmatin Delivery Prtal Tree Navigatr prtlet and SAS Infrmatin Delivery Prtal Stred Prcess Navigatr prtlet, and the SAS Infrmatin Delivery Prtal Search feature. SAS Stred Prcess Web Applicatin is used t view stred prcesses that are selected in Navigatr prtlets and Prtal Search results lists. 11

14 Yu can create and access stred prcesses thrugh any BI rt flder in the repsitry, requiring ReadMetadata permissin t execute and requiring WriteMetadata permissin t create. The default lcatin fr stred prcesses that are used by web reprts is /BIP Tree/ReprtStudi/Shared/Reprts/StredPrcesses/. Yu can create grup flders in this lcatin t rganize and secure stred prcesses that are available fr web reprts. Other BI rt flders that are available in a typical SAS Enterprise BI Server install are: /Samples/Stred Prcesses/ Used by the SAS Integratin Technlgies installatin t stre sample stred prcesses. Mst custmers want t deny ReadMetadata access t the PUBLIC grup fr the /Samples rt and nly grant ReadMetadata access t authring grups (SAS Enterprise Guide users) that need t access the samples fr example cde. /Integratin Technlgies SAS Publish-Subscribe metadata is stred in this rt flder and used t manage channels and subscriber prfiles. Deny WriteMetadata access t the PUBLIC grup in this flder area, and limit access t users wh wrk with the publish framewrk. /Prtal Applicatin Tree SAS Infrmatin Delivery Prtal uses the rt flder t maintain permissin trees t secure Prtal cntent. Deny WriteMetadata access t the PUBLIC grup fr this flder and grant WriteMetadata access t SAS Web Administratr, the Prtal s utility administratr accunt. When permissin tree flders are created, they are prgrammatically secured t the wning user r grup. CAUTION: Althugh it is pssible, DO NOT stre stred-prcess bjects in these repsitry flders. Best practice is t manage all cntent in the /BIP Tree rt flder. This prvides a simpler envirnment t secure. Grup flders can be maintained as /BIP Tree/Grups/grup. At this lcatin, yu can create grup subflders and apply permissins as fllws: Grup users Grant ReadMetadata Grup administratrs and cntent authrs Grant ReadMetadata, Grant WriteMetadata PUBLIC Deny ReadMetadata, Deny WriteMetadata As seen previusly, yu can easily save this grup-wner permissin pattern and apply it as an ACT fr each grup. /BIP Tree/GrupA (apply GrupA wner ACT).../BIP Tree/GrupZ (apply GrupZ wner ACT) Stred prcesses are unique in that they must have an assciated Surce directry bject fr the lcatin f stred prcess surce cde. As a result, clients that create stred-prcess bjects must als create Stred Prcess Surce directry bjects. The directry bjects btain access cntrls nly frm the Default ACT. Therefre, users wh create stred prcesses (fr example, SAS Enterprise Guide users and the BI Manager plug-in fr SAS Management Cnsle users) must have WriteMetadata permissin in the Default ACT. Stred-prcess bjects are als unique in that they have an assciatin t a server bject fr executin (either SAS Wrkspace Server r SAS Stred Prcess Server). A user wh creates a stred-prcess bject must als have WriteMetadata permissin fr the lgical stred-prcess server fr the executin server. Finally, a stred prcess authr must have WriteMetadata fr the flder where the stred prcess is saved. 12

15 As a pattern f access cntrls, stred-prcess authrs (using the BI Manager plug-in fr SAS Management Cnsle r SAS Enterprise Guide) must be granted ReadMetadata and WriteMetadata permissins fr the fllwing lcatins and bjects: the flder that cntains the stred-prcess entry the lgical stred-prcess server fr executin the Default ACT fr creating the assciated surce directry bject Creating and Securing Stred Prcesses with SAS Enterprise Guide Yu can cnfigure SAS Enterprise Guide 3 t use the SAS Metadata Repsitry t lcate wrkspace servers and stred-prcess servers and t save and share stred prcesses. Stred-prcess authrs must first use the SAS Enterprise Guide administratr t cnfigure the SAS Metadata Repsitry as a prject repsitry. The credentials that are prvided fr the metadata server cnnectin shuld be thse f the user and nt a general purpse access accunt. This allws the use f metadata access cntrls t restrict stred-prcess authrs t grup flders specific t their scpe f wrk. When a SAS Enterprise Guide Prject is pened, a cnnectin is made t the metadata server using the credentials that were defined by the SAS Enterprise Guide Administratr applicatin. First-time users are prmpted fr these credentials, and these credentials are persisted by the applicatin via default security settings. The prcess f creating, testing, and delivering a stred prcess requires cnnectins t bth wrkspace servers (stres the SAS Enterprise Guide Prject and executes the SAS cde) and stred-prcess servers (executes the stred prcess). In SAS Enterprise Guide 3.01, users were prmpted fr server access credentials fr the wrkspace server. Fr SAS Enterprise Guide 3.02, a cnnectin t the wrkspace server is attempted with the cached metadata-server credential, and then using available metadata lgns fr the user. When yu cnnect t a stredprcess server, cached credentials are nt used. Metadata lgns are used instead. If n metadata lgns are available, the user is then prmpted. Cnsistent credential caching and lgn management is in SAS Enterprise Guide 4. The use f secured grup flders restricts stred-prcess authrs t flders based n their scpe f wrk, and enables secure delivery t the grup. Hwever, due t the nature f stred-prcess bjects and assciatins (t servers and surce directries), stred-prcess authrs must have WriteMetadata access fr bth the stredprcess flder and the lgical stred-prcess server where the stred prcess will execute. They must als have WriteMetadata access in the Default ACT. Fr SAS Enterprise Guide 3.0, a user must be granted WriteMetadata permissin t all stred-prcess entries that exist in a flder in rder t save a new stred prcess in the flder. Because f this restrictin, access cntrls fr stred-prcess entries shuld always be made at the flder level and passed by inheritance t each stred-prcess entry in the flder. This behavir ensures that cnsistent WriteMetadata access is prvided t authrs wh create and save stred prcesses in the flder. Publishing Framewrk Metadata Clients that Create Publishing Framewrk: SAS Management Cnsle Publishing Framewrk plug-in Clients that View Publishing Framewrk: SAS Enterprise Guide 3, SAS Infrmatin Delivery Prtal Channels are managed in the SAS Integratin Technlgies BI rt flder: /Integratin Technlgies/Publish-Subscribe/Channels 13

16 Administratrs can create channel entries using the SAS Management Cnsle Publishing Framewrk plug-in. Administratrs can create secure grup subflders t rganize and secure channel access fr user grups. Examples: /Integratin Technlgies/Publish-Subscribe/Channels/Sales /Integratin Technlgies/Publish-Subscribe/Channels/DeptA/WeeklyReprts /Integratin Technlgies/Publish-Subscribe/Channels/DeptB/FinanceReprts The Publish-Subscribe mdel requires the fllwing access cntrl patterns: Subscriber r Admin must be granted WriteMetadata n the Package Subscribers flder in the Publishing Framewrk permissin tree t create subscriber prfiles Publishers must be granted ReadMetadata n the channel flder t read subscriber prfiles fr delivery Publishers t Channels with Archives (the cntent f which is tracked in Metadata) must be granted WriteMetadata n the Channel bject In the prtal, the Manage Subscriptins ptin presents a list f channels that users can subscribe t. The list is created frm a search f channel bjects in flders and subflders starting at this lcatin: /Integratin Technlgies/Publish-Subscribe/Channels A user must be granted ReadMetadata permissin t view the channel in the user interface, and must be granted WriteMetadata permissin t subscribe t the channel. Nte: Fr this reasn, ReadMetadata and WriteMetadata permissins shuld always be granted r denied tgether fr a channel bject r a flder that cntains channel bjects that the administratr wants t ffer fr pen subscriptin t a grup. This prvides cnsistency fr the user interface that enables the user t subscribe t any Channel that is displayed t them. Clsed Enrllment Channels Sme channels might be ffered with clsed enrllment. A prtal administratr might want t manage a channel t which all prtal users are subscribed, r create a channel fr news that is displayed n the prtal s public kisk. Fr these channels, the administratr can create a flder such as the fllwing: /Integratin Technlgies/Publish-Subscribe/Channels/AdminCntrlled The administratr can als place an ACT n this flder with the fllwing permissins: Administratrs grups Grant ReadMetadata, Grant WriteMetadata PUBLIC Deny ReadMetadata, Deny WriteMetadata Then, the administratr creates tw channels: PrtalNews subscribe all prtal users PublicNews nly subscribe SAS Guest (accunt used fr the public kisk) Only the administratr can change subscriptins fr these channels. If users ther than the administratr grup need t publish t these channels, thse users must be granted WriteMetadata permissin. The prtal Manage Subscriber Prfiles feature enables yu t create subscriber prfiles that prvide infrmatin t publishing prcesses fr cntent delivery. Alternatively, an administratr can create prfiles fr subscribers by using the Publishing Framewrk plug-in t SAS Management Cnsle. 14

