Categories
"Whitelist" functionality for BI Publisher Reports of exceptions to 'Email Recipient Domains' restri

Description
We've created a list of Allowed Email Recipient Domains for BI Publisher which is working well for restricting communications and enforcing our Data Loss Prevention (DLP) policies.
However, we wish to send out communications to suppliers via the BI Publisher reports - though presently the control prevents all BI Publisher reports from being sent to any organisation that is not on the domain list. For other organisations this is likely to be even more of a challenge if they wish to email customers.
As a solution, would suggest that there is:
- an ‘exception list’ for BI Publisher reports that can avoid the domain listing,
- a log of all mails that have been sent - the report and to whom - that have avoided the domain whitelisting as a result of being on the 'exception list', and
- logging of changes to this BI Publisher 'exception list', such that BI Administrators cannot add reports to the exception list and send out the results without this being known
Use Case and Business Need
The challenges are that:
a) there are hundreds of suppliers in use and hence we have not added these to the permitted list of domains,
b) we'd rather not have to manually maintain this full long list of domains for suppliers on an ongoing basis as new suppliers are used/old ones are removed, and
c) some smaller suppliers have 'gmail', 'hotmail', etc email addresses. Including these in the list of permitted domains would be against DLP policies as it would allow any user to send any report to their personal emails.
Note: Each of the above are likely to be even more of a challenge for organisations wishing to send emailed BI Publisher reports to customers.
More details
Implementing the three suggested activities in the description would allow more organisations to enforce the strong, but limited, preventative control around email domain restrictions and provide the reports required to operate a robust monitoring control of exceptions to this preventative control.
Original Idea Number: ea1ec6454d
Comments
-
It is noted that functionality in BI Publisher differs from OTBI, as in the OTBI there is no equivalent of the 'Allowed Email Recipient Domains' control exists at the time of raising this Idea.
Please support the Ideas raised by others around controlling the domains that OTBI reports can be emailed to.
1 -
This will be a great feature to have.
1 -
Definitely a feature we would use as well!
0 -
A very necessary idea.
1 -
it will be helpful
1 -
This will be very helpful.
0 -
This is a much needed feature to avoid Data Loss. There is no way to tell today if any user has generated any report and sent it outside the Corporate Domain. We cannot restrict the domain because we need to send out POs and Billing Invoices to customers and suppliers. Having this pick and choose feature will help address the security concerns.
0 -
This will be indeed useful.
0