Implementing PII Attribute Security In Oracle Fusion Data Intelligence

Implementing PII Attribute Security In Oracle Fusion Data Intelligenceimage

By Praveen Reddy Atturi, HEXstream solutions engineering manager

First, let’s define what we mean by PII attributes.

Personally Identifiable Information (PII) refers to any data that can identify an individual, such as their name, email address, social security number (SSN), salary or performance rating. In data security, it is crucial to ensure that PII attributes are protected and not visible to all users, even those within the same functional area.

For example, while multiple users may have access to the payroll module, only authorized users should be able to view compensation-related KPIs. This blog post outlines the detailed steps to secure sensitive data by hiding specific columns within a subject area using the security features available in Oracle Fusion Data Intelligence.

Introduction

Oracle FDI provides object-level security at both the subject area and workbook levels. However, the prebuilt object-level security does not account for restricting PII attributes, which are often included across multiple FDI subject areas. To ensure data privacy and compliance, these sensitive attributes can be restricted by implementing custom security in FDI, utilizing either prebuilt or custom application roles to control user access effectively.

Prerequisites

Before implementing column-level security, ensure the following prerequisites are met:

  1. Create or identify an application role that will be used to restrict access to PII attributes. In this example, the role of custom restricted PII access is used.
  2. Assign the user who should have restricted access to the PII attributes to a group role that is mapped to the custom restricted PII access application role.

Implementation steps

  1. Access semantic-model extensions from the FDI console, navigate to semantic model extensions.
  2. Open security configurations under security configurations, select configure object permissions and click next. This displays a list of both prebuilt and custom subject areas available in the environment, along with their current security configurations.
  3. Select the subject area and PII attribute In the left pane, navigate to the required subject area and expand the folders to locate the specific column to be restricted. For example, the PII attribute column under a specified table is selected for restriction.
  4. Restrict access for authenticated users after selecting the column, set authenticated users to no access on the right-hand side. This ensures that access to the column is controlled exclusively through role-based permissions defined in the semantic model.
  5. Restrict access for custom application role click show all roles, search for the application role identified in the prerequisites section (for example, custom restricted PII access) and set its access level to no access. Review your configuration and click finish to apply the changes.

Before vs. after implementation comparison

Before implementing the configuration, the #column was visible to all users with access to the corresponding subject area, including those who should not have permission to view sensitive information.

After applying the custom security configuration, the #column attribute is successfully hidden from users who do not have the appropriate access privileges. This ensures that only authorized roles can view PII-related data while maintaining smooth functionality across the subject area and related workbooks.

Implementation summary

Try implementing this configuration in any subject area containing PII attributes that require restricted access. Once applied, the security rules automatically extend to all FDI workbooks using that subject area, ensuring that sensitive columns remain hidden from unauthorized users without additional setup.

CLICK HERE TO CONTACT US ABOUT ENHANCING YOUR SECURITY STRATEGIES.



Let's get your data streamlined today!