17 By default, the Subscriber flder is created withut access cntrls. Hwever, this enables users f clients with navigatin user interfaces (such as VDE and Prtal Tree Navigatr prtlet) t view subscriber prfile names in this lcatin: /Integratin Technlgies/Publish-Subscribe/Subscribers/Cntent Subscribers Nte: If the administratr chses t keep this flder lcatin pen by granting ReadMetadata permissin, then subscriber prfile names shuld nt be based n full user name, user ID, r ther infrmatin that culd expse user identity. Publish-Subscribe Usage Publishing frm the Prtal Cllabratin In this lw-security scenari, a grup f users share a channel amng themselves that is secure t the grup, and all subscribers can als be publishers. Publishing frm the Prtal requires an archive because the Prtal s Publicatin Channel Subscriptins prtlet is used t view channel cntent. Create a flder and apply access cntrls that grant the grup and administratrs ReadMetadata, WriteMetadata while denying PUBLIC ReadMetadata, WriteMetadata. Within this flder, a channel is created, and a subscriber grup is created fr channel subscribers. Alternatively, the channel can be secured directly t the grup (grant ReadMetadata, WriteMetadata fr the grup, deny ReadMetadata, WriteMetadata PUBLIC, grant Admins ReadMetadata, WriteMetadata). The grup is granted ReadMetadata access t the subscriber prfile fr each member f the grup while the PUBLIC grup is denied ReadMetadata access t the grup s subscriber prfiles. As a lw-security scenari, it des nt matter if the subscriber infrmatin fr grup members is expsed t the grup. If a DAV directry is used as the archive fr the channel, it shuld be created and secured t limit access t grup members and administratrs. If a prtal user s subscriber prfile specifies as the publish delivery mechanism, the will cntain a link t the prtal cntent. When the user first attempts t access the link, the Prtal uses the SAS Guest accunt (used t manage the prtal s public kisk page) t access the cntent. If this fails, the user is prmpted t lg n. Using the SAS Guest accunt enables publishers t cnvenient publish lw-security cntent that is available t all users. If the channel archive is a DAV directry, then access must be prvided t the SAS Guest accunt, and all publishers must knw that any user wh searches fr cntent at the public kisk have access t the published package. Cntent that must be secure t a specific grup membership shuld be placed in a metadata flder that denies the PUBLIC grup ReadMetadata access and grants grup members ReadMetadata access. Further, SAS Guest must be denied ReadMetadata access. Grup users wh receive cntent via URLs in are prmpted t lg n fr access, and the cntent is secure frm search frm the public kisk. Publishing Channels fr High Security and Assured Delivery In sme publishing envirnments, channel cntent is sensitive and subscribers have limited access t channels. The same access cntrl requirements might exist when there is a channel fr imprtant alert infrmatin and subscribers are nt allwed t unsubscribe frm the channel. Here the administratr has a larger task. That is, he r she uses the Publishing Framewrk plug-in t SAS Management Cnsle t create bth the channel and subscribers, subscribing individuals t the channel, and then retaining sle WriteMetadata access cntrl fr the channels and subscribers. N user can begin r end a subscriptin except thrugh a request t the administratr. A publishing accunt is als required that has 15

18 WriteMetadata permissin fr the channel and ReadMetadata permissin fr the subscriber prfiles. Create the channel with the fllwing permissins: PUBLIC Deny ReadMetadata, Deny WriteMetadata Subscribed Grups Grant ReadMetadata Users publishing t the channel Grant ReadMetadata Administratr Grant ReadMetadata, Grant WriteMetadata Subscriber prfiles are created and lcked by the administratr with the fllwing permissins: PUBLIC Deny `, Grant WriteMetadata Metadata is written t track-persisted result packages in the archive. Because prtal channels require an archive, channel publishers must be granted WriteMetadata access fr channels with archives, Prtal Permissin Trees Prtal permissin trees (flders) are maintained t secure cntent items that are unique t the prtal applicatin: pages, prtlets, web applicatins, links, and publicatin and syndicatin channels. Permissin trees are managed in the BI rt flder, /Prtal Applicatin Tree, and cntain references t prtal pages. After an installatin, users can navigate t this BI rt flder with the Prtal Navigatr prtlets and see their wn permissin tree and the permissin trees f grups t which they belng. In additin, client user interfaces that can prvide the File Save cmmand selectin can stre cntent in this space. This behavir presents tw areas f pssible cncern: Sme applicatin service prvider (ASP) custmers might differentiate service fferings by grup names t distinguish custmer relatinships (fr example, Ecnmy, Gld, and Platinum). They might nt want custmers t knw this classificatin. Because such grup names are viewable by clients, such grup names shuld nt reveal sensitive infrmatin. Prtal users can navigate t their permissin trees (user and grups that they are members f) and try t view the pages. This event is harmless because the pages are already part f the user s desktp. Prtal users and grups each have a permissin tree flder that is used t secure prtal cntent. When a user r grup becmes active in the prtal, that permissin tree flder is created as a subflder in the Prtal Applicatin Tree rt flder. An access cntrl that grants WriteMetadata permissin is required fr prtal users fr the Prtal Applicatin Tree rt flder when a user first lgs n t the prtal. When the user's permissin tree is created, prtal cde applies direct access cntrls t the tree flder as fllws: PUBLIC Deny ReadMetadata, Deny WriteMetadata Owner, either user r grup Grant ReadMetadata, Grant WriteMetadata Prtal Admins Grant ReadMetadata, Grant WriteMetadata, grant-delete These ACEs enable prtal cde t access the permissin tree flder. Fr strngly secured prtal applicatins where new users must be apprved fr access, yu can cntrl WriteMetadata access fr the Prtal Applicatin Tree flder by using a direct ACE. 16

19 Nte: A direct ACE that denies WriteMetadata access t SASUSERS prevents new users frm first-time lg n t the prtal. T enable a new user t lg n and create the required user permissin tree, apply a direct ACE t that user that grants WriteMetadata. Remve that direct ACE after the user's first lgn. Audits fr Metadata Permissins Custmers wh have strict security requirements will want t audit SAS metadata-based security. Requirements might include the fllwing: Persnal cntent is secured t the wner. Grup cntent is secured t grup members. Such grupings can be based n external custmer-client relatinships r internal user grups. Privacy: Users must nt be aware f ther users f the applicatin, individually r by grup assciatin as expsed by metadata navigatr-type clients r search features. If the custmer is an applicatin service prvider (ASP), users must nt be able t see infrastructure metadata abut the service prvider relatinship (fr example, a service user is placed in a lw-pririty usage grup). Here are sme alternatives fr perfrming such audits t verify cmpliance fr security requirements, but nne f these alternative are autmated fr SAS 9.1.3: Lg n t the prtal with representative rle-based accunts, and use the Tree Prtal Navigatr prtlets t navigate all available Infrmatin Service repsitries and t inventry available grup flders. The Tree Navigatr prtlet shws all cntent types. This feature makes it useful fr audit checks, but the administratr can chse t limit its availability t prtal administratrs. Lg n t the prtal with representative rle-base accunts, and use the search feature and all cntent, and review the list. The lcatin that is prvided in the results list indicates the metadata repsitry lcatin fr the item. Lg n t SAS Management Cnsle with representative rle-based accunts, and use the Authrizatin Manager plug-in t view subflders and available cntent. Review the shared cntent areas fr prducts (such as SAS Web Reprt Studi) that using representative rlebased accunts. Cnfirm that grup flders are accessible nly by grup members. Areas fr Custmer Attentin A default installatin f SAS Enterprise BI requires additinal cnfiguratin by the SAS administratr t prvide adequate security fr cntent that is managed by metadata. Fr specific backgrund and guidance, see the SAS Intelligence Platfrm: Security Administratin Guide, Secnd Editin, available at supprt.sas.cm/dcumentatin/nlinedc/intellplatfrm/913/bisecag.pdf. Nte: The SAS Intelligence Platfrm: Security Administratin Guide, Secnd Editin includes cntent that was frmerly in the SAS Enterprise Intelligence Platfrm: Administratin Guide befre Nvember

20 SAS 9 applicatins navigate thrugh the metadata repsitry as a means t access cntent items. Prtal Navigatr prtlets and Visual Data Explrer dialg bxes that are pened by selecting File Open r File Save enable users t navigate the entire Infrmatin Service, including cntent f the fllwing BI rt flders: /BIP Tree /Samples /Integratin Technlgies /Prtal Applicatin Tree additinal BI rt flders that are created by the custmer Fr Prtal Navigatr prtlets, the DAV repsitry that is assciated with the Infrmatin Service is accessible and shuld be secured by using the apprpriate DAV administratin tls. The fllwing review prvides a quick summary f the cmmn cntent flders in a SAS Enterprise Business Intelligence deplyment and the first steps t prvide basic metadata security. In SAS Management Cnsle, an administratr might need t use a specific manager plug-in t create a flder r cntent bject and then use the Authrizatin Manager plug-in t apply access permissins. Administratrs will find it useful t create ACTs fr cmmn access cntrl patterns: Public Read Metadata Only ACT: PUBLIC Grant ReadMetadata, Deny WriteMetadata Administratr grups (including SAS Web Administratr) Grant ReadMetadata, Grant WriteMetadata Admin Access Only ACT: PUBLIC Deny ReadMetadata, Deny WriteMetadata Administratr grups Grant ReadMetadata, Grant WriteMetadata Grup Owner ACT: PUBLIC Grant ReadMetadata, Deny WriteMetadata Grup Grant ReadMetadata Grup administratrs and cntent authrs Grant ReadMetadata, Grant WriteMetadata Administratr grups Grant ReadMetadata, Grant WriteMetadata The Default ACT must prvide ReadMetadata access either t the PUBLIC grup r the SASUSERS grup, depending n security plicy. The PUBLIC grup represents all authenticated users. The SASUSERS grup cnsists f authenticated users wh have established user identities. A typical, secure access permissin pattern is applied as fllws: In /BIP Tree, apply the Public Read Metadata Only ACT. In /BIP Tree/ReprtStudi/Shared/Reprts SAS Web Reprt Studi Shared reprts flders: Create a Public subflder and apply ACE t grant ReadMetadata and WriteMetadata permissins t the PUBLIC grup. Create grup subflders and apply the Grup Owner ACT. 18

