Chapter 1This red paper is a practical guide for technical users, installers, system administrators, and programmers who implement, maintain, or develop applications for your PeopleSoft system. In this red paper, we discuss guidelines on how to address the security of your implementation, including Network infrastructure considerations, hardening of the PeopleSoft Internet Architecture and Portal and other system hardening configuration recommendations. This document doesn’t cover the configuration of batch processes. The information contained in this document originated from many sources including, Industry research and knowledge, internal expertise, as well as PeopleSoft Global Support Center (GSC) and therefore contains "real-life" solutions and recommendations that have been implemented in in the field. Since we can’t address every security consideration that might be applicable to your specific implementation and environment, the items discussed in this document are intended to give a broad “best practices” baseline for security a PeopleSoft environement. As such, many of the frequently asked questions we receive from the field are covered in this document. This red paper provides guidance in setting up security for PeopleSoft systems beyond application security. The intent of this document is to provide information about securing the overall infrastructure of a deployed PeopleSoft system.
- Chapter 1 “Introduction”: introduces the red paper.
- Chapter 2 “Security Model”: discusses required reading and gives a conceptual overview of security issues. Individuals and groups who may be tasked with setting security policy as well as ensuring compliance and adherence to industry best practices should find this section useful.
- Chapter 3 “Securing Network Infrastructure”: discusses different approaches to network infrastructure security. Network and security administrators (or other individuals tasked with network security) will find this section to be a useful guideline to securing the supporting network of a PeopleSoft environment.
- Chapter 4 “Securing PeopleSoft Internet Architecture”: gives practical solutions for Pure Internet Architecture (PIA) security. A practical guide to providing security solutions and recommended settings for providing and maintaining PIA security. System and Security Administrators should find this information useful.
- Chapter 5 “PeopleTools Security Hardening”: discusses hardening of PeopleTools Security. System administrators should find valuable information in this section about how to address hardening and improving PeopleTools Security
- Chapter 6 “Securing Customized PeopleSoft Applications”: Gives some guidelines for addressing securing customized application. Developers, System Administrators and Business analyst can find guidance and recommendations for good security practices when customizing applications in this section.
Keep in mind that PeopleSoft updates this document as needed so that it reflects the most current feedback we receive from the field. Therefore, the structure, headings, content, and length of this document are likely to vary with each posted version. To see if the document has been updated since you last downloaded it, compare the date of your version to the date of the version posted on Customer Connection.
This paper is not a general introduction to environment tuning, and we assume that our readers are experienced IT professionals, with a good understanding of PeopleSoft’s internet architecture. To take full advantage of the information covered in this document, we recommend that you have a basic understanding of system administration, internet architecture, relational database concepts, SQL, and how to use PeopleSoft applications. This document is not intended to replace the documentation delivered with the PeopleTools CD or PeopleBooks (note: you should reference those documents appropriate to your specific version of PeopleSoft products). We recommend that before you read this document, you read the PIA-related information in the PeopleTools PeopleBooks to ensure that you have a well-rounded understanding of PIA technology.
Note. Much of the information in this document eventually gets incorporated into subsequent versions of the PeopleBooks.
Many of the fundamental concepts related to PIA are discussed in the following documents:
Enterprise PeopleTools PeopleBooks
-
System and Server Administration
-
Security Administration
-
PeopleSoft Application Designer
-
PeopleSoft Integration Broker
-
PeopleCode Language Reference
Separate PeopleSoft documents:
Additionally, we recommend that you read the BEA documentation (in HTML format) delivered with the BEA CD-ROM, to gain a thorough understanding of the BEA products that PeopleSoft uses, including Tuxedo, Jolt, and WebLogic Server 8.1. Refer to your PeopleSoft Installation and Administration documentation for directions on accessing the delivered BEA documentation.