21 /BIP Tree/ReprtStudi/Maps SAS Web Reprt Studi Maps flders: Use the same subflder and permissin pattern as is used the Reprts flders (see previus bullet item) t prvide each grup secure access t grup maps. /BIP Tree/ReprtStudi/Users SAS Web Reprt Studi user flders: SAS Service Pack 4: Grant WriteMetadata access t the Admin grup (includes SAS Web Administratr and the SAS Web Reprt Studi privileged accunt). SAS Service Pack 3 (withut ht fix 21WRS01 applied): Apply ACE t grant WriteMetadata access t the PUBLIC grup. This actin enables users t create and secure their wn flders. /BIP Tree/Users Visual Data Explrer user flders: In SAS Service Pack 4 and SAS Service Pack 3 with Ht Fix 913CDD02 applied, user flders are secured t wner. Users cannt create cntent at this lcatin. Apply an ACE t grant WriteMetadata access t the PUBLIC grup, depending n whether the security plicy allws creatin f user flders. In SAS Service Pack 3 (withut Ht Fix 913CDD02 applied), flders are nt secured when they are created. /BIP Tree/SASGeneratedMaps When either Visual Data Explrer r SAS Web OLAP Viewer fr Java access cubes directly, infrmatin maps are generated and stred in this lcatin. Ht fix 913CDD01 prvides an ptin t cntrl direct access f cubes. Generated maps can be accessed by any user wh has been granted WriteMetadata permissin n this lcatin. Applying an ACE t deny WriteMetadata access t the PUBLIC grup r the SASUSERS grup prevents the strage f generated maps (and direct access t cubes). /Samples Apply the Admin Access Only ACT t the Grant Admin grup (includes SAS Web Administratr and the SAS Web Reprt Studi privileged accunt). Grant ReadMetadata and WriteMetadata access t stred-prcess writers. Apply ACEs t grant ReadMetadata access t pwer user grups, as needed. /Integratin Technlgies Apply the Public Read Metadata Only ACT. Grant ReadMetadata and WriteMetadata access, as needed, t lwer flders t manage grup channels and subscriber prfiles. /Integratin Technlgies/Publish-Subscribe/Channels/ Publishing Framewrk channel definitins The administratr uses the Publishing Framewrk plug-in t SAS Management Cnsle t create channels. The administratr applies ACEs r ACTs t grant grups ReadMetadata and WriteMetadata access t individual channels t view (ReadMetadata) and enable grup subscriptin (WriteMetadata). Security and privacy needs determine whether ReadMetadata and WriteMetadata permissins shuld be granted as a pair. (list cntinued) 19

22 (Optinal) The Metadata administratr can create a channel flder and grant a channel administratr grup WriteMetadata permissins t create channels, as needed, in the flder. If channels have archives, apply ACEs t grant ReadMetadata and WriteMetadata access t publishing grups fr the channel r channel flder. /Integratin Technlgies/Publish-Subscribe/Subscribers/Cntent Subscribers/ The prtal, SAS Enterprise Guide, and the Publishing Framewrk plug-in t SAS Management Cnsle stre subscriber prfiles in this directry. If the administratr wants sle cntrl f subscriptin prfiles, apply an ACT t grant Admin grups the permissin pattern ReadMetadata,WriteMetadata Deny PUBLIC WriteMetadata. This permissin pattern can be inherited frm ACT applied at rt flder. Yu can prvide additinal access cntrl by creating subscriber prfiles and granting ReadMetadata and WriteMetadata access t a limited grup: wner, administratr grup, and publishing grup. /Prtal Applicatin Tree - Prtal permissin trees fr cntent items: Prtal users require the Grant ReadMetadata, Grant WriteMetadata pattern fr this flder. This pattern is usually inherited frm the Default ACT. Permissin trees that are created fr users and grups are secured t the wning user r grup. Administratrs, including the SAS Web Administratr accunt, must als have the Grant ReadMetadata, Grant WriteMetadata permissin pattern fr this rt flder. The SAS Web Administratr accunt is used t manage prtal permissins trees at this lcatin, and administratrs might need t directly manage permissin tree flders here. Best Practices fr a Strnger Metadata-Based Security Plicy Limit cntent lcatins t a small number f BI rt flders, preferably nly in the BIP Tree rt flder. Limit use f the Tree Navigatr prtlet t administrative users nly. T d this, cmplete the fllwing steps: 1. Start the SAS Management Cnsle. 2. In the Authrizatin Manager plug-in, select Resurce Management By Type and pen the Prttype flder. 3. Lcate the TreeNavigatr template. 4. Right-click the template and select Prperties. 5. On the Authrizatin tab, grant ReadMetadata permissin t Admin grups and deny ReadMetadata permissin t the PUBLIC grup. Deny WriteMetadata access whenever pssible. This actin prevents users frm writing cntent in unsecured lcatins. Generally, ReadMetadata access must be bradly granted fr navigatin and searching, and it can be denied at the lwest subflders that must be secured t the wning user r grup. 20

23 When yu apply a direct ACE r ACT t deny ReadMetadata permissin fr an identity, always deny WriteMetadata permissin as well fr the identity. Appendix A: Flat Flder Structure Permissins (Generic Example) The specific lcatin f cntent items depends n the applicatin and the custmer s envirnment. The fllwing is a generic example that shws access cntrl permissin patterns fr infrmatin maps in a typical SAS Web Reprt Studi installatin. In this example, the infrmatin architect has identified a set f infrmatin maps that must be available nly t a certain grup, and anther set t be available nly t anther grup. Fr example, ne grup, Dept A, might be decisin makers viewing maps with the Data Explrer in SAS Infrmatin Delivery Prtal. The ther grup, Dept B, might be business analysts wh wrk with SAS Web Reprt Studi t deliver web reprts. Because f the sensitive infrmatin expsed by the maps, access must be limited t specific grups. The Default ACT is as fllws: PUBLIC Deny ReadMetadata, Deny WriteMetadata SASUSERS Grant ReadMetadata, Grant WriteMetadata Nte: SAS applicatin users must have a user identity in the metadata repsitry t access cntent. SAS Web Reprt Studi (SAS 9.1.3, Service Pack 3) requires that maps be stred in a specific lcatin in the metadata repsitry: /BIP Tree/ReprtStudi/Maps/ The administratr creates an administratrs grup that cntains SAS Web Administratr accunt and ther custmer administratr accunts. The generic user grups are Dept A and Dept B. The administratr als creates a grup called DW Analysts, which cnsists f prgrammers and analysts wrking with the data warehuse and infrmatin maps. The cmmn cntent lcatin is as fllws: /BIP Tree/ReprtStudi/Maps/ Apply default permissins using the fllwing ACE: PUBLIC Deny Write Metadata Administratr grups Grant WriteMetadata DW Analysts Grant WriteMetadata This ACE blcks all users except Administratr grups and Analysts frm creating flders r adding cntent at this lcatin. The administratr creates the fllwing flder fr the Dept A grup: /BIP Tree/ReprtStudi/Maps/DeptA/ 21

24 Apply Dept A Owner permissins using the fllwing ACE: PUBLIC Deny ReadMetadata, Deny WriteMetadata Dept A Grant ReadMetadata Administratr grups Grant ReadMetadata, Grant WriteMetadata DW Analysts Grant ReadMetadata, Grant WriteMetadata The result f applying this ACE is that nly Dept A grup members, administratrs, and analysts can access this flder t view reprts. Only administratrs and analysts can create r manage maps. The administratr als creates a flder fr the Dept B grup: /BIP Tree/ReprtStudi/Maps/DeptB/ Apply Dept B Owner permissins by using the fllwing ACE: PUBLIC Deny ReadMetadata, Deny WriteMetadata Dept B Grant ReadMetadata Administratr grups Grant ReadMetadata, Grant WriteMetadata DW Analysts Grant ReadMetadata, Grant WriteMetadata The result f this ACE is that nly Dept B grup members, administratrs, and analysts can access this flder t view maps. Only admins and Analysts can create r manage maps. Nte: deny PUBLIC WriteMetadata and SAS Admins Grant WriteMetadata permissins are inherited frm the Reprts parent flder. Yu can define the abve cllectin f ACEs as an Access Cntrl Template (ACT) that yu apply t the grup flder t secure a grup flder. Cmplete the fllwing steps t create the ACT: 1. Start the SAS Management Cnsle. 2. In the Authrizatin Manager plug-in, select Prperties fr the grup flder. In the Prperties dialg bx, click the Authrizatin tab. 3. Click the Access Cntrl Template buttn t apply the ACT t the flder. ACEs that are applied thrugh a direct ACT appear with a green backgrund fr the permissin check bxes that are viewed n the Authrizatin tab in that dialg bx. Appendix B: Hierarchic Flder Structure (Generic Example) The example in this appendix deals with the shared web reprts lcatin in the fllwing rt flder: /BIP Tree/ReprtStudi/Shared/Reprts By default, this lcatin in the metadata repsitry has nly thse access cntrls that are inherited frm the Default ACT, meaning that mst grups will have WriteMetadata access at this lcatin and can create flders and reprts. Fr a site where grup cntent must be secure t the grup, the first step fr the administratr is t create grup flders that represent brad user grupings at the site: Sales, Marketing, Operatins, Finance, Human 22

25 Resurces, and s n. In a secure setting, the administratr can als limit the creatin f flders at this level, t frce users t wrk in secure subflders created fr them. If there is a need fr sharing nnsecured reprts between grups, the administratr can create an pen-access Public flder and allw SAS Web Reprt Studi users t create flders and save reprts in these flders. Flder Examples: /BI Tree/ReprtStudi/Shared/Reprts/Public /BI Tree/ReprtStudi/Shared/Reprts/Sales /BI Tree/ReprtStudi/Shared/Reprts/Marketing /BI Tree/ReprtStudi/Shared/Reprts/Finance /BI Tree/ReprtStudi/Shared/Reprts/Executive Use-Case Scenari A U.S. whlesale business divides sales territries int regins (Sutheast, Suthwest, Nrtheast, and Nrthwest) and then by states within regins. Sales teams are managed by state, with a state manager and a reginal manager. Fur reginal managers reprt t the Sales Executive. Sales reprts include discunts and cmmissin data, s state managers must nt see ther managers reprts. Reginal managers can review all state reprts fr their regin but nt the reprts f ther regins. The Sales Executive can review reginal and state reprts and shares a US Sales reprt with the cmpany s Executive grup. The administratr creates and ppulates metadata grups, as fllws: Admins SAS Administratr(s) BI Analysts BI Cntent creatr(s) Executive Sales Exec is a member, with thers Reginal Sales Managers 4 State Managers by Regin 4 grups Sutheast State Managers Nrtheast State Managers Suthwest State Managers Nrthwest State Managers State Sales Managers = 4 Reginal State Manager grups The hierarchic flder structure lks like this:../reprts/public../reprts/executive../reprts/sales../reprts/sales/natinal (list cntinued) 23

26 ../Reprts/Sales/Sutheast/Regin../Reprts/Sales/Sutheast/Flrida../Reprts/Sales/Sutheast/Gergia...mre flders... When yu build permissins in a hierarchic flder structure, there are tw appraches: Prvide brad access at the tp f the hierarchy and blck it as yu wrk dwn the subflders Prvide limited access at the tp f the hierarchy and add access t subflders as yu wrk dwn the hierarchy. In deep hierarchies, either apprach can be difficult t visualize because effective permissins are cmbinatins f inherited permissins and direct permissins. Yu can create an ACT fr repeating patterns f permissins. Applying the ACT t each subflder in the hierarchy can make it easier t determine effective permissins. In the fllwing use case, the secnd apprach is use. This apprach prvides limited access at the tp f the hierarchy and adds access t subflders, cmbined with an ACT. 1. The administratr begins wrk in this flder: /BIP Tree/ReprtStudi/Shared/Reprts/ The administratrs sets permissins by using the fllwing ACE: PUBLIC Deny WriteMetadata Administratr grups Grant WriteMetadata The result f this ACE is that nly administratrs can create flders r cntent at this flder. This permissins setting prevents SAS Web Reprt Studi users frm accidentally saving reprts in an unsecured lcatin. 2. The administratr then creates the Public flder: /BIP Tree/ReprtStudi/Shared/Reprts/Public/ This flder is created with a direct ACE t grant WriteMetadata permissin fr the SASUSERS grup. This actin creates a public lcatin where registered users can share nnsensitive cntent. The administratr then uses the Authrizatin Manager plug-in in SAS Management Cnsle t create an ACT called Base Sales: PUBLIC Deny ReadMetadata Administratr grups Grant ReadMetadata, Grant WriteMetadata BI Analysts Grant ReadMetadata, Grant WriteMetadata Executives Grant ReadMetadata The result f applying this ACT t a flder (r any bject) blcks inheritance f the ReadMetadata permissin fr all users. It als enables administratrs t administer cntent, BI analysts t navigate and create cntent, and executives t navigate and view cntent. (list cntinued) 24

27 3. Next, the administratr creates the Sales flder:../shared/reprts/sales The administratr applies the Base Sales ACT t set the fllwing permissins: Reginal Sales Managers grup Grant ReadMetadata State Sales Managers grup (a supergrup f grups) Grant ReadMetadata The result f applying this ACT is that administratrs, BI analysts, and all sales management can navigate t this flder. Others emplyees cannt navigate t this flder. BI analysts and administratrs can manage flders at this level. 4. The administratr creates the Natinal flder:../shared/reprts/sales/natinal The administratr then applies the Base Sales ACT. The result f applying this ACT is that nly executives can view this flder and cntent. Administratrs and analysts can create and manage cntent. 5. The administratr creates the Sutheast flder:../shared/reprts/sales/sutheast The administratr then applies the Base Sales ACT and creates a direct ACE that sets the fllwing permissins: Sutheast Regin Sales Manager Grant ReadMetadata Sutheast State Sales Managers Grant ReadMetadata The result f applying the ACT and the direct ACE is that executives, the Sutheast reginal manager, and Sutheast state managers can navigate t this flder. 6. The administratr creates the Regin flder:../shared/reprts/sales/sutheast/regin The administratr applies the Base Sales ACT and creates a direct ACE that sets Grant ReadMetadata permissin fr the Sutheast Reginal Manager. The result f applying the ACT and the direct ACE is that executives and the Sutheast Reginal manager can read cntent in this flder. Administratrs and analysts can create and manage cntent. 7. The administratr creates the Gergia flder:../reprts/sales/sutheast/gergia The administratr applies the Base Sales ACT and creates a direct ACE t set the fllwing permissins: Gergia Sales Manager Grant ReadMetadata Sutheast Regin Manager Grant ReadMetadata The result f applying the ACT and the direct ACE is that executives, the Sutheast Reginal Sales Manager, and the Gergia Sales Manager can view this flder and cntent. Administratrs and analysts can create and manage cntent. 25

28 8. The administratr creates the Flrida flder:../reprts/sales/sutheast/flrida The administratr applies the Base Sales ACT and creates a direct ACE t set the fllwing permissins: Flrida Sales Manager Grant ReadMetadata Sutheast Regin Manager Grant ReadMetadata The result f applying the ACT and the direct ACE is that executives, the Sutheast Reginal Sales Manager, and the Flrida Sales Manager can view this flder and cntent. Administratrs and analysts can create and manage cntent. This pattern f flder creatin is repeated thrughut each regin. 26

29

30 T cntact yur lcal SAS ffice, please visit: sas.cm/ffices SAS and all ther SAS Institute Inc. prduct r service names are registered trademarks r trademarks f SAS Institute Inc. in the USA and ther cuntries. indicates USA registratin. Other brand and prduct names are trademarks f their respective cmpanies. Cpyright 2015, SAS Institute Inc. All rights reserved.

Down Payment Online Manual

Down Payment Online Manual Dwn Payment Online Manual Dwn Payment Online Manual Member cntacts may use this manual t help navigate Dwn Payment/Set Aside Prgram (DP) Online and perfrm the fllwing functins: 1. Lg int DP Online thrugh

More information

LSU HEALTH SHREVEPORT NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION

LSU HEALTH SHREVEPORT NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION LSU HEALTH SHREVEPORT NOTICE OF PRIVACY PRACTICES FOR PROTECTED HEALTH INFORMATION THIS NOTICE DESCRIBES HOW YOUR MEDICAL INFORMATION MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

Denver Public Schools. Financial Services. Financial Services Manual. Grants

Denver Public Schools. Financial Services. Financial Services Manual. Grants Denver Public Schls Financial Services Financial Services Manual Grants Table f Cntents Grants... 3 Prcedures GRC Website... 3 Step by Step Guide... 4 Federal Grants... 7 Title I... 7 Title II... 8 Time

More information

Financial Officer 18 Applicant Inventory

Financial Officer 18 Applicant Inventory Financial Officer 18 Applicant Inventry Frequently Asked Questins Why has an applicant inventry been created t fill Financial Officer 18 vacancies? The creatin f applicant inventries allws fr a mre cnsistent

More information

Academic Health Center Mayo Mail Code Delaware Street SE, Minneapolis, MN nexusipe.

Academic Health Center Mayo Mail Code Delaware Street SE, Minneapolis, MN nexusipe. Academic Health Center May Mail Cde 501 420 Delaware Street SE, Minneaplis, MN 55455 612-625-3972 nexusipe@umn.edu nexusipe.rg Natinal Center fr Interprfessinal Practice and Educatin Nexus Summit 2017:

More information

VMware AirWatch Certificate Authentication for EAS with SEG and TMG. For VMware AirWatch

VMware AirWatch Certificate Authentication for EAS with SEG and TMG. For VMware AirWatch VMware AirWatch Certificate Authenticatin fr EAS with SEG and TMG Fr VMware AirWatch H a v e d c u m e n t a t i n f e e d b a c k? S u b m it a D c u m e n t a t i n F e e d b a c k s u p p r t t ic k

More information

Council Camp Staff and the Annual Health & Medical Record. CampDoc FAQs

Council Camp Staff and the Annual Health & Medical Record. CampDoc FAQs Cuncil Camp Staff and the Annual Health & Medical Recrd CampDc FAQs What is CampDc? CampDc.cm is an electrnic health recrd system designed by physicians, nurses, and camp directrs fr use in camps. Web-based

More information

Frequently asked questions about health identifiers August 2015

Frequently asked questions about health identifiers August 2015 Frequently asked questins abut health identifiers August 2015 1 P a g e Questins abut individual health identifiers What is an individual health identifier r IHI? An individual health identifier r IHI

More information

FAQs: ARC PARTICIPATION & ELIGIBILITY CRITERIA

FAQs: ARC PARTICIPATION & ELIGIBILITY CRITERIA FAQs: ARC PARTICIPATION & ELIGIBILITY CRITERIA TOGETHER FOR DEVELOPMENT One UN Plaza DC1-16 Flr New Yrk NY 10017 T +1 212 906 6924 undg.rg FREQUENTLY ASKED QUESTIONS ARC PARTICIPATION & ELIGIBILITY CRITERIA

More information

Regional Sports and Recreation Grants Programme Application Guidelines

Regional Sports and Recreation Grants Programme Application Guidelines Reginal Sprts and Recreatin Grants Prgramme Applicatin Guidelines Aucklanders: mre active, mre ften Auckland ffers sprt and recreatin pprtunities withut equal in the suthern hemisphere which inspire and

More information

Archive and Destruction of Patient Records

Archive and Destruction of Patient Records Archive and Destructin f Patient Recrds If yu have run ut f rm t stre paper recrds yu may need t archive the riginal dcuments. A cmprehensive archive prcess, with written plicies and prcedures will help

More information

Smart Energy GB in Communities Fund Small grants. Grant Guidelines May 2016

Smart Energy GB in Communities Fund Small grants. Grant Guidelines May 2016 Smart Energy GB in Cmmunities Fund Small grants Grant Guidelines May 2016 0 What can I d nw? Befre yu apply fr funding make sure yu have lked at the free resurces available. Yu can start using these immediately.

More information

REGIONAL ARTS FUND Quick Response Grant

REGIONAL ARTS FUND Quick Response Grant REGIONAL ARTS FUND Quick Respnse Grant Intrductin The Reginal Arts Fund is an Australian Gvernment prgram that supprt sustainable cultural develpment in reginal and remte cmmunities in Australia. The prgram

More information

Key Points for Approving Officers Regarding Electronic Filing

Key Points for Approving Officers Regarding Electronic Filing Key Pints fr Apprving Officers Regarding Electrnic Filing The Land Title Act allws a subdivisin plan t be prepared and submitted t the Land Title Office electrnically. T assist Apprving Officers (AO) with

More information

CALL FOR ABSTRACTS. Overview of Summit Themes. Skills-Based Workshops

CALL FOR ABSTRACTS. Overview of Summit Themes. Skills-Based Workshops CALL FOR ABSTRACTS Submissin will pen January 26, 2018 Submissin deadline is March 6, 2018 Presenters will be ntified April 6, 2018 Overview f Summit Themes Nexus Summit 2018 brings tgether a grwing cmmunity

More information

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section.

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section. TITLE ACCESS TO A DESIGNATED LIVING OPTION IN CONTINUING CARE SCOPE Prvincial DOCUMENT # HCS-117 APPROVAL LEVEL Alberta Health Services Executive Leadership Team SPONSOR Vice President Prvince-Wide Clinical

More information

Original Date: January 27, 2010 Reviewed/Last Modified Date: September 15, 2015

Original Date: January 27, 2010 Reviewed/Last Modified Date: September 15, 2015 Hme and Cmmunity Care - Feedback Reprting Prcess: Cmplaints, Cmpliments and Inquiries Manual: Administratin Sectin: Risk and Safety Management Subsectin: Original Date: January 27, 2010 Reviewed/Last Mdified

More information

VMware AirWatch Certificate Authentication for EAS with SEG

VMware AirWatch Certificate Authentication for EAS with SEG VMware AirWatch Certificate Authenticatin fr EAS with SEG Fr VMware AirWatch Have dcumentatin feedback? Submit a Dcumentatin Feedback supprt ticket using the Supprt Wizard n supprt.air-watch.cm. This prduct

More information

Government of Ontario IT Standard (GO-ITS) GO-ITS Number 56.5 OPS Grants Management Reference Model

Government of Ontario IT Standard (GO-ITS) GO-ITS Number 56.5 OPS Grants Management Reference Model Gvernment f Ontari IT Standard (GO-ITS) GO-ITS Number 56.5 OPS Grants Management Reference Mdel Versin #: 2.4 Status: Apprved Prepared fr the Infrmatin Technlgy Standards Cuncil (ITSC) under the delegated

More information

About this guide 5 Section 1: Meeting VET sector requirements 7

About this guide 5 Section 1: Meeting VET sector requirements 7 Cntents Abut this guide 5 Sectin 1: Meeting VET sectr requirements 7 1.1 Hw Aspire s resurces assist in meeting requirements 7 1.2 Resurce quality assurance prcesses 16 Sectin 2: Unit f cmpetency infrmatin

More information

Award and Description. Inspire Award. Think Award. Removing engineering obstacles through creative thinking. 1 P a g e. Updated

Award and Description. Inspire Award. Think Award. Removing engineering obstacles through creative thinking. 1 P a g e. Updated 2017-2018 Award Descriptins Updated 11.27.2017 Award and Descriptin Inspire Award Criteria Required criteria fr the Inspire Award: This judged award is given t the Team that embdied the challenge f the

More information

Wireless Nurse Calling System Technical Document

Wireless Nurse Calling System Technical Document Wireless Nurse Calling System Technical Dcument Wireless Nurse Calling System Technical Dcument [July 2016] Bangalre, India Please feel free t give feedback thrugh: sales@frbixindia.cm 1 P a g e Wireless

More information

ITS Annual Report: Talking Points and Institutional Effectiveness Statements July 27, 2010 Contact: Gloria Thornton

ITS Annual Report: Talking Points and Institutional Effectiveness Statements July 27, 2010 Contact: Gloria Thornton ITS Annual Reprt: Talking Pints and Institutinal Effectiveness Statements July 27, 2010 Cntact: Glria Thrntn This extract frm the ITS Annual Reprt 09-10, highlights sme imprtant ITS activities fr 09-10,

More information

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section.

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section. TITLE MANAGEMENT OF PATIENT S OWN MEDICATIONS SCOPE Prvincial APPROVAL AUTHORITY Clinical Operatins Executive Cmmittee SPONSOR Prvincial Medicatin Management Cmmittee PARENT DOCUMENT TITLE, TYPE AND NUMBER

More information

Service Description: Cisco ACI Implementation Review Service (CON-AS-ACI-IMP-REV)

Service Description: Cisco ACI Implementation Review Service (CON-AS-ACI-IMP-REV) Page 1 f 5 Service Descriptin: Cisc ACI Implementatin Review Service (CON-AS-ACI-IMP-REV) This dcument describes the Cisc ACI Implementatin Review Service. Related Dcuments: This dcument shuld be read

More information

SEQOHS Accreditation Assessor Job Description

SEQOHS Accreditation Assessor Job Description SEQOHS Accreditatin Assessr Jb Descriptin Abut this Dcument This dcument supprts the SEQOHS Office prcess fr the recruitment f assessrs fr the SEQOHS accreditatin scheme. Assessrs must be frm an ccupatinal

More information

IT222 Microsoft Network Operating System II [Onsite]

IT222 Microsoft Network Operating System II [Onsite] IT222 Micrsft Netwrk Operating System II [Onsite] Curse Descriptin: This curse serves as an extensin n Micrsft netwrk server technlgies. Issues n infrastructure administratin are discussed. Aspects f active

More information

Quincy University Grants Development & Management Guide

Quincy University Grants Development & Management Guide 1 Quincy University Grants Develpment & Management Guide Intrductin The Office f University Advancement versees the grants prcess at Quincy University and is yur resurce fr seeking funding frm any external

More information

PRIVACY IMPACT ASSESSMENT (PIA) For the

PRIVACY IMPACT ASSESSMENT (PIA) For the PRIVACY IMPACT ASSESSMENT (PIA) Fr the Medical Bards Online Tracking System (MEDBOLTS) Department f the Navy - TMA DHP Funded System SECTION 1: IS A PIA REQUIRED? a. Will this Department f Defense (000)

More information

CMS Change Request User Guide. Required April 1, Consolo Services CMS Change Request 8358 User Guide P a g e 1

CMS Change Request User Guide. Required April 1, Consolo Services CMS Change Request 8358 User Guide P a g e 1 CMS Change Request 8358 User Guide Required April 1, 2014 Cnsl Services CMS Change Request 8358 User Guide P a g e 1 CMS Change Request 8358 Required April 1, 2014 User Guide Overview: CMS Change Request

More information

COMMUNITY PHARMACY WARFARIN SERVICE Community Pharmacy Anti-coagulation Management (CPAM) Service

COMMUNITY PHARMACY WARFARIN SERVICE Community Pharmacy Anti-coagulation Management (CPAM) Service COMMUNITY PHARMACY WARFARIN SERVICE Cmmunity Pharmacy Anti-cagulatin Management (CPAM) Service Intrductin INFORMATION FOR GENERAL PRACTICE In cuntries such as the UK, Australia, Canada and USA anticagulant

More information

Patient Portal Introduction and Overview

Patient Portal Introduction and Overview A health IT web slutin brught t yu by TSI Healthcare Patient Prtal Intrductin and Overview Cntrl Panel Audi Optins: This is a listen nly presentatin Audi by Phne Select Use Telephne Tl Dial the prvided

More information

For purposes of this Security Agreement, the use of the terms you and your includes both the Oil and Gas Operator and the EFA when appropriate.

For purposes of this Security Agreement, the use of the terms you and your includes both the Oil and Gas Operator and the EFA when appropriate. Oil and Gas Operatr and Electrnic Filing Administratr (EFA) Registratin and Security Agreement fr Oil and Gas Electrnic Filing Systems Oil and Gas Operatr (Primary Reprting Entity) Name f Oil and Gas Operatr:

More information

Choose Pharmacy Application Frequently Asked Questions (FAQs)

Choose Pharmacy Application Frequently Asked Questions (FAQs) Chse Pharmacy Applicatin Frequently Asked Questins (FAQs) What is Chse Pharmacy? Wh develped the Chse Pharmacy applicatin? Wh can use the Chse Pharmacy applicatin? Des Chse Pharmacy integrate with the

More information

Terminating the Provider- Patient Relationship. Provided by Coverys Risk Management

Terminating the Provider- Patient Relationship. Provided by Coverys Risk Management Terminating the Prvider- Patient Relatinship Prvided by Cverys Risk Management Terminating the Prvider-Patient Relatinship What s the Risk? An allegatin f abandnment may be brught against a prvider if

More information

Work Instruction Patient Visits

Work Instruction Patient Visits Wrk Instructin Patient Visits THE UNIVERSITY OF TEXAS HEALTH SCIENCE CENTER AT SAN ANTONIO Wrk Instructin Patient Visits Vels - eresearch Versin 9.2 Versin: 2.0, 04/30/2015 Wrk Instructin Patient Visits

More information

Advanced Resume Writing:

Advanced Resume Writing: Advanced Resume Writing: Targeting Yur Resume Get mre inf at www.wrkfrce-ks.cm Equal Opprtunity Emplyer/Prgram Auxiliary aids and services are available upn request t individuals with disabilities. The

More information

Meaningful Use - Menu Measure 4 Family History Configuration Guide

Meaningful Use - Menu Measure 4 Family History Configuration Guide Enterprise EHR Meaningful Use - Menu Measure 4 Family Histry Cnfiguratin Guide Last Updated: January 21, 2014 Cpyright 2013 Allscripts Healthcare, LLC. www.allscripts.cm MU Menu 04 Family Histry This guide

More information

Each Home Instead Senior Care franchise office is independently owned and operated Home Instead, Inc.

Each Home Instead Senior Care franchise office is independently owned and operated Home Instead, Inc. Each Hme Instead Senir Care franchise ffice is independently wned and perated. 2010 Hme Instead, Inc. The nrmal aging prcess, which may invlve sensry lss, decline in memry, and slwer prcessing f infrmatin

More information

Engaging in End of Life Conversations with Patients and Families: A Four Part Series

Engaging in End of Life Conversations with Patients and Families: A Four Part Series Engaging in End f Life Cnversatins with Patients and Families: A Fur Part Series Part One: General Explratin f End f Life Optins We receive training and build skills thrughut ur careers that allw us t

More information

Scheduling and Registration (Specialty Hospital) Training Guide

Scheduling and Registration (Specialty Hospital) Training Guide Scheduling and Registratin (Specialty Hspital) Visin 4.3 (December 2012) Training Guide SurceMedical Learning Center f Excellence Last change made: January 2013 2013 Surce Medical Slutins, Inc. All Rights

More information

FREQUENTLY ASKED QUESTIONS ARC PARTICIPATION & ELIGIBILITY CRITERIA 2017

FREQUENTLY ASKED QUESTIONS ARC PARTICIPATION & ELIGIBILITY CRITERIA 2017 FREQUENTLY ASKED QUESTIONS ARC PARTICIPATION & ELIGIBILITY CRITERIA 2017 1. Why is the ARC participatin list imprtant? Why des ARC participatin nly include the RC and selected members f the UNCT? Defining

More information

PAPER FOR NHS LUTON COMMUNITY SERVICES BOARD MEETING HELD ON 21 ST APRIL 2010

PAPER FOR NHS LUTON COMMUNITY SERVICES BOARD MEETING HELD ON 21 ST APRIL 2010 PAPER FOR NHS LUTON COMMUNITY SERVICES BOARD MEETING HELD ON 21 ST APRIL 2010 TITLE AUTHOR(S) PRESENTED BY DIRECTOR S SIGNATURE PURPOSE/ SUMMARY DECISION REQUIRED Standards fr Better Health & CQC Registratin

More information

Geofencing in ehealth

Geofencing in ehealth Gefencing in ehealth Mbile Services Prject by Fatimah Zahra (7515) Faculty f Cmputer Science Free University f Bzen-Blzan Italy, 2009 Cntents Cntents...2 Figures...2 1. Intrductin...3 2. System Functins...3

More information

Medicaid EHR Incentive Program Eligible Professionals

Medicaid EHR Incentive Program Eligible Professionals Medicaid EHR Incentive Prgram Eligible Prfessinals Payment Year 1 Adpt, Implement, Upgrade New Hampshire Department f Health and Human Services Office f Medicaid Business and Plicy First Year Attestatin

More information

CANADIAN FOUNDATION FOR DIETETIC RESEARCH LA FONDATION CANADIENNE DE LA RECHERCHE EN DIETETIQUE

CANADIAN FOUNDATION FOR DIETETIC RESEARCH LA FONDATION CANADIENNE DE LA RECHERCHE EN DIETETIQUE CANADIAN FOUNDATION FOR DIETETIC RESEARCH LA FONDATION CANADIENNE DE LA RECHERCHE EN DIETETIQUE CFDR Research Shwcase DC Cnference 2018 Late Breaking Abstract Submissin Infrmatin The Canadian Fundatin

More information

Obtain an official copy of your PN transcript to submit with this packet.

Obtain an official copy of your PN transcript to submit with this packet. Advanced Placement Packet fr LPNs fr Spring 2018 Deadline fr packet submissin: 11/16/17 It is pssible t receive credit fr yur LPN experience and begin the RN prgram at Crning Cmmunity Cllege. Advanced

More information

Client and Health Coach Support System

Client and Health Coach Support System Client and Health Cach Supprt System HOW TO USE THE CLIENT AND HEALTH COACH SUPPORT SYSTEM HOW TO USE THE CLIENT & HEALTH COACH SUPPORT SYSTEM The Client and Health Cach Supprt System is an rganized way

More information

The project may wish to consider a number of options to support and improve the quality of advice in Bournemouth, Dorset and Poole.

The project may wish to consider a number of options to support and improve the quality of advice in Bournemouth, Dorset and Poole. QUALITY MARK REVIEW Intrductin This review cnsiders a number f quality marks r qualificatins available t the advice sectr and summarises the key infrmatin fr each. The Cnnecting Advice in Drset prject

More information

Re- Defining Physician Credentialing Software A New Approach

Re- Defining Physician Credentialing Software A New Approach Sftware A New Apprach The upcming reimbursement shift frm fee fr service t fee fr quality has generated an increased fcus n ppulatin health management. In rder t ensure a sufficient clinical delivery base,

More information

SAMPLE- Visit FirehouseSubsFoundation.org to apply online. Firehouse Subs Public Safety Foundation Grant Application

SAMPLE- Visit FirehouseSubsFoundation.org to apply online. Firehouse Subs Public Safety Foundation Grant Application SAMPLE- Visit FirehuseSubsFundatin.rg t apply nline. Firehuse Subs Public Safety Fundatin Grant Applicatin 1 SAMPLE- Visit FirehuseSubsFundatin.rg t apply nline. Cngratulatins! Yur rganizatin has met Firehuse

More information

REGIONAL ARTS FUND Step Out

REGIONAL ARTS FUND Step Out REGIONAL ARTS FUND Step Out Intrductin The Reginal Arts Fund is an Australian Gvernment prgram that supprts sustainable cultural develpment in reginal and remte cmmunities in Australia. The prgram is managed

More information

State of Florida Department of Children and Families

State of Florida Department of Children and Families State f Flrida Department f Children and Families Rick Sctt Gvernr Mike Carrll Secretary Request fr Applicatins #11H20GN1 ADDENDUM #001 Criminal Justice Mental Health and Substance Abuse (CJMHSA) Reinvestment

More information

Department of Teacher Education Tentative Admission

Department of Teacher Education Tentative Admission Department f Teacher Educatin Tentative Admissin Requirements Must have cmpleted a minimum f 60 cllege credit hurs Minimum GPA f 2.75 Minimum cmpsite scre (r super scre) f 20 n the ACT Cmplete the Missuri

More information

Government Equalities Office Returners Fund

Government Equalities Office Returners Fund Gvernment Equalities Office Returners Fund Overview In the Spring Budget 2017, the Prime Minister cmmitted 5 millin t prmte returnships t the public and private sectrs, helping peple back int emplyment

More information

DOCUMENT TITLE: Clarification of Bureau of Primary Health Care Credentialing and Privileging Policy outlined in Policy Information Notice

DOCUMENT TITLE: Clarification of Bureau of Primary Health Care Credentialing and Privileging Policy outlined in Policy Information Notice 2002-22 DATE: July 10, 2002 DOCUMENT TITLE: Clarificatin f Bureau f Primary Health Care Credentialing and Privileging Plicy utlined in Plicy Infrmatin Ntice 2001-16 TO: Cmmunity Health Centers Migrant

More information

Champions for Healthy Kids Grants

Champions for Healthy Kids Grants Champins fr Healthy Kids Grants 2015-2016 Champins fr Healthy Kids Grants Nw Available! $1 Millin Champins fr Healthy Kids grants available t nnprfit rganizatins fr prgrams perating June 1, 2015-May 31,

More information

PLACEMENT POLICIES FOR WORK & TRAVEL AND TRAINEE/INTERN PROGRAMS

PLACEMENT POLICIES FOR WORK & TRAVEL AND TRAINEE/INTERN PROGRAMS PLACEMENT POLICIES FOR WORK & TRAVEL AND TRAINEE/INTERN PROGRAMS TABLE OF CONTENTS Wrk & Travel Prgram Submissin Prcess 1 Placement Prcedures 2 Trainee/Intern Prgram Submissin Prcess 3 Placement Prcedures

More information

Medical Assistance in Dying: Update Stakeholder Presentation

Medical Assistance in Dying: Update Stakeholder Presentation Medical Assistance in Dying: Update Stakehlder Presentatin Ministry f Health and Lng-Term Care and Ministry f the Attrney General Week f August 1, 2016 Implementatin Questins: What We Heard Frm Yu 1. Reprting:

More information

R&D Tax Incentive Taxpayer alerts issued

R&D Tax Incentive Taxpayer alerts issued TaxTalk Insights Research and Develpment R&D Tax Incentive Taxpayer alerts issued 28 February 2017 In brief Recently, the Cmmissiner f Taxatin (the Cmmissiner), in cnjunctin with the Department f Industry,

More information

WORKFORCE IMPLEMENTATION GUIDANCE (WIG) LETTER RELEASE OF GEORGIA LWDA STRATEGIC PROGRAMMING GRANTS

WORKFORCE IMPLEMENTATION GUIDANCE (WIG) LETTER RELEASE OF GEORGIA LWDA STRATEGIC PROGRAMMING GRANTS WORKFORCE IMPLEMENTATION GUIDANCE (WIG) LETTER DATE: December 16, 2015 NO: TO: FROM: SUBJECT: WIG GA-15-006 LOCAL WORKFORCE SYSTEM STAKEHOLDERS ODIE DONALD, WIOA Services Directr RELEASE OF GEORGIA LWDA

More information

APPLICATION FOR REGISTERED NURSING PROGRAM FALL 2017 (Filing deadline: February 10, 2017, 4:00 PM) PLEASE TYPE OR PRINT NEATLY

APPLICATION FOR REGISTERED NURSING PROGRAM FALL 2017 (Filing deadline: February 10, 2017, 4:00 PM) PLEASE TYPE OR PRINT NEATLY APPLICATION FOR REGISTERED NURSING PROGRAM FALL 2017 (Filing deadline: February 10, 2017, 4:00 PM) PLEASE TYPE OR PRINT NEATLY NOTE: N student may enrll in the Nursing Prgram unless he/she is admitted

More information

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section.

NOTE: The first appearance of terms in bold in the body of this document (except titles) are defined terms please refer to the Definitions section. TITLE RESTRAINT AS A LAST RESORT SCOPE Prvincial APPROVAL AUTHORITY Clinical Operatins Executive Cmmittee SPONSOR Senir Operating Officer, Glenrse Rehabilitatin Hspital PARENT DOCUMENT TITLE, TYPE AND

More information

Pre-shift Meeting Procedure

Pre-shift Meeting Procedure Pre-shift Meeting Prcedure Table f Cntents Intrductin...4 Purpse... 4 Scpe... 4 Rles... 4 Training... 4 Prcedure (Steps)...5 Owner prduces daily ntes fr pre-shift meetings...5 Step 1Owner fills ut Pre-shift

More information

Instructions. Important Dates. Application Deadline: May 15, 2013 at 5:00 p.m. Grant Awards Announced: July 15, 2013

Instructions. Important Dates. Application Deadline: May 15, 2013 at 5:00 p.m. Grant Awards Announced: July 15, 2013 Instructins Imprtant Dates Applicatin Deadline: May 15, 2013 at 5:00 p.m. Grant Awards Annunced: July 15, 2013 Prject Cmpletin: December 31, 2014 CONTACT: Lancaster Cunty Cnservancy Fritz Schreder PO Bx

More information

Medical Assistant Program Western Technical College. Supplemental Information

Medical Assistant Program Western Technical College. Supplemental Information Medical Assistant Prgram Western Technical Cllege Supplemental Infrmatin Curse Sequence and Delivery. This is a tw-term prgram. During the first term, the student cmpletes the basic r fundatinal curses.

More information

Community Development Small Grants Fund. Guidelines 2018

Community Development Small Grants Fund. Guidelines 2018 Cmmunity Develpment Small Grants Fund Guidelines 2018 This fund is pen t charitable nt-fr-prfit cmmunity welfare grups whse primary clientele cme frm within Palmerstn Nrth City Cuncil (PNCC) bundaries.

More information

GRANT APPLICATION. Sustainable Agricultural Land Strategy Grants SUSTAINABLE AGRICULTURAL LANDS CONSERVATION PROGRAM

GRANT APPLICATION. Sustainable Agricultural Land Strategy Grants SUSTAINABLE AGRICULTURAL LANDS CONSERVATION PROGRAM SUSTAINABLE AGRICULTURAL LANDS CONSERVATION PROGRAM Sustainable Agricultural Land Strategy Grants GRANT APPLICATION Strategic Grwth Cuncil Califrnia Natural Resurces Agency Califrnia Department f Cnservatin

More information

The Veteran s Guide to Developing a Resume

The Veteran s Guide to Developing a Resume The Veteran s Guide t Develping a Resume by Lisa Rsser The single biggest mistake I see service members make when creating resumes is that they dump everything they have ever dne in the military int ne

More information

YOUTH What is Heads Up Football? What are the benefits of a youth football organization adopting Heads Up Football?

YOUTH What is Heads Up Football? What are the benefits of a youth football organization adopting Heads Up Football? YOUTH What is Heads Up Ftball? Heads Up Ftball is a USA Ftball rganizatinal membership prgram designed t create a better, safer game. Key cmpnents f this prgram include caches cmpleting the nly natinally

More information

SC Launch Grant Programs Qualifications and Processing Procedures Effective August 1, 2017

SC Launch Grant Programs Qualifications and Processing Procedures Effective August 1, 2017 SC Launch Grant Prgrams Qualificatins and Prcessing Prcedures Effective August 1, 2017 SCRA s SC Launch Prgram supprts entrepreneurs, increases technlgy cmmercializatin, and fsters early-stage cmpany develpment

More information

2018 HBS New Venture Competition Student Social Enterprise Track

2018 HBS New Venture Competition Student Social Enterprise Track 2018 HBS New Venture Cmpetitin Student Scial Enterprise Track Details fr Participating Teams KEY DATES See details fr each n fllwing pages Date January 31, 2018 12:00 nn February 21, 2018 12:00 nn March

More information

Working Location: Science Council office in Farringdon, London. With some London and UKtravel

Working Location: Science Council office in Farringdon, London. With some London and UKtravel Jb Title: Registratin and Licensing Manager Reprts t: Chief Executive Wrking Hurs: 5 days a week (1.0 FTE); Wrking Lcatin: Science Cuncil ffice in Farringdn, Lndn. With sme Lndn and UKtravel expected.

More information

Career Program for Life Sciences. for female PhD students, postdocs, and group leaders. Guide for applicants

Career Program for Life Sciences. for female PhD students, postdocs, and group leaders. Guide for applicants Career Prgram fr Life Sciences fr female PhD students, pstdcs, and grup leaders Guide fr applicants The prgram is crdinated by the Zurich-Basel Plant Science Center and supprted by the Swiss Federal Office

More information

DoD Plain Writing Act Compliance Report April 13, 2018

DoD Plain Writing Act Compliance Report April 13, 2018 DD Plain Writing Act Cmpliance Reprt April 13, 2018 This reprt utlines the prgress twards implementing the Plain Writing Act f 2010 within the DD. Please check back fr updates. I. Senir Agency Official

More information

Kansas Paralegal Association's Code of Ethics and Professional Responsibility

Kansas Paralegal Association's Code of Ethics and Professional Responsibility Kansas Paralegal Assciatin's Cde f Ethics and Prfessinal Respnsibility PREAMBLE: Kansas Paralegal Assciatin ("KPA") is a prfessinal rganizatin frmed t: (1) prmte and maintain high standards in the Paralegal

More information

CITY OF MELBOURNE APPLICATION FOR DOWNTOWN MELBOURNE CRA RETAIL CORE COMMERCIAL LIGHTING PROGRAM

CITY OF MELBOURNE APPLICATION FOR DOWNTOWN MELBOURNE CRA RETAIL CORE COMMERCIAL LIGHTING PROGRAM The Melburne Dwntwn Cmmunity Redevelpment Agency (CRA) is prviding funding fr a lighting enhancement prgram within the dwntwn retail cre. Grant funding is prvided t encurage building wners r businesses

More information

Safety Attendant for Patients At-Risk for Self Injury

Safety Attendant for Patients At-Risk for Self Injury Safety Attendant fr Patients At-Risk fr Self Injury 2.0 Cntact Hurs Califrnia Bard f Registered Nursing CEP#_16140 American Medical Educatin Center Disclaimer: This packet is intended t prvide infrmatin

More information

Guidelines for Analysis of Credentials to be Included on COOL

Guidelines for Analysis of Credentials to be Included on COOL Guidelines fr Analysis f Credentials t be Included n COOL Relatedness Determinatin Guidelines Relatedness Determinatin (RD) refers t the identificatin f certificatins relevant t a Navy rating/designatr/ccupatin.

More information

Resident Assistant Application

Resident Assistant Application Resident Assistant Applicatin 2017-2018 We are excited that yu have decided t apply t be a Resident Assistant (RA). It is a unique pprtunity t wrk with diverse grups f students and be actively invlved

More information

Vantel Pearls International, Inc. 46 Eastman Street, South Easton, MA Tel Compensation Plan.

Vantel Pearls International, Inc. 46 Eastman Street, South Easton, MA Tel Compensation Plan. Vantel Pearls Internatinal, Inc. 46 Eastman Street, Suth Eastn, MA 02035 www.vantelpearls.cm Tel. 508.698.2220 (March, 2016) Welcme t Vantel Pearls! This dcument prvides an verview f the incme, benefits,

More information

WHAT IS CAL MEDICONNECT? Cal MediConnect is a health plan that combines all of the benefits you now get from Medicare and Medi-Cal into a single plan.

WHAT IS CAL MEDICONNECT? Cal MediConnect is a health plan that combines all of the benefits you now get from Medicare and Medi-Cal into a single plan. Last updated: 3/8/2016 5:25 PM DO YOU HAVE BOTH MEDICARE AND MEDI-CAL? Intrductin If s, yu may be eligible t jin a Cal MediCnnect health plan. WHAT IS CAL MEDICONNECT? Cal MediCnnect is a health plan that

More information

Career Program. for female PhD students, postdocs, and group leaders. Guide for applicants

Career Program. for female PhD students, postdocs, and group leaders. Guide for applicants Career Prgram fr female PhD students, pstdcs, and grup leaders Guide fr applicants The prgram is crdinated by the Zurich-Basel Plant Science Center and supprted by the Swiss Federal Office fr Gender Equality

More information

Our Epic Project Frequently Asked Questions

Our Epic Project Frequently Asked Questions Our Epic Prject Frequently Asked Questins What is EPIC? EPIC is a state-f-the art integrated infrmatin system that cmbines all available patient infrmatin in a single database t imprve all caregivers ability

More information

Home Modifications Enrolment Form

Home Modifications Enrolment Form Hme Mdificatins Enrlment Frm Please answer all questins t cmplete yur Hme Mdificatins enrlment Persnal details 1. Enter yur full name Family Name (Surname) Given Names 2. Enter yur birth date Day/mnth/year

More information

Florida Department of Financial Services Florida Accountability Contract Tracking System (FACTS)

Florida Department of Financial Services Florida Accountability Contract Tracking System (FACTS) Flrida Department f Financial Services Flrida Accuntability Cntract Tracking System (FACTS) Agreement Agency FTP Batch Transmissin User Guide July 2014 Table f Cntents Intrductin:... 3 Agency Assumptins:...

More information

Who is authorized to give consent (substitute decision makers) Health Care Consent Act

Who is authorized to give consent (substitute decision makers) Health Care Consent Act Mdule 7 Cnsent In this mdule yu will learn abut Health Care Cnsent Act including Elements f cnsent Definitins including Capable Prpser Treatment Curse and plan f treatment Activities nt cnsidered t be

More information

Environment, Health and Safety Policy Appendix B: Environment, Health and Safety Responsibilities

Environment, Health and Safety Policy Appendix B: Environment, Health and Safety Responsibilities U f A Plicies and Prcedures On-Line (UAPPOL) Original Apprval Date: August 22, 2006 (frmerly a prcedure) Mst Recent Apprval Date: May 28, 2014 Parent Plicy: Envirnment, Health and Safety Plicy Envirnment,

More information

The information and instructions below are for College of Business Administration [Departmental] Scholarships only.

The information and instructions below are for College of Business Administration [Departmental] Scholarships only. COLLEGE OF BUSINESS ADMINISTRATION DEPARTMENTAL SCHOLARSHIPS Cllege f Business Administratin departmental schlarships are available t business majrs in all cncentratins and are awarded t Business students

More information

Guide to Complete the Steps for Foreign-Trained Nurses to Obtain the Maryland Registered Nurse (RN) License

Guide to Complete the Steps for Foreign-Trained Nurses to Obtain the Maryland Registered Nurse (RN) License Guide t Cmplete the Steps fr Freign-Trained Nurses t Obtain the Maryland Registered Nurse (RN) License Welcme Back Center Suburban Maryland Mntgmery Cunty, Maryland Department f Health and Human Services

More information

Application. Community Health Excellence (CHE) Grant Program

Application. Community Health Excellence (CHE) Grant Program Cmmunity Health Excellence (CHE) Grant Prgram 2017 2018 Applicatin A cmpleted applicatin must be submitted by July 30, 2017, and must include: A cmpleted Applicatin Cver Sheet and Narrative A cmpleted

More information

GMS 640: Introduction to Biomedical Information Grants Handout. Grants. Grant facts (NIH)

GMS 640: Introduction to Biomedical Information Grants Handout. Grants. Grant facts (NIH) GMS 640: Intrductin t Bimedical Infrmatin Grants Handut Grants Grant facts (NIH) The NIH, cmprising 27 institutes and centers, prvides a significant amunt f funding fr US medical research. It awards nearly

More information

Health Commerce System (HCS)

Health Commerce System (HCS) New Yrk State Department f Health Divisin f ACF/Assisted Living Surveillance New Administratr/EHP Prgram Crdinatr and/r Operatr Checklist and Infrmatinal Guide As a new Administratr/EHP Prgram Crdinatr

More information

CANADA-JERUSALEM CO-DEVELOPMENT AND CO-PRODUCTION INCENTIVE GUIDELINES 2017

CANADA-JERUSALEM CO-DEVELOPMENT AND CO-PRODUCTION INCENTIVE GUIDELINES 2017 CANADA-JERUSALEM CO-DEVELOPMENT AND CO-PRODUCTION INCENTIVE GUIDELINES 2017 The Canada-Jerusalem C-Develpment and C-Prductin Incentive The Canada-Jerusalem C-Develpment and C-Prductin Incentive ( Incentive

More information

Position Description

Position Description Psitin Descriptin Psitin Title: Direct Reprts: Lcatin: Nurse Team Leader HNS IPU Team Leader, Cmmunity Nursing Team, Cmmunity Vlunteer Crdinatr and Physitherapist Clinical Administratrs (dtted line) Hspice

More information

Oregon Registry. Infant Toddler Professional Credential. Overview. Oregon Center for Career Development in Childhood Care and Education

Oregon Registry. Infant Toddler Professional Credential. Overview. Oregon Center for Career Development in Childhood Care and Education Oregn Registry Infant Tddler Prfessinal Credential Overview Oregn Center fr Career Develpment in Childhd Care and Educatin March 2011 Oregn Center fr Career Develpment in Childhd Care and Educatin SETTING

More information

AOTF Health Services Research Grant Request For Application

AOTF Health Services Research Grant Request For Application AOTF Health Services Research Grant 2018-2019 Request Fr Applicatin The AOTF Health Services Research Grant (HSR) is targeted t principal investigatrs wh d nt currently have substantial extramural research

More information

Changes in the Scope of Practice Environment for Nurse Practitioners in Michigan

Changes in the Scope of Practice Environment for Nurse Practitioners in Michigan Changes in the Scpe f Practice Envirnment fr Nurse Practitiners in Michigan It has been an exciting and interesting year in the plicy wrld fr NP practice in Michigan. The changes that have ccurred happened

More information

Annual South Carolina School Health LPN of the Year Award ( )

Annual South Carolina School Health LPN of the Year Award ( ) Annual Suth Carlina Schl Health LPN f the Year Award (2017-2018) The SC Schl Health LPN f the Year Award is presented annually by the SC Department f Health and Envirnmental Cntrl and the SC Department

More information

EXPLANATORY NOTES. (applicable from 1 July 2015) STAGE 1 DESKTOP ASSESSMENT. for the RECOGNITION OF OVERSEAS OCCUPATIONAL THERAPY QUALIFICATIONS

EXPLANATORY NOTES. (applicable from 1 July 2015) STAGE 1 DESKTOP ASSESSMENT. for the RECOGNITION OF OVERSEAS OCCUPATIONAL THERAPY QUALIFICATIONS Phne: +61-8-9368 2655 GPO Bx 959 Suth Perth WA 6951 Website: www.tcuncil.cm.au E-mail: admin@tcuncil.cm.au ABN 50 377 833 627 EXPLANATY NOTES (applicable frm 1 July 2015) STAGE 1 DESKTOP ASSESSMENT fr

